Create the website bucket
An S3 bucket configured as a public static website for the React app.
About 15 min · Verified 8 October 2026
The frontend is a set of static files (HTML, JavaScript, CSS). S3 static website hosting serves them directly with no server to run. The bucket must be publicly readable, so you will deliberately relax one of S3's safety defaults, for this bucket only.
You create the bucket now, before the server, because the API needs to know the website's address (its CORS origin) and the address is derived from the bucket name.
Create the bucket#
Open the wizard#
Open S3BucketsCreate bucket.
| Field | Value |
|---|---|
| Bucket type | General purpose |
| AWS Region | your Region, ap-south-1 |
| Bucket name | <WEB_BUCKET> |
| Object Ownership | ACLs disabled (recommended) |
Allow public policies, but not ACLs#
Under Block Public Access settings for this bucket:
- Untick Block all public access.
- Tick the orange acknowledgement box.
- In the four checkboxes that appear, make them look like this:
| Setting | State |
|---|---|
| Block public access granted through new ACLs | ticked |
| Block public access granted through any ACLs | ticked |
| Block public access granted through new public bucket or access point policies | unticked |
| Block public access granted through any public bucket or access point policies | unticked |
Only bucket policies may grant public read. ACLs stay blocked, which is the narrowest setting that works.
Versioning and encryption#
| Field | Value |
|---|---|
| Bucket Versioning | Enable (lets you recover overwritten files) |
| Default encryption | SSE-S3 (the default) |
Choose Create bucket.
Turn on website hosting#
Enable static website hosting#
Open the bucket → Properties → scroll to Static website hosting → Edit.
| Field | Value |
|---|---|
| Static website hosting | Enable |
| Hosting type | Host a static website |
| Index document | index.html |
| Error document | index.html |
Save changes. At the bottom of Properties, Bucket website endpoint now shows a URL. It must match the website URL that My values works out for you:
<WEB_URL>Add the public-read bucket policy#
Open Permissions → Bucket policy → Edit, paste the policy below, and save.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "PublicReadStaticAssets",
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::<WEB_BUCKET>/*"
}
]
}Replace <WEB_BUCKET> with your own value (or fill in the known ones once under My values at the top of the page).
It grants one action, s3:GetObject (download a file), to everyone, on the objects of this one bucket. Nobody can list, upload or delete.
Verify#
The bucket is empty, so the site has nothing to serve yet. The right answer at this point is a not found page, not an access error.
curl -sI <WEB_URL>/ | head -n 1Replace <WEB_URL> with your own value (or fill in the known ones once under My values at the top of the page).
HTTP/1.1 404 Not Found- 404 means the website endpoint works and the policy is fine. You will upload the app soon.
- 403 Forbidden means public read is blocked: re-check the two unticked boxes and the policy.
Saving the bucket policy says 'Access denied' or 'blocked by Block Public Access'
Your account or organisation has account-level Block Public Access turned on, which overrides the bucket setting. Open S3Block Public Access settings for this account. If you own the account you can relax Block public access to buckets and objects granted through new public bucket or access point policies there. If your organisation controls it, ask the administrator; this guide cannot work around it.
Next: launch the API server.
Found a mistake? Edit this page on GitHub.