How to Make an S3 Bucket Public

Making a bucket public allows its contents to be accessed by anyone with the URL, without requiring authentication. This is useful for serving static assets such as images, CSS, JavaScript files, etc. for a website.

Prerequisites

  • AWS CLI configured with the access credentials generated from your Fullhost client area and your S3-compatible endpoint
  • An existing bucket (create one with AWS S3 mb s3://your-bucket-name if needed)

Steps

1. Create a bucket policy allowing public read access

Save the following as /tmp/public-read-policy.json:

{
    "Version": "2012-10-17",
    "Statement": [
        {
        "Sid": "PublicReadGetObject",
        "Effect": "Allow",
        "Principal": "*",
        "Action": "s3:GetObject",
        "Resource": "arn:aws:s3:::your-bucket-name/*"
        }
    ]
}

2. Apply the policy

aws s3api put-bucket-policy \
--bucket your-bucket-name \
--policy file:///tmp/public-read-policy.json

3. Upload a file and verify public access

aws s3 cp /tmp/testfile.txt s3://your-bucket-name/testfile.txt
curl https://your-s3-endpoint/your-bucket-name/testfile.txt

A successful response confirms the file is publicly accessible.

Important Notes:

  • Any file uploaded to a public bucket is accessible to anyone who knows the URL
  • Bucket names are unique across the endpoint: your bucket name cannot be claimed by other users
  • Never make backup buckets public: keep separate buckets for public assets and private data
  • To revert, delete the bucket policy using the following command:
    aws s3api delete-bucket-policy -- bucket your-bucket-name
  • Deleting the bucket policy only revokes public access if no object-level ACLs were set. If individual files were made public via put-object-acl -- acl public-read, each file must also be reverted individually with put-object-acl --acl private
Was this answer helpful? 0 Users Found This Useful (0 Votes)