S3 bucket policy with wildcard actions and principals

Limit S3 bucket-policy actions and principals to the workload's needs to avoid excessive permissions.

Description

Allowing access with wildcards in both Action and Principal can include operations or callers beyond the workload's needs. Review both scopes, particularly to avoid granting broad permissions to anonymous requests.

s3:* refers to all S3 actions, while s3:Get* refers only to actions whose names match that pattern. Effective access also depends on the resources applicable to each action, conditions, explicit denies, and Block Public Access, so a wildcard alone does not determine the complete permissions.

Potential impact

  • If a wildcard includes unintended actions or principals and the permissions are effective, it can grant excessive access.
  • Whether objects can be read, written, or deleted depends on the matching actions and target resources.

Remediation

  • Specify the required actions and principals, and limit permissions to the correct bucket or object ARNs.
  • Where access such as public reading is intentional, review the data and conditions involved and exclude unnecessary operations.
  • Check the complete policy, explicit denies, and Block Public Access, then test that required access works and unwanted access is denied.

Examples

In both examples, the bucket named in Resource differs from name: mys3bucket; correct it for the actual target bucket. An object ARN ending in /* does not grant every operation on the bucket itself. Use the appropriate ARNs for bucket and object operations.

Before

yaml
- name: Create s3 bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    policy:
      Id: "id113"
      Version: "2012-10-17"
      Statement:
        - Action: "s3:*"
          Effect: "Allow"
          Resource: "arn:aws:s3:::S3B_181355/*"
          Principal: "*"

After

yaml
- name: Create s3 bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    policy:
      Id: "id113"
      Version: "2012-10-17"
      Statement:
        - Action:
            - "s3:GetObject"
          Effect: "Allow"
          Resource: "arn:aws:s3:::S3B_181355/*"
          Principal:
            AWS: "arn:aws:iam::123456789012:role/read-only-bucket-role"

Explanation:

  • First example: s3:* and Principal: "*" specify broad actions and principals. Even after correcting the resource ARN, review whether this scope is needed.
  • Second example: The statement allows a specific role only the object-reading action s3:GetObject. Use the real role ARN and the target object ARNs within the bucket, and check additional permissions granted by other policies.

References