Description
AWS::S3::Bucket declares an object-storage bucket. Its presence belongs in the asset inventory and does not itself indicate public exposure or a vulnerability.
Potential impact
An omitted bucket can be missed during access-policy, data-retention, and cost reviews.
Remediation
Record the bucket’s owner and purpose, and check Block Public Access, bucket policies, versioning, and encryption-key selection.
Examples
Choose an available unique bucket name. Both configurations encrypt new objects; the second selects versioning and SSE-KMS. Changing default encryption does not re-encrypt existing objects.
Before
yaml
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
BucketName: jenkins-artifacts
After
yaml
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
BucketName: jenkins-artifacts
VersioningConfiguration:
Status: Enabled
BucketEncryption:
ServerSideEncryptionConfiguration:
- ServerSideEncryptionByDefault:
SSEAlgorithm: aws:kms