Description
Access controls defined in a bucket policy must be attached to the intended bucket. Absence of a bucket policy does not itself make a bucket public; IAM permissions and other S3 controls also apply.
Potential impact
An incorrect bucket reference can fail deployment or leave the intended controls unapplied to the target bucket.
Remediation
Use the bucket’s !Ref for Bucket in AWS::S3::BucketPolicy, and check the policy’s resource ARNs and principals. Allow only the access that is needed.
Examples
The examples compare a nonexistent bucket reference with a correct association. Define BucketReaderRole separately as an approved role, and replace bucket names for the actual environment.
Before
yaml
Resources:
S3Bucket3:
Type: 'AWS::S3::Bucket'
Properties:
BucketName: docexamplebucket1
SampleBucketPolicy5:
Type: 'AWS::S3::BucketPolicy'
Properties:
Bucket:
Ref: docexamplebucketfail
PolicyDocument:
Version: "2012-10-17"
Statement:
- Action:
- 's3:GetObject'
Effect: Allow
Resource: !Sub '${S3Bucket3.Arn}/*'
Principal:
AWS: !GetAtt BucketReaderRole.Arn
After
yaml
Resources:
S3Bucket:
Type: 'AWS::S3::Bucket'
Properties:
BucketName: docexamplebucket
SampleBucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref S3Bucket
PolicyDocument:
Version: "2012-10-17"
Statement:
- Action:
- 's3:GetObject'
Effect: Allow
Resource: !Sub '${S3Bucket.Arn}/*'
Principal:
AWS: !GetAtt BucketReaderRole.Arn