S3 bucket policy with Put actions and a wildcard principal

Restrict S3 object writes and configuration changes to required principals and resources to prevent unwanted uploads and modifications.

Description

Allowing Put actions for Principal: "*" in a bucket policy can let unintended callers write objects or change settings. The operations actually permitted depend on the specified actions and resources, conditions, explicit denies, and Block Public Access settings.

Not every Put action uploads an object. s3:PutObject writes objects, while other actions can change separate settings, so review the permissions needed for each operation.

Potential impact

  • If principals that do not need to write objects effectively have s3:PutObject permission, they can create objects or change the current contents at an existing key. Versioning, conditional requests, and other settings also affect the outcome.
  • Changes to objects used by an application can affect its content or processing results. Assess other Put actions according to the resources and settings they change.
  • Unnecessary uploads can increase storage and request costs. Put permissions alone do not also grant reading or deletion.

Remediation

  • Identify the exact operations required, and grant write or configuration-change permissions only to the necessary principals and resource ARNs.
  • Determine effective access from the full policy, including conditions, explicit denies, and Block Public Access.
  • Where object uploads are required, also review how consuming services validate uploaded data and manage storage costs.

Examples

These historical examples cannot be deployed as written. Version: "2020-10-07" is an unsupported policy-language version, PutObject lacks the service prefix, and Resource is missing. For a real policy, specify a supported version, an exact action such as s3:PutObject, and the correct target ARN.

Before

yaml
- name: Bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    policy:
      Version: "2020-10-07"
      Statement:
        - Effect: Allow
          Action: PutObject
          Principal: "*"

After

yaml
- name: Bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    policy:
      Version: "2020-10-07"
      Statement:
        - Effect: Allow
          Action: PutObject
          Principal:
            AWS: "arn:aws:iam::123456789012:role/upload-service-role"

Explanation:

  • First example: Principal: "*" does not limit who can write objects. When correcting the policy format, also restrict the principals and object scope.
  • Second example: A role responsible for uploads is specified. Correct the policy format, use the real role and target object ARNs, and verify that required uploads succeed while unwanted writes are denied.

References