如何更新 aws IAM 权限以允许更新存储桶策略

Sy3*_*y3d 1 amazon-s3 amazon-web-services

我创建了一个 aws s3 存储桶,我想在其中存储图像。我创建了一个获取预签名 url 的快速 API 路由。通过我的 Vue 应用程序,我使用预先签名的 url 将图像发布到 s3 存储桶。图像被很好地上传到存储桶中。

我现在想通过生成的 url 查看 s3 存储桶中的图像,但我收到 XML 格式的 AccessDenied。要解决此问题,我需要更新存储桶策略,但我无法执行此操作,因为当我尝试时,我得到:

You don't have permissions to edit bucket policy
After you or your AWS administrator have updated your permissions to allow the s3:PutBucketPolicy action, choose Save changes.
Learn more about Identity and access management in Amazon S3
Run Code Online (Sandbox Code Playgroud)

我对 aws 相当陌生,如何更新当前策略以添加s3:PutBucketPolicy。我找不到添加该政策的选项。

小智 5

我遇到了同样的问题,我的根用户也无法编辑策略。对我有用的是(i)将存储桶可访问性从私有更改为公共,(ii)然后我能够以 root 用户身份更改“编辑”s3 存储桶的策略(但没有尝试以 IAM 身份),( iii) 将存储桶恢复为私有。

我找到了这个指南,它没有帮助 - 但它可能对未来的其他问题有用: https://aws.amazon.com/premiumsupport/knowledge-center/s3-access-denied-bucket-policy/