Skip to content

Create the website bucket

An S3 bucket configured as a public static website for the React app.

About 15 min · Verified 8 October 2026

0 of 6 steps done0%

The frontend is a set of static files (HTML, JavaScript, CSS). S3 static website hosting serves them directly with no server to run. The bucket must be publicly readable, so you will deliberately relax one of S3's safety defaults, for this bucket only.

You create the bucket now, before the server, because the API needs to know the website's address (its CORS origin) and the address is derived from the bucket name.

Create the bucket#

Open the wizard#

Open S3BucketsCreate bucket.

FieldValue
Bucket typeGeneral purpose
AWS Regionyour Region, ap-south-1
Bucket name<WEB_BUCKET>
Object OwnershipACLs disabled (recommended)

Allow public policies, but not ACLs#

Under Block Public Access settings for this bucket:

  1. Untick Block all public access.
  2. Tick the orange acknowledgement box.
  3. In the four checkboxes that appear, make them look like this:
SettingState
Block public access granted through new ACLsticked
Block public access granted through any ACLsticked
Block public access granted through new public bucket or access point policiesunticked
Block public access granted through any public bucket or access point policiesunticked

Only bucket policies may grant public read. ACLs stay blocked, which is the narrowest setting that works.

Versioning and encryption#

FieldValue
Bucket VersioningEnable (lets you recover overwritten files)
Default encryptionSSE-S3 (the default)

Choose Create bucket.

Turn on website hosting#

Enable static website hosting#

Open the bucket → Properties → scroll to Static website hosting → Edit.

FieldValue
Static website hostingEnable
Hosting typeHost a static website
Index documentindex.html
Error documentindex.html

Save changes. At the bottom of Properties, Bucket website endpoint now shows a URL. It must match the website URL that My values works out for you:

<WEB_URL>

Add the public-read bucket policy#

Open Permissions → Bucket policy → Edit, paste the policy below, and save.

Paste in the AWS consoleBucket policy
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "PublicReadStaticAssets",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::<WEB_BUCKET>/*"
    }
  ]
}

Replace <WEB_BUCKET> with your own value (or fill in the known ones once under My values at the top of the page).

It grants one action, s3:GetObject (download a file), to everyone, on the objects of this one bucket. Nobody can list, upload or delete.

You should see
The console shows a red Publicly accessible badge next to the bucket's name. For a website bucket that is correct.

Verify#

The bucket is empty, so the site has nothing to serve yet. The right answer at this point is a not found page, not an access error.

Your computerAsk for the (still missing) home page
curl -sI <WEB_URL>/ | head -n 1

Replace <WEB_URL> with your own value (or fill in the known ones once under My values at the top of the page).

Expected output
HTTP/1.1 404 Not Found
  • 404 means the website endpoint works and the policy is fine. You will upload the app soon.
  • 403 Forbidden means public read is blocked: re-check the two unticked boxes and the policy.
Saving the bucket policy says 'Access denied' or 'blocked by Block Public Access'

Your account or organisation has account-level Block Public Access turned on, which overrides the bucket setting. Open S3Block Public Access settings for this account. If you own the account you can relax Block public access to buckets and objects granted through new public bucket or access point policies there. If your organisation controls it, ask the administrator; this guide cannot work around it.

Next: launch the API server.

Found a mistake? Edit this page on GitHub.