0Pricing
AWS for Backend Developers (EC2, S3, RDS, Lambda) · Aula

Protegendo o acesso aos dados do S3

Configure o controle de acesso a buckets e objetos do S3 usando políticas de bucket, ACLs e URLs pré-assinadas.

Protegendo o acesso aos dados do S3 é uma aula grátis de AWS for Backend Developers (EC2, S3, RDS, Lambda) no CoddyKit. Esta é a aula 3 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de AWS for Backend Developers (EC2, S3, RDS, Lambda), e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de AWS for Backend Developers (EC2, S3, RDS, Lambda) inclui 4 aulas no total.

Partes desta aula ainda não foram traduzidas e aparecem em inglês.

S3 Security: Why It Matters

Amazon S3 is a highly durable and available storage service, but securing your data is paramount. Misconfigured S3 buckets can expose sensitive information to the public internet.

In this lesson, we'll explore key mechanisms AWS provides to control who can access your S3 data.

Access Control Basics in S3

S3 uses several layers to manage access:

  • Bucket Policies: JSON-based policies applied to a bucket.
  • Access Control Lists (ACLs): Legacy, finer-grained permissions on buckets and objects.
  • Pre-signed URLs: Temporary, time-limited access to specific objects.

Understanding these helps you implement the principle of least privilege.

Understanding Bucket Policies

A Bucket Policy is a resource-based policy written in JSON. It defines permissions for actions on a bucket and its objects.

These policies are powerful because they can grant or deny access to specific AWS accounts, IAM users, roles, or even anonymous users.

Anatomy of a Bucket Policy

Bucket policies consist of statements with these main elements:

  • Effect: Allow or Deny.
  • Principal: Who is allowed or denied (e.g., an IAM user ARN).
  • Action: What actions are allowed (e.g., s3:GetObject, s3:PutObject).
  • Resource: On which resource the action is allowed (e.g., arn:aws:s3:::your-bucket/*).

Bucket Policy Example: Read-Only

Here's a policy that grants an IAM user (arn:aws:iam::123456789012:user/DevUser) read-only access to all objects in my-example-bucket.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789012:user/DevUser"
      },
      "Action": [
        "s3:GetObject",
        "s3:GetObjectVersion"
      ],
      "Resource": "arn:aws:s3:::my-example-bucket/*"
    }
  ]
}

Introduction to S3 ACLs

Access Control Lists (ACLs) are a legacy access control mechanism that predates bucket policies. They grant specific permissions (READ, WRITE, FULL_CONTROL) to other AWS accounts or predefined S3 groups.

ACLs are typically used for cross-account access or when an object is owned by a different account than the bucket.

ACL vs. Bucket Policy

While both control access, Bucket Policies are generally preferred for their flexibility and centralized management. They allow complex conditions and fine-grained permissions.

ACLs are simpler and are primarily used for granting basic read/write access to individual objects or when ownership of objects differs from the bucket owner (e.g., when objects are uploaded by another account).

What are Pre-signed URLs?

A Pre-signed URL gives temporary, time-limited access to a specific S3 object. An authorized user (or application with appropriate credentials) generates this URL.

It's perfect for scenarios like securely sharing a private file for a few minutes or allowing a user to upload a file directly to S3 without exposing your AWS credentials.

Generate a Pre-signed URL

Here's a Python example using the boto3 library to create a pre-signed URL for downloading an object. The URL will be valid for 3600 seconds (1 hour).

import boto3

def create_presigned_url(bucket_name, object_name, expiration=3600):
    s3_client = boto3.client('s3')
    try:
        response = s3_client.generate_presigned_url('get_object',
                                                    Params={'Bucket': bucket_name,
                                                            'Key': object_name},
                                                    ExpiresIn=expiration)
    except Exception as e:
        print(f"Error generating presigned URL: {e}")
        return None
    return response

if __name__ == '__main__':
    # Replace with your bucket and object details
    my_bucket = "your-unique-bucket-name"
    my_object = "my-secret-document.pdf"

    url = create_presigned_url(my_bucket, my_object)
    if url:
        print(f"Pre-signed URL for {my_object}:")
        print(url)
    else:
        print("Failed to generate URL.")

Quick Check

Which S3 access control method is generally preferred for comprehensive, centralized permissions on a bucket and its objects?

Recap: Securing S3 Data

We covered three key ways to secure your S3 data:

  • Bucket Policies: Powerful, JSON-based rules for comprehensive bucket-level access control.
  • ACLs: Legacy, object-level permissions for specific scenarios like cross-account uploads.
  • Pre-signed URLs: Temporary, time-limited access to individual objects, perfect for sharing or direct uploads.

Always apply the principle of least privilege when securing your S3 resources!

Perguntas Frequentes

A aula “Protegendo o acesso aos dados do S3” é grátis?

Sim — o texto completo de “Protegendo o acesso aos dados do S3” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de AWS for Backend Developers (EC2, S3, RDS, Lambda), atualize para CoddyKit PRO. O curso de AWS for Backend Developers (EC2, S3, RDS, Lambda) inclui 4 aulas no total.

O que vou aprender em “Protegendo o acesso aos dados do S3”?

Configure o controle de acesso a buckets e objetos do S3 usando políticas de bucket, ACLs e URLs pré-assinadas. Você pratica AWS for Backend Developers (EC2, S3, RDS, Lambda) com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.

Preciso ter experiência prévia para começar AWS for Backend Developers (EC2, S3, RDS, Lambda)?

Nenhuma experiência prévia é necessária. AWS for Backend Developers (EC2, S3, RDS, Lambda) no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 3 de 4.

Quanto tempo leva a aula “Protegendo o acesso aos dados do S3”?

A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.

Posso escrever e executar código nesta aula de AWS for Backend Developers (EC2, S3, RDS, Lambda)?

Sim. Cada aula de AWS for Backend Developers (EC2, S3, RDS, Lambda) inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.

Todas as aulas deste curso

  1. Buckets e objetos do S3 explicados
  2. Versionamento e políticas de ciclo de vida do S3
  3. Protegendo o acesso aos dados do S3
  4. Hospedando sites estáticos e entrega por CDN
← Voltar para AWS for Backend Developers (EC2, S3, RDS, Lambda)