You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

S3 Bucket上传文件遇Access Denied,是否需添加加密参数?

Answer

Absolutely—you do need to add encryption parameters to your upload request. Let me break down why and how to resolve this access denied error:

Why the error happens

The Bucket policy you shared explicitly denies all s3:PutObject requests that don't specify server-side encryption using either AES256 (S3-managed encryption) or AWS KMS. Here's the key part of the policy to focus on:

"Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": [ "AES256", "aws:kms" ] } }

This means any upload without the required encryption header gets blocked immediately. Your ability to list Bucket contents works because s3:ListBucket isn't restricted by this policy.

How to fix the upload

You'll need to include encryption flags/parameters in your upload command or code, depending on the tool you're using:

AWS CLI Example

  • Using S3-managed AES256 encryption:

    aws s3 cp your-test-file.txt s3://<bucketname>/your-test-file.txt --profile your-profile --server-side-encryption AES256
    
  • Using AWS KMS encryption (requires a KMS key ID/ARN, and your profile needs permissions to use the key):

    aws s3 cp your-test-file.txt s3://<bucketname>/your-test-file.txt --profile your-profile --server-side-encryption aws:kms --ssekms-key-id 1234abcd-12ab-34cd-56ef-1234567890ab
    

AWS SDK Example (Python boto3)

  • AES256 encryption:

    import boto3
    
    s3_client = boto3.client('s3', profile_name='your-profile')
    s3_client.upload_file(
        'your-test-file.txt',
        '<bucketname>',
        'your-test-file.txt',
        ExtraArgs={'ServerSideEncryption': 'AES256'}
    )
    
  • KMS encryption:

    import boto3
    
    s3_client = boto3.client('s3', profile_name='your-profile')
    s3_client.upload_file(
        'your-test-file.txt',
        '<bucketname>',
        'your-test-file.txt',
        ExtraArgs={
            'ServerSideEncryption': 'aws:kms',
            'SSEKMSKeyId': '1234abcd-12ab-34cd-56ef-1234567890ab'
        }
    )
    

Important Note

If you choose KMS encryption, make sure the IAM identity associated with your profile has permissions to interact with the specified KMS key (specifically kms:GenerateDataKey and kms:Decrypt). Without these, you might hit another access denied error even after adding the encryption parameters.

内容的提问来源于stack exchange,提问作者Punter Vicky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 04:23:33