S3 bucket policy not associated with its target

Attach required bucket policies to the correct bucket.

Description

Access controls defined in a bucket policy must be attached to the intended bucket. Absence of a bucket policy does not itself make a bucket public; IAM permissions and other S3 controls also apply.

Potential impact

An incorrect bucket reference can fail deployment or leave the intended controls unapplied to the target bucket.

Remediation

Use the bucket’s !Ref for Bucket in AWS::S3::BucketPolicy, and check the policy’s resource ARNs and principals. Allow only the access that is needed.

Examples

The examples compare a nonexistent bucket reference with a correct association. Define BucketReaderRole separately as an approved role, and replace bucket names for the actual environment.

Before

yaml
Resources:
  S3Bucket3:
    Type: 'AWS::S3::Bucket'
    Properties:
      BucketName: docexamplebucket1

  SampleBucketPolicy5:
    Type: 'AWS::S3::BucketPolicy'
    Properties:
      Bucket:
        Ref: docexamplebucketfail
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Action:
              - 's3:GetObject'
            Effect: Allow
            Resource: !Sub '${S3Bucket3.Arn}/*'
            Principal:
              AWS: !GetAtt BucketReaderRole.Arn

After

yaml
Resources:
  S3Bucket:
    Type: 'AWS::S3::Bucket'
    Properties:
      BucketName: docexamplebucket

  SampleBucketPolicy:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref S3Bucket
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Action:
              - 's3:GetObject'
            Effect: Allow
            Resource: !Sub '${S3Bucket.Arn}/*'
            Principal:
              AWS: !GetAtt BucketReaderRole.Arn

References