September 30, 2026 · 6 min read
How to make an Amazon S3 bucket public
New S3 buckets block all public access, and ACLs are disabled by default, so the old "make public" button on each object no longer does anything. Public reads now come from a bucket policy.
Step 1: allow public bucket policies
- Open the bucket in the S3 console and go to the Permissions tab.
- Under Block public access (bucket settings), select Edit.
- Clear the two settings about bucket and access point policies. You can leave the two ACL settings on, because the policy doesn't use ACLs.
- Save and confirm.
If the setting is also on at the account level (Block Public Access settings for this account in the S3 sidebar), it wins over the bucket setting and has to allow policies too.
Step 2: add a public-read bucket policy
Still on Permissions, edit the Bucket policy and paste this, with your bucket name:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "PublicRead",
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::your-bucket/*"
}
]
}
This allows reading objects, not listing the bucket. To make only one folder public, narrow the resource, for example arn:aws:s3:::your-bucket/public/*.
With the AWS CLI, the same two steps are:
aws s3api put-public-access-block --bucket your-bucket \
--public-access-block-configuration \
BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=false,RestrictPublicBuckets=false
aws s3api put-bucket-policy --bucket your-bucket --policy file://policy.jsonStep 3: find the public URL
Objects are now available at the virtual-hosted URL:
https://your-bucket.s3.eu-central-1.amazonaws.com/2026/09/report.pdf
Use your bucket's region. If this address returns AccessDenied, the Block Public Access settings are still blocking the policy, or the policy's bucket name has a typo.
The safer alternative: CloudFront with a private bucket
If you'd rather not open the bucket itself, keep Block Public Access on and create a CloudFront distribution with the bucket as its origin and Origin access control (OAC). CloudFront shows you the bucket policy that lets only the distribution read objects. You get HTTPS on your own domain, caching, and a bucket that stays private. See custom domains for bucket links.
Common questions
Why doesn't "Make public using ACL" work anymore?
Since April 2023, new buckets have Object Ownership set to Bucket owner enforced, which disables ACLs. Public access has to come from a bucket policy or CloudFront.
Does a public bucket let people list my files?
Not with the policy above. It allows s3:GetObject only. Listing would need s3:ListBucket on the bucket itself, which you shouldn't grant publicly.
Will a public bucket increase my AWS bill?
You pay for requests and data transfer out when people download files. For heavily shared files, CloudFront or a provider without egress fees, such as Cloudflare R2, is usually cheaper.