Replies: 1 comment
|
Why this happens: By default, boto3 uses the global S3 endpoint ( Option 1 (recommended): import boto3
from botocore.config import Config
s3 = boto3.client(
's3',
region_name='us-east-1',
config=Config(s3={'addressing_style': 'virtual'})
)
url = s3.generate_presigned_url('get_object', Params={'Bucket': 'mybucket', 'Key': 'mykey'}, ExpiresIn=3600)This forces boto3 to build the URL as Option 2: Explicit s3 = boto3.client(
's3',
region_name='us-east-1',
endpoint_url='https://s3.us-east-1.amazonaws.com'
)This is the most explicit option — you're telling boto3 to use the regional endpoint directly. The generated presigned URL will use that endpoint and won't redirect. Both options are stable. |
Uh oh!
There was an error while loading. Please reload this page.
Hi,
I'm using boto3 v1.42.70 to generate a presigned url for S3
get_objectwithin a lambda function. The boto3 client is initialised with the correct region.I turned on debug logging in boto and I can see that the host in the signing data is set to the global mybucket.s3.amazonaws.com. The presigned url that is generated is also a global s3 url.
But when I hit that url, I get a 307 redirect to the regional endpoint, which then fails signature validation as the hosts are now different and create a different signature.
I've seen various posts/comments online about setting the
addressing_style: "virtual"in the s3 config block on the client - and yes, that appears to have resolved the issue - the host in the signing data is regional and the presigned url is regional - no redirects.But the boto3 code that uses addressing_style in https://github.com/boto/botocore/blob/develop/botocore/signers.py#L982 is internal logic and could change at some point.
Is there a better way to overcome this issue, or is using the addressing_style the ultimate solution?
Many thanks.
All reactions