Visitors must read objects anonymously, and Block Public Access stands in the way: four switches, all on for new buckets by default, two for ACLs and two for policies (BlockPublicPolicy refuses a public policy, RestrictPublicBuckets ignores one). The template relaxes only the policy pair and grants s3:GetObject alone:
PublicAccessBlockConfiguration:
BlockPublicAcls: true
IgnorePublicAcls: true
BlockPublicPolicy: false
RestrictPublicBuckets: false
FrontEndBucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref FrontEndBucket
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: PublicReadForWebsite
Effect: Allow
Principal: "*"
Action: s3:GetObject
Resource: !Sub ${FrontEndBucket.Arn}/*The resource ends in /*, the objects, so visitors can neither list keys nor write. Account-level Block Public Access overrides every bucket; with it on, AWS 24 rejects this policy with AccessDenied and the stack fails. cfn-guard's guard rule buckets_block_public_access fails here too, by design: public buckets should be reviewed exceptions.