Q: A team in AWS Account A is writing data to an S3 bucket in Account B. Account B explicitly grants them `s3:PutObject` in the bucket policy. However, when Account B administrators try to read the files, they get `Access Denied`. Why, and how is it fixed?
Historically, in S3, the AWS account that uploads the object retains explicit ownership and full control of that object, even if the buck...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
Historically, in S3, the AWS account that uploads the object retains explicit ownership and full control of that object, even if the bucket itself belongs to a different account. Because Account A uploaded the file, Account A owns it, and Account B (the bucket owner) is locked out unless Account A explicitly grants them read ACLs during the upload (--acl bucket-owner-full-control). *The Modern Fix:* In Account B, go to the S3 bucket settings and enable S3 Object Ownership: Bucket owner enforced. This entirely disables all legacy ACLs. The bucket owner (Account B) automatically and forcefully assumes ownership of every file uploaded to the bucket, instantly restoring their read access.
- Immediate Triage: Historically, in S3, the AWS account that uploads the object retains explicit ownership and ful
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.