You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

创建S3存储桶后从EC2访问延迟超1小时的问题排查

Troubleshooting EC2 Access to Private S3 Bucket Created via CloudFormation

Hey there, let's dig into why you're still having trouble accessing your private test-bucket from EC2 even after waiting an hour—propagation delay is almost certainly not the issue here. Here are the most likely culprits and step-by-step fixes:

1. IAM Instance Profile & Policy Misconfiguration

This is the most common root cause. Let's verify the basics first:

  • Check if your EC2 instance is attached to the correct instance profile: Sometimes CloudFormation can fail to properly associate the profile, or you might have attached the wrong one. You can confirm this via the EC2 console (Instance > Details > IAM role) or run aws ec2 describe-instances --instance-ids YOUR-EC2-ID and look for the IamInstanceProfile field.
  • Validate your IAM policy content: Ensure your policy explicitly allows the actions you're trying to perform (e.g., s3:ListBucket for listing the bucket, s3:GetObject for downloading objects) and targets the correct resources. For example, a valid policy should include:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": ["s3:ListBucket", "s3:GetObject"],
                "Resource": [
                    "arn:aws:s3:::test-bucket",
                    "arn:aws:s3:::test-bucket/*"
                ]
            }
        ]
    }
    
  • Confirm the policy is attached to the instance role: Run aws iam list-role-policies --role-name YOUR-INSTANCE-ROLE-NAME to check if your policy is listed. If not, reattach it manually or update your CloudFormation stack to ensure the association is correct.

2. Conflicting S3 Bucket Policy

Even though you set AccessControl='Private', a bucket policy can override or restrict access:

  • Check for deny statements: Bucket policies use an "allow/deny" logic where deny statements take precedence. Run aws s3api get-bucket-policy --bucket test-bucket to retrieve the policy. Look for any Deny entries that might block your EC2 instance's IAM role.
  • Remember the AND rule: IAM role permissions and bucket policies work together—both must allow the action for access to be granted. If either denies it, the request will fail.

3. CloudFormation Stack Execution Issues

Occasionally, CloudFormation stacks can report success even if a resource (like the IAM role-policy attachment) didn't fully apply:

  • Check stack events: Go to the CloudFormation console, select your stack, and review the event log for any failed or stuck resources. If you see issues, try updating the stack (even with no changes) to force a reapplication of the configuration.
  • Reattach the policy manually: As a test, detach and reattach the IAM policy to your instance role. This can resolve any lingering sync issues.

4. VPC Endpoint Restrictions (If EC2 Is In a VPC)

If your EC2 instance is running in a VPC with an S3 VPC endpoint, the endpoint's policy might be blocking access:

  • Verify the endpoint policy: Run aws ec2 describe-vpc-endpoints --vpc-endpoint-ids YOUR-ENDPOINT-ID and check the PolicyDocument field. Ensure it allows access to test-bucket.
  • Check routing configuration: Confirm your VPC's route table has an entry pointing to the S3 endpoint for the com.amazonaws.region.s3 service (replace region with your AWS region). Without this, traffic might be routing over the public internet, leading to unexpected permission issues.

5. Object-Level ACL Conflicts

If you're trying to access specific objects in the bucket, check their individual ACLs:

  • By default, objects inherit the bucket's private permissions, but if you uploaded objects manually (not via CloudFormation), they might have custom ACLs. Run aws s3api get-object-acl --bucket test-bucket --key YOUR-OBJECT-KEY to verify.

Step-by-Step Debugging Command

To get granular details about why your request is failing, run this on your EC2 instance:

aws s3 ls s3://test-bucket --debug

The debug output will show exactly which policy or permission is blocking your request—this is often the fastest way to pinpoint the issue.

内容的提问来源于stack exchange,提问作者Noam Mansur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:54:43