AWS S3 Headobject operation: Forbidden

Viewed 783

I want to access an object on an S3 bucket that was created by antoher user:

$ aws s3 cp s3://awsexamplebucket1/pathname/filename .
fatal error: An error occurred (403) when calling the HeadObject operation: Forbidden

I can actually list the file:

$ aws s3 ls s3://awsexamplebucket1/pathname/
2021-11-09 03:47:16     0  _SUCCESS
2021-11-09 03:47:16  1234  filename

The permission policy of my iam role on this bucket:

{
   "Version":"2012-10-17",
   "Statement":[
      {
         "Effect":"Allow",
         "Principal": {
           "AWS": [
             "arn:aws:iam::123456789:role/my-role"
           ]
         },
         "Action":[
            "s3:PutObject",
            "s3:PutObjectAcl",
            "s3:GetObject",
            "s3:GetObjectAcl",
            "s3:DeleteObject",
            "s3:ListBucket",
         ],
         "Resource": [
             "arn:aws:s3:::awsexamplebucket1",
             "arn:aws:s3:::awsexamplebucket1/*"
      }
   ]
}

I can write and read other files on this bucket.

Following this doc I try to change the ACL from the other account:

aws s3api put-object-acl --bucket awsexamplebucket1 --key pathname/filename --acl bucket-owner-full-control

But the issue is not resolved

0 Answers
Related