如何延长AWS S3通过getSignedUrl生成链接的过期时间?永久访问方案咨询
Hey there, let's tackle your two AWS S3 presigned URL questions one by one:
When generating a presigned URL with getSignedUrl (or generate_presigned_url in boto3), you control the expiration using a time-based parameter—this varies slightly by SDK, but the core idea is the same.
First, know the hard limit: AWS restricts presigned URLs to a maximum expiration time of 7 days (604800 seconds). Any value beyond this will throw an error. To set the longest allowed expiration, just pass that value to the expiration parameter.
Here's an example using Python's boto3:
import boto3 s3_client = boto3.client('s3') presigned_url = s3_client.generate_presigned_url( 'get_object', Params={'Bucket': 'your-bucket-name', 'Key': 'your-object-key'}, ExpiresIn=604800 # 7 days in seconds )
If you need access longer than 7 days, a presigned URL isn't the right tool—you'll want to use the permanent access method below, or consider CloudFront signed URLs (which can have longer expiration windows, though still not truly permanent).
Presigned URLs are inherently temporary, so to get a permanent, always-accessible link, you need to configure your S3 object (or bucket) to allow public read access. Here are two common ways to do this:
Option 1: Set public-read ACL on individual objects
You can update the Access Control List (ACL) of a specific object to grant read access to everyone. Using boto3:
s3_client.put_object_acl( Bucket='your-bucket-name', Key='your-object-key', ACL='public-read' )
Once set, you can access the object directly with a static URL like:https://your-bucket-name.s3.amazonaws.com/your-object-key
(Note: Adjust the domain if you're using a non-standard region or S3 Transfer Acceleration.)
Option 2: Use a bucket policy for bulk public access
If you want all objects (or objects under a specific prefix) in your bucket to be publicly accessible, use a bucket policy instead. Here's a policy that allows anyone to get objects in your bucket:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::your-bucket-name/*" } ] }
You can apply this policy via the AWS Console, CLI, or SDK.
⚠️ Important note: Publicly accessible objects are visible to anyone on the internet. Only use this for content you're comfortable sharing widely—never for sensitive data.
内容的提问来源于stack exchange,提问作者Prasad Vivek

