Legacy aws_s3 task specifies a public ACL

Public S3 ACLs can let unintended users list objects, read their contents, or upload objects. Restrict public access according to the permissions that apply.

Description

Public ACLs such as public-read and public-read-write can grant S3 access to anyone, including anonymous users. Avoid these ACLs for data that does not need to be public.

Specifying a public ACL does not establish that every object in a bucket is public. READ on a bucket ACL permits listing objects; READ on an object ACL permits reading that object's contents. Block Public Access can reject or ignore public ACLs. When Object Ownership is set to Bucket owner enforced, ACLs do not grant access.

Potential impact

  • If a public read ACL is effective, it can expose an object listing or object contents to unintended users, depending on its target.
  • If public WRITE permission on a bucket is effective, uploads of new objects by external users can increase storage and request costs. This permission alone does not let users who own neither the bucket nor an existing object overwrite or delete that object.

Remediation

  • Remove public ACLs that are not needed. Configure required existing access through policies before disabling ACLs. If you must continue using ACLs, grant permissions only to the accounts that need them.
  • Check Block Public Access, Object Ownership, bucket policies, and object ACLs together to determine effective access. For intentionally public data, grant only the required read access to the intended resources.
  • Use amazon.aws.s3_bucket to manage buckets with current Ansible collections. After the change, inspect the actual ACLs and policies, and verify that required access still works while unwanted access is denied.

Examples

These examples use the legacy amazon.aws.aws_s3 module. Its current documentation redirects to amazon.aws.s3_object, whose bucket creation and deletion support was removed in collection version 6.0.0. Do not use the following mode: create snippets as instructions for creating buckets with a current collection.

Before

yaml
- name: Create an empty bucket
  amazon.aws.aws_s3:
    bucket: mybucket
    mode: create
    permission: public-read

- name: Create an empty bucket
  amazon.aws.aws_s3:
    bucket: mybucket-logs
    mode: create
    permission: public-read-write

After

yaml
- name: Create an empty bucket
  amazon.aws.aws_s3:
    bucket: mybucket
    mode: create
    permission: private

Explanation:

  • First example: On a bucket, public-read can allow object listing, and public-read-write can also allow uploads of new objects. Effective permissions depend on whether ACLs are enabled and on other access controls.
  • Second example: The private ACL does not grant public permissions. Check access granted separately by bucket policies or object ACLs, and verify that the required change was actually applied to an existing bucket.

References