AccessControlListNotSupported ☁️ AWS

AccessControlListNotSupported: The bucket does not allow ACLs

The upload sets an ACL (like public-read), but the bucket uses “Bucket owner enforced” Object Ownership, which disables ACLs.

Seen on: AWS

Meaning

Since April 2023 new buckets disable ACLs by default. Tools and plugins that send x-amz-acl: public-read (old WordPress offload plugins, s3 sync --acl, older SDK examples) fail. Use a bucket policy (or CloudFront) for public access instead.

Common causes

  • Code/plugin sends ACL headers (public-read, bucket-owner-full-control)
  • Bucket created with ACLs disabled (default)
  • CLI uses --acl

⚡ Quick fix

  1. Remove the ACL parameter from uploads
  2. Grant public read via bucket policy (and disable Block Public Access deliberately) or serve through CloudFront
  3. Re-enable ACLs only if a legacy tool truly needs them

Detailed fix by platform

AWS CLI

  1. bash
    aws s3 cp file.png s3://my-bucket/   # no --acl
    aws s3api get-bucket-ownership-controls --bucket my-bucket

How to diagnose

  1. Ownership — ObjectOwnership value
  2. Client — Which ACL header is sent?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.