Description
Public read access to an ActionTrail log bucket can expose operational activity, account actions and security events. Audit logs support incident investigation and should be accessible only to the services and operators that need them.
Avoid public-read and public-read-write ACLs, and review bucket policies, object ACLs and Block Public Access together. An internet-reachable OSS endpoint does not by itself allow anonymous access.
Potential impact
- Resource details and activity records in logs can reveal information about the environment.
- If write access is also public, changes or deletion of log objects can undermine investigation evidence.
Remediation
- Set the log bucket ACL to
privateand remove unnecessary public grants from its policy and object ACLs. - Retain the role permissions needed for ActionTrail delivery and grant read access only to the required operators.
- Verify that new logs still arrive and unauthorized requests are denied after the change.
Examples
Use available, unique bucket names and set actiontrail_oss_write_role_arn to an actual RAM role ARN with log-delivery permissions. Keep the bucket name and Terraform resource address when changing an existing bucket's ACL.
Before
resource "alicloud_oss_bucket" "actiontrail_bucket" {
bucket = "bucket-actiontrail-3"
acl = "public-read"
}
resource "alicloud_actiontrail_trail" "actiontrail" {
trail_name = "action-trail"
oss_write_role_arn = var.actiontrail_oss_write_role_arn
oss_bucket_name = "bucket-actiontrail-3"
event_rw = "All"
trail_region = "All"
}
This requests a public-read ACL. Review object ACLs and other access controls to establish the actual exposure.
After
resource "alicloud_oss_bucket" "actiontrail_bucket" {
bucket = "bucket-actiontrail-1"
acl = "private"
}
resource "alicloud_actiontrail_trail" "actiontrail" {
trail_name = "action-trail"
oss_write_role_arn = var.actiontrail_oss_write_role_arn
oss_bucket_name = "bucket-actiontrail-1"
event_rw = "All"
trail_region = "All"
}
This uses a private ACL. Also check separate bucket-policy grants and the permissions required for log delivery.