AWS Ruby SDK中put_object与upload_file的权限差异及跨桶上传问题
put_object vs upload_file Permission Differences Great question! I’ve run into this exact scenario before, so let’s break down why put_object works but upload_file fails when uploading to another user’s bucket with limited write permissions.
Core Difference in How They Work
The key lies in what API calls each method triggers under the hood:
put_object: This is a direct wrapper for the S3PutObjectAPI. It sends a single request to upload your file (assuming it’s small enough to fit in one request). For this to succeed, your IAM identity only needs thes3:PutObjectpermission on the target bucket/object path.upload_file: This is a higher-level convenience method. It automatically handles large files by splitting them into chunks and using S3’s Multipart Upload feature. That means it makes multiple API calls:CreateMultipartUploadto initialize the uploadUploadPartfor each file chunkCompleteMultipartUploadto finalize the upload- (Optional)
AbortMultipartUploadto clean up if the upload fails
Why upload_file Fails for You
If your IAM policy only grants s3:PutObject, you’re missing the permissions required for the Multipart Upload workflow. upload_file needs all of these additional permissions to work properly:
s3:CreateMultipartUploads3:UploadParts3:CompleteMultipartUploads3:AbortMultipartUpload(recommended to avoid leftover incomplete uploads)
Fixes to Get upload_file Working
Update Your IAM Policy
Add the necessary Multipart Upload permissions to your IAM identity’s policy. Here’s an example policy snippet:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:PutObject", "s3:CreateMultipartUpload", "s3:UploadPart", "s3:CompleteMultipartUpload", "s3:AbortMultipartUpload" ], "Resource": "arn:aws:s3:::YOUR_TARGET_BUCKET/*" } ] }Force Single-Part Upload (For Small Files)
If your file is smaller than the Ruby SDK’s default multipart threshold (15MB by default),upload_filewill use a singlePutObjectrequest just likeput_object—and it should work with your existings3:PutObjectpermission. You can even override the threshold manually if needed:s3_client.upload_file('local_file.txt', 'target_bucket', 'object_key', multipart_threshold: 30 * 1024 * 1024) # 30MB threshold
Quick Note on Bucket Policies
Don’t forget to check the target bucket’s bucket policy too! Even if your IAM policy has the right permissions, the bucket policy must explicitly allow these actions for your identity (or the role you’re using).
内容的提问来源于stack exchange,提问作者Zillah

