I want to access an object on an S3 bucket that was created by antoher user:
$ aws s3 cp s3://awsexamplebucket1/pathname/filename .
fatal error: An error occurred (403) when calling the HeadObject operation: Forbidden
I can actually list the file:
$ aws s3 ls s3://awsexamplebucket1/pathname/
2021-11-09 03:47:16 0 _SUCCESS
2021-11-09 03:47:16 1234 filename
The permission policy of my iam role on this bucket:
{
"Version":"2012-10-17",
"Statement":[
{
"Effect":"Allow",
"Principal": {
"AWS": [
"arn:aws:iam::123456789:role/my-role"
]
},
"Action":[
"s3:PutObject",
"s3:PutObjectAcl",
"s3:GetObject",
"s3:GetObjectAcl",
"s3:DeleteObject",
"s3:ListBucket",
],
"Resource": [
"arn:aws:s3:::awsexamplebucket1",
"arn:aws:s3:::awsexamplebucket1/*"
}
]
}
I can write and read other files on this bucket.
Following this doc I try to change the ACL from the other account:
aws s3api put-object-acl --bucket awsexamplebucket1 --key pathname/filename --acl bucket-owner-full-control
But the issue is not resolved