You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需将S3 Bucket设为公开,如何托管网站及含提交表单的index.html?

Host an index.html with Submission Form in a Non-Public AWS S3 Bucket

Got it, let's walk through how to get this set up properly, using the permission policy you provided. Here's a step-by-step breakdown tailored to your needs:

1. Prep Your Bucket & Files

First off, make sure your target bucket (in your example, test-2018) is created, and you haven't enabled public access for static website hosting—keep those public access blocks turned on to maintain the non-public requirement.

  • Upload your index.html file directly into the test/ prefix of the bucket (this matches the Resource path in your policy: arn:aws:s3:::test-2018/test/*).

2. Apply the Custom Bucket Policy

The policy you shared already locks down access to only your AWS root account via HTTPS, which is perfect for non-public access. Just a couple quick checks before applying:

  • Replace the xxxxxxxxx in the Principal ARN with your actual AWS account ID.
  • Head to your bucket's Permissions tab in the AWS Console, find the Bucket Policy section, paste this JSON, and save:
{ 
  "Version": "2008-10-17", 
  "Id": "permissionTohttps", 
  "Statement": [ 
    { 
      "Sid": "AddPerm", 
      "Effect": "Allow", 
      "Principal": { 
        "AWS": "arn:aws:iam::xxxxxxxxx:root" 
      }, 
      "Action": "s3:GetObject", 
      "Resource": "arn:aws:s3:::test-2018/test/*", 
      "Condition": { 
        "Bool": { 
          "aws:SecureTransport": "true" 
        } 
      } 
    } 
  ] 
}
  • Double-check that Block public access settings are fully enabled to avoid any accidental public access conflicts.

3. Access Your index.html (Non-Publicly)

Since the bucket isn't public, you can't just use a regular URL to load the page. Here are the most reliable ways to access it:

  • AWS CLI: Run this command to download and open the file (adjust for Windows if needed):
    aws s3 cp s3://test-2018/test/index.html - | xdg-open  # Linux/macOS
    
  • Pre-Signed URLs: Generate a time-limited, secure URL using the AWS SDK. For example, in Python:
    import boto3
    from botocore.config import Config
    
    s3_client = boto3.client('s3', config=Config(signature_version='s3v4'))
    presigned_url = s3_client.generate_presigned_url(
        'get_object',
        Params={'Bucket': 'test-2018', 'Key': 'test/index.html'},
        ExpiresIn=3600  # URL expires in 1 hour
    )
    print(presigned_url)
    
    Share this URL with authorized users, and they'll be able to load the page over HTTPS until it expires.
  • AWS Console: Navigate to the test/index.html file in your bucket, click the Open button—AWS will generate a temporary secure link for you to access the page.

4. Handle Form Submissions (Critical Note!)

S3 doesn't natively support processing form POST requests—it's only built for serving static files. So you'll need a backend to handle the form data. Here are two straightforward options:

  • Lambda + API Gateway:
    1. Create a Lambda function that accepts POST data, then stores it (e.g., in DynamoDB, another S3 bucket, or sends it via email).
    2. Set up an API Gateway REST API with a POST endpoint that forwards requests to your Lambda function.
    3. Update your index.html form's action attribute to point to your API Gateway endpoint, and set method="POST".
  • Amazon EventBridge Pipes (For S3 Storage):
    If you want to store form submissions directly as files in S3, you can use EventBridge Pipes to trigger processing when new objects are uploaded, but Lambda is still the more flexible choice for handling form data.

Just make sure your backend service (Lambda, etc.) has the necessary IAM permissions to process and store the form data.

5. Validate Everything

  • Test accessing your index.html via one of the methods above to confirm it loads over HTTPS.
  • Submit a test form entry to verify your backend is receiving and processing the data correctly.

内容的提问来源于stack exchange,提问作者Fafi Tauma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:54:01