使用YAML配置AWS S3桶遇异常:未生成指定名称且静态访问出错
Let's break down your two main issues and walk through the fixes step by step:
1. Why your bucket name became cf-templates-xxxx instead of sayit
AWS S3 bucket names are globally unique across all AWS accounts and regions. If the name sayit is already taken by another user in your target region, CloudFormation can't create a bucket with that exact name. Wait, normally this would throw an error—but if your deployment succeeded with a generated name, it might mean you accidentally modified the template during deployment, or the name was already claimed.
Fix steps:
- First, check if
sayitis available: Run this AWS CLI command (adjust the region if needed):aws s3api head-bucket --bucket sayit --region us-east-1- If you get a
404 Not Foundresponse: The name is available. Re-deploy your template and double-check that no parameters are overriding theBucketNamevalue. - If you get
403 Forbiddenor200 OK: The name is taken. Pick a unique alternative (likesayit-westonsapusek-2024or append a random string) and update theBucketNameproperty in your template. - Alternatively, remove the
BucketNameproperty entirely: CloudFormation will generate a unique name automatically, and you can add anOutputssection to retrieve the bucket name later.
- If you get a
2. Fixing Static Website Hosting Access Errors
Your original template uses AccessControl: PublicRead, but modern AWS S3 has Block Public Access (BPA) settings enabled by default at both account and bucket levels. Even with PublicRead, these settings block public access. Plus, the AccessControl property is legacy—AWS recommends using bucket policies instead.
Updated Template with Full Fixes
Here's a revised version of your template that resolves both issues:
Resources: S3Bucket: Type: AWS::S3::Bucket Properties: BucketName: sayit-yourunique-suffix # Replace with your unique bucket name WebsiteConfiguration: IndexDocument: Suffix: voice-label.html # Corrected format: uses "Suffix" key DeletionPolicy: Retain S3BucketPolicy: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref S3Bucket PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: "*" Action: "s3:GetObject" Resource: !Sub "${S3Bucket.Arn}/*" Outputs: WebsiteURL: Value: !GetAtt S3Bucket.WebsiteURL Description: URL for your S3 static website
Key Improvements:
- Fixed WebsiteConfiguration: The
IndexDocumentrequires aSuffixkey (your original template missed this, which likely caused the endpoint misbehavior). - Replaced Legacy Access Control: Uses a bucket policy to explicitly grant public read access to bucket objects, which is the modern AWS-recommended approach.
- Added Outputs: Makes it easy to grab your website URL right after deployment.
- Cleaned Up DeletionPolicy: Moved it inside the S3Bucket resource for clearer association.
Final Checks:
- Go to your bucket in the AWS Console → Permissions → Block Public Access → Edit, and uncheck all boxes (required for public website access).
- Upload your
voice-label.htmlfile to the bucket, then use theWebsiteURLfrom CloudFormation outputs to test access.
内容的提问来源于stack exchange,提问作者Weston Sapusek

