Description
Public ACLs such as public-read and public-read-write can grant S3 access to anyone, including anonymous users. Avoid these ACLs for data that does not need to be public.
Specifying a public ACL does not establish that every object in a bucket is public. READ on a bucket ACL permits listing objects; READ on an object ACL permits reading that object's contents. Block Public Access can reject or ignore public ACLs. When Object Ownership is set to Bucket owner enforced, ACLs do not grant access.
Potential impact
- If a public read ACL is effective, it can expose an object listing or object contents to unintended users, depending on its target.
- If public
WRITEpermission on a bucket is effective, uploads of new objects by external users can increase storage and request costs. This permission alone does not let users who own neither the bucket nor an existing object overwrite or delete that object.
Remediation
- Remove public ACLs that are not needed. Configure required existing access through policies before disabling ACLs. If you must continue using ACLs, grant permissions only to the accounts that need them.
- Check Block Public Access, Object Ownership, bucket policies, and object ACLs together to determine effective access. For intentionally public data, grant only the required read access to the intended resources.
- Use
amazon.aws.s3_bucketto manage buckets with current Ansible collections. After the change, inspect the actual ACLs and policies, and verify that required access still works while unwanted access is denied.
Examples
These examples use the legacy amazon.aws.aws_s3 module. Its current documentation redirects to amazon.aws.s3_object, whose bucket creation and deletion support was removed in collection version 6.0.0. Do not use the following mode: create snippets as instructions for creating buckets with a current collection.
Before
- name: Create an empty bucket
amazon.aws.aws_s3:
bucket: mybucket
mode: create
permission: public-read
- name: Create an empty bucket
amazon.aws.aws_s3:
bucket: mybucket-logs
mode: create
permission: public-read-write
After
- name: Create an empty bucket
amazon.aws.aws_s3:
bucket: mybucket
mode: create
permission: private
Explanation:
- First example: On a bucket,
public-readcan allow object listing, andpublic-read-writecan also allow uploads of new objects. Effective permissions depend on whether ACLs are enabled and on other access controls. - Second example: The
privateACL does not grant public permissions. Check access granted separately by bucket policies or object ACLs, and verify that the required change was actually applied to an existing bucket.