S3 bucket policy with delete actions and a wildcard principal

Limit S3 deletion permissions to intended principals and review versioning and retention policies to reduce the risk of data loss.

Description

Grant S3 deletion permissions only to principals that need them. Allowing delete operations for Principal: "*" in a bucket policy can allow unwanted access, including anonymous requests. Whether deletion is actually permitted depends on the allowed actions and resources, conditions, explicit denies, and Block Public Access settings.

Potential impact

  • If effective authorization permits principals that do not need deletion permission to delete objects, data loss or service disruption can result.
  • Permission to delete log or backup objects can affect investigation and recovery. Deletion permission alone does not grant permission to read objects.
  • In a general purpose S3 bucket with versioning enabled, an ordinary deletion usually adds a delete marker. Permanently deleting a specific version requires separate version-deletion permission, so the impact depends on versioning and the actions actually allowed.

Remediation

  • Identify the required deletion operations and principals, then limit permissions to those principals and resource ARNs.
  • Review conditions, explicit denies, and Block Public Access together to determine effective access.
  • Review version-deletion permissions and retention policies separately, and test recovery procedures. Versioning alone does not prevent every deletion.

Examples

These historical examples cannot be deployed as written. Version: "2020-10-07" is not a supported policy-language version, DeleteObject lacks the service prefix, and Resource is missing. For a real policy, specify a supported version, an exact action name such as s3:DeleteObject, and the intended resources.

Before

yaml
- name: Bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    policy:
      Version: "2020-10-07"
      Statement:
        - Effect: Allow
          Action: DeleteObject
          Principal: "*"

After

yaml
- name: Bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    policy:
      Version: "2020-10-07"
      Statement:
        - Effect: Allow
          Action: DeleteObject
          Principal:
            AWS: "arn:aws:iam::123456789012:role/ops-bucket-admin"

Explanation:

  • First example: Principal: "*" leaves the principals for deletion unrestricted. Even after correcting the format issues above, review whether this broad scope is necessary.
  • Second example: A specific role is named as the principal for deletion. Correct the policy format, replace the role ARN with the real value, and verify that deletion permissions apply only to the intended objects.

References