You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Ruby SDK中put_object与upload_file的权限差异及跨桶上传问题

AWS Ruby SDK: put_object vs upload_file Permission Differences

Great question! I’ve run into this exact scenario before, so let’s break down why put_object works but upload_file fails when uploading to another user’s bucket with limited write permissions.

Core Difference in How They Work

The key lies in what API calls each method triggers under the hood:

  • put_object: This is a direct wrapper for the S3 PutObject API. It sends a single request to upload your file (assuming it’s small enough to fit in one request). For this to succeed, your IAM identity only needs the s3:PutObject permission on the target bucket/object path.

  • upload_file: This is a higher-level convenience method. It automatically handles large files by splitting them into chunks and using S3’s Multipart Upload feature. That means it makes multiple API calls:

    1. CreateMultipartUpload to initialize the upload
    2. UploadPart for each file chunk
    3. CompleteMultipartUpload to finalize the upload
    4. (Optional) AbortMultipartUpload to clean up if the upload fails

Why upload_file Fails for You

If your IAM policy only grants s3:PutObject, you’re missing the permissions required for the Multipart Upload workflow. upload_file needs all of these additional permissions to work properly:

  • s3:CreateMultipartUpload
  • s3:UploadPart
  • s3:CompleteMultipartUpload
  • s3:AbortMultipartUpload (recommended to avoid leftover incomplete uploads)

Fixes to Get upload_file Working

  1. Update Your IAM Policy
    Add the necessary Multipart Upload permissions to your IAM identity’s policy. Here’s an example policy snippet:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "s3:PutObject",
            "s3:CreateMultipartUpload",
            "s3:UploadPart",
            "s3:CompleteMultipartUpload",
            "s3:AbortMultipartUpload"
          ],
          "Resource": "arn:aws:s3:::YOUR_TARGET_BUCKET/*"
        }
      ]
    }
    
  2. Force Single-Part Upload (For Small Files)
    If your file is smaller than the Ruby SDK’s default multipart threshold (15MB by default), upload_file will use a single PutObject request just like put_object—and it should work with your existing s3:PutObject permission. You can even override the threshold manually if needed:

    s3_client.upload_file('local_file.txt', 'target_bucket', 'object_key', multipart_threshold: 30 * 1024 * 1024) # 30MB threshold
    

Quick Note on Bucket Policies

Don’t forget to check the target bucket’s bucket policy too! Even if your IAM policy has the right permissions, the bucket policy must explicitly allow these actions for your identity (or the role you’re using).

内容的提问来源于stack exchange,提问作者Zillah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:00:39