Write down the exact request
Reading an object requires an object-level action and resource. Listing a bucket is a different operation. An allow on arn:aws:s3:::lesson-assets does not by itself cover reading arn:aws:s3:::lesson-assets/index.html. Conversely, an object-only resource is not the bucket listing resource.
Identify whether the caller is a signed identity or anonymous website visitor. Switching between those paths changes the policies and controls involved. A successful console operation by root does not prove that a public reader or application role can access the same object.
Public website access is a separate case
The experiment models anonymous object access through a bucket policy. A supported public allow must cover the requested object. RestrictPublicBuckets can block public reads; BlockPublicPolicy rejects a public policy when it is submitted. Those settings do different jobs, so do not describe them as interchangeable switches.
Keeping an S3 origin private behind CloudFront uses a different configuration than a public S3 website endpoint. Decide which architecture you want before disabling controls. The local model does not implement CloudFront origin access control or KMS authorization.
Test denial before and after the repair
Use the controls below to change policy coverage and public-access restrictions. An explicit deny should win even when an allow also matches. A bucket-level resource should not grant an object read. Predict the result before running the request.
In the console lab, upload index.html, configure hosting, deliberately adjust public-access settings, attach the policy and test the simulated website request. The lab validates the request result, not a regular-expression match for words inside JSON.
Know the limits of a simplified evaluator
Real S3 authorization can involve identity and resource policies, Organizations controls, permissions boundaries, endpoint policies, object ownership and encryption. This educational model supports a documented subset. Unsupported policy constructs should fail visibly rather than imply that real AWS would allow them.
Use the official troubleshooting guide for a live account. Preserve the operation name, principal and target resource in your investigation; changing several policies at once removes the evidence explaining which one fixed the request.
Predict it. Test it. Change one thing.
Local educational model. No account or cloud charges. Nothing is deployed to AWS.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::lesson-assets/*"
}
]
}Assumes the object exists and the policy has already been stored. BlockPublicPolicy controls submission of public policies; RestrictPublicBuckets controls the public read modeled here. KMS, ACLs and endpoint policies are outside this model.
sim.shahriarlabs.com · Free to explore
Sources and scope
Reviewed against these official references. The model’s supported scope appears alongside its controls.
How we review explanations