# Create an S3 Bucket for File Uploads: Lambda to S3 Access Denied

**URL:** <https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874>\
**Category:** Chapter Comments\
**Created:** [March 11, 2019, 9:23pm UTC](https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874 "2019-03-11T21:23:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dehallman](https://avatars.discourse-cdn.com/v4/letter/d/b5a626/32.png) [@dehallman](https://discourse.sst.dev/u/dehallman)\
**Post date:** [March 11, 2019, 9:23pm UTC](https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874/1 "2019-03-11T21:23:27Z")

</div>

I followed the Basic 1 section and got everything running fine. I wanted to enhance it somewhat for something I’m doing and part of that included reading the file that was uploaded to s3 from within a Lambda function. When I run the function through “serverless invoke local” it works just fine, finds the s3 file and able to read it. When I deploy the Lambda function through “serverless deploy” and run it, it gives me an “Access denied” trying to read the S3 bucket. I know the full key name is correct. My permissions on the IAM role are the same as in the Basic 1 guide.

Has anybody tried to read those private files in the S3 bucket?  
Am I missing something simple?

---

<div class="post-metadata">

**Author:** ![dehallman](https://avatars.discourse-cdn.com/v4/letter/d/b5a626/32.png) [@dehallman](https://discourse.sst.dev/u/dehallman)\
**Post date:** [March 11, 2019, 9:40pm UTC](https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874/2 "2019-03-11T21:40:29Z")

</div>

Disregard. I think I just figured it out. It looks like I had not wild-carded my permissions for the s3 bucket in the yaml iamRoleStatements section:

```auto
  iamRoleStatements:
    - Effect: Allow
      Action:
        - s3:getObject
        - s3:putObject
      Resource: "arn:aws:s3::*:*"

```

---

<div class="post-metadata">

**Author:** ![dehallman](https://avatars.discourse-cdn.com/v4/letter/d/b5a626/32.png) [@dehallman](https://discourse.sst.dev/u/dehallman)\
**Post date:** [March 11, 2019, 9:53pm UTC](https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874/3 "2019-03-11T21:53:49Z")

</div>

Clarifying:

```auto
 iamRoleStatements:
    - Effect: Allow
      Action:
        - s3:getObject
        - s3:putObject
      Resource: "arn:aws:s3:::<my-bucket>/*"

```

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [March 12, 2019, 9:39pm UTC](https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874/4 "2019-03-12T21:39:46Z")

</div>

Glad you figured it out. Thanks for reporting back.

---

<div class="post-metadata">

**Author:** ![robmoores](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/robmoores/32/1121_2.png) [@robmoores](https://discourse.sst.dev/u/robmoores)\
**Post date:** [February 2, 2021, 1:31am UTC](https://discourse.sst.dev/t/create-an-s3-bucket-for-file-uploads-lambda-to-s3-access-denied/874/5 "2021-02-02T01:31:31Z")

</div>

What worked for me was adding a bucket policy to the S3 notes bucket as follows (and I need to tighten up the Principal !):

```json
{
    "Version": "2012-10-17",
    "Id": "Policy1612228858328",
    "Statement": [
        {
            "Sid": "Stmt1612228855942",
            "Effect": "Allow",
            "Principal": "*",
            "Action": "s3:PutObject",
            "Resource": "arn:aws:s3:::notes-app-xxxxxxx/*"
        }
    ]
}

```
