Granting public access to your Amazon S3 data
Amazon S3 provides multiple ways to grant public access to your data. You can grant public access through a bucket policy, through object tags combined with a bucket policy, or through object access control lists (ACLs). The mechanism you use depends on your goal. For example, to make an entire bucket publicly accessible, you can use a bucket policy. To make only specific objects accessible, you can add a tag to those objects and make them public with a bucket policy.
By default, Amazon S3 blocks public access. New buckets have Block Public Access turned on and have Object Ownership set to Bucket owner enforced, which disables ACLs. Before any object in a bucket can be publicly accessible, you must turn off the Block Public Access settings for the bucket and the account. For more information, see Blocking public access to your Amazon S3 storage.
If you want to grant temporary access to a single object, you can use a presigned URL. A presigned URL gives limited time access to a single object, and you can control how long the URL remains valid by setting its expiration time. For more information, see Sharing objects with presigned URLs.
Important
When you turn off Block Public Access and grant public access, anyone on the internet can access your objects. Grant public access only when a specific use case requires it.
Topics
Granting public access to an entire bucket
You can grant public access to an entire bucket with a bucket policy. This is useful when all the objects that you want to make public can be stored together, such as the files for a static website. Store those objects in a bucket that holds only public content, and keep private data in a separate bucket. We recommend this approach because it keeps a clear boundary between public and private data.
To make the objects in a bucket publicly readable, turn off Block Public Access for the
bucket and add a bucket policy that grants everyone the s3:GetObject
permission.
Example
The following bucket policy grants public read access to every object in the bucket.
{ "Version": "2012-10-17", "Statement": [ { "Sid": "PublicReadGetObject", "Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::amzn-s3-demo-bucket/*" } ] }
Granting public access to specific objects with object tags
You can grant public access to specific objects in a bucket by applying an object tag to them and adding a bucket policy that grants read access to any object with that tag. We recommend this approach when you must keep both private and public objects in the same bucket.
With object tags, a single condition in the bucket policy matches every object that has the tag, so one statement can make a large number of objects public. This approach avoids listing individual object keys in the policy, which can contain characters that a policy does not accept and can exceed the bucket policy size limit.
To grant public access to specific objects, turn off Block Public Access for the
bucket, apply an object tag such as public=true to each object that you want
to make public, and add a bucket policy that grants s3:GetObject to objects
with that tag. For more information about tagging objects, see Tagging your objects.
Note
Object tags incur additional charges, both to apply them and to store them. For
more information, see Amazon S3 pricing
Example
The following bucket policy grants public read access to every object that has the
public=true tag.
{ "Version": "2012-10-17", "Statement": [ { "Sid": "PublicReadTaggedObjects", "Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::amzn-s3-demo-bucket/*", "Condition": { "StringEquals": { "s3:ExistingObjectTag/public": "true" } } } ] }
Granting public access to an individual object with an ACL
Object ACLs are a legacy way to grant access, and new buckets disable them by default. We recommend that you keep ACLs disabled, and use Amazon S3 resource-based policies (bucket policies and access point policies) or IAM policies instead, unless you must control access for each object individually. Policies provide simpler and more flexible access control. For more information, see Controlling ownership of objects and disabling ACLs for your bucket.
Important
Enabling ACLs applies to the entire bucket, not only the object that you make public. After ACLs are enabled, another account that uploads an object can own it, so you might not control every object in your bucket.
To make an object public with an ACL, turn off Block Public Access for the bucket and
enable ACLs by changing the Object Ownership setting from Bucket owner enforced to Bucket
owner preferred. Then apply the public-read ACL to the object, which grants
read access to everyone, so anyone can read the object. For more information, see Managing access with ACLs.