在OAC的存储桶策略中明确允许CloudFront访问该桶。您可以通过以下步骤解决此问题:
{
"Version":"2012-10-17",
"Statement":[{
"Sid":"AddPerm",
"Effect":"Allow",
"Principal":{
"AWS":"arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity YOUR_CF_DISTRIBUTION_ID"
},
"Action":["s3:GetObject"],
"Resource":["arn:aws:s3:::YOUR_BUCKET_NAME/*"]
}]
}