使用Lambda函数读取S3 Bucket时出现Access Denied问题求助
Hey there, let's work through that AccessDenied error you're hitting when trying to read an S3 JSON file from your Lambda function. This is a super common issue, so here are the most likely fixes to check step by step:
1. Lambda Execution Role Missing S3 Permissions
This is the #1 culprit. Your Lambda's execution role needs explicit permission to run s3:GetObject on your target bucket (test-dev-cognito-settings-us-west-2).
To fix this:
- Head to the IAM Console, find your Lambda's execution role.
- Attach a custom policy like this (replace the resource ARN with your bucket's path):
The{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::test-dev-cognito-settings-us-west-2/*" } ] }/*at the end ensures you can access all objects in the bucket—you can narrow it down to a specific JSON file path if you know it.
2. S3 Bucket Policy Blocking Access
Sometimes the bucket itself has a policy that overrides your Lambda's permissions. Check your bucket's policy:
- Make sure there are no
Denystatements that target your Lambda role or the account it belongs to. - If needed, add an explicit allow statement for your Lambda role:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::YOUR_ACCOUNT_ID:role/your-lambda-execution-role-name" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::test-dev-cognito-settings-us-west-2/*" } ] }
3. Object Ownership or ACL Issues
If the JSON file was uploaded by another AWS account, the bucket owner might not have full access to it:
- Enable Bucket owner preferred in your S3 bucket settings (under Permissions > Object Ownership). This ensures the bucket owner gets full control over objects uploaded by external accounts.
- Alternatively, check the object's ACL and make sure it grants read access to your Lambda's execution role.
4. VPC Endpoint Configuration (If Lambda is in a VPC)
If your Lambda is running inside a VPC, it can't reach S3 by default unless you set up an S3 VPC endpoint:
- Create a Gateway or Interface endpoint for S3 in your VPC.
- Update your VPC's route tables to route S3 traffic to this endpoint.
- Ensure the endpoint's policy allows
s3:GetObjectfor your Lambda role.
5. Typos in Bucket/Object Path
Double-check your code for typos! S3 bucket names are case-sensitive (and must be lowercase), so confirm the bucket name in your code exactly matches test-dev-cognito-settings-us-west-2. Also verify the object key (file path) is correct.
Add some logging to your Lambda to confirm what you're trying to access:
import boto3 import logging def trigger_handler(event, context): logger = logging.getLogger() logger.setLevel(logging.INFO) s3 = boto3.resource('s3') bucket_name = 'test-dev-cognito-settings-us-west-2' object_key = 'path/to/your/target.json' # Replace with your actual file path logger.info(f"Attempting to access bucket: {bucket_name}, object: {object_key}") try: obj = s3.Object(bucket_name, object_key) json_content = obj.get()['Body'].read().decode('utf-8') logger.info("Successfully retrieved JSON content") # Process your JSON here except Exception as e: logger.error(f"Failed to access S3: {str(e)}") raise
If none of these fix it, check AWS CloudTrail for the specific AccessDenied event—it will show exactly which policy or permission is blocking the request.
内容的提问来源于stack exchange,提问作者Jayesh Dhandha

