Updated on 2026-09-10 GMT+08:00

Configuring an Object ACL

Prerequisites

You are the object owner or you have the permission to write the object ACL.

An object owner is the account that uploads the object and is not necessarily the owner of the bucket that stores the object. For example, if account B is granted access to a bucket owned by account A, and account B uploads a file to that bucket, then account B becomes the owner of the object. Account A, although the bucket owner, is not the object owner. By default, the bucket owner (account A) cannot access the object uploaded by account B and cannot read or modify the object ACL unless explicitly granted permission.

Procedure

  1. In the navigation pane of OBS Console, choose Buckets.
  2. In the bucket list, click the desired bucket. The Objects page is displayed.
  3. Click the desired object.
  4. On the Object ACL page, choose either Private or Public Read to grant object ACL permissions to anonymous users.

    • After you change Public Read to Private, only the bucket owner or object owner has the access.
    • After you change Private to Public Read, anyone can read the object content and metadata. No identity authentication is required.
    Figure 1 Changing a public access permission
    Figure 2 Changing a public access permission

  5. Click Edit to grant the owner, anonymous user, or other accounts required permissions for the object.

    ACL permissions for encrypted objects cannot be granted to registered users or anonymous users.

    Click Export to get the object ACL configuration. The file includes the user type, account, object access, and ACL access.

    Click Add to apply specific ACL permissions to an account.

    Enter an account ID and specify ACL permissions for it. You can obtain the account ID from the My Credentials page.

    Click OK.

    Figure 3 Granting permissions

    Table 1 Object access permissions

    Permission

    Description

    Read

    Grants the permission to obtain the content and metadata of the object.

    Table 2 Object ACL access permissions

    Permission

    Description

    Read

    Grants the permission to read the object ACL.

    Write

    Grants the permission to update the object ACL.