OSS bucket policy combines wildcard principals with delete actions

Restrict OSS deletion permissions to required accounts and roles to prevent unintended data loss and removal of settings.

Description

Granting deletion actions to all principals in an OSS bucket policy can let principals that do not need deletion rights remove data or settings when suitable access restrictions are absent. Effective permissions depend on the actions, target resources, conditions, explicit denies, and Block Public Access.

Deleting a bucket, an object, and a setting are different operations. In particular, DeleteBucket requires the bucket owner to make the request and the bucket to be empty. Specifying that permission does not allow anyone to delete the bucket and all its data in one operation.

Potential impact

  • If principals that do not need object deletion permission receive it, they may be able to delete data or objects used by an application.
  • Permission to delete bucket configuration can remove settings and affect bucket operations. Deleting the bucket itself, its objects, and its configuration are distinct actions.
  • Actual deletion may require data recovery and incident response. The effects of versioning and retention policies must also be checked for the operation and resource involved.

Remediation

  • Grant only the required delete operations on the required resources to the accounts or roles that need them. Do not include unnecessary deletion permissions in policies intended for public access.
  • Distinguish bucket resources from object resources. Review conditions, explicit denies, ACLs, and Block Public Access together. A private ACL does not block all policy-based access.
  • Inline policy has been deprecated since provider 1.220.0. Manage new configurations with alicloud_oss_bucket_policy, and verify that required permissions and restrictions remain intact after migration.

Examples

These examples use the legacy inline policy form supported in provider 1.293.0. Choose an available, unique bucket name and update the policy's resource paths to match.

Bucket deletion and upload actions

hcl
resource "alicloud_oss_bucket" "bucket-policy1" {
  bucket = "bucket-1-policy"
  acl    = "private"

  policy = <<POLICY
  {"Statement": [
    {
        "Action": [
            "oss:PutObject", "oss:DeleteBucket"
        ],
        "Effect": "Allow",
        "Principal": [
            "*"
        ],
        "Resource": [
            "acs:oss:*:*:bucket-1-policy",
            "acs:oss:*:*:bucket-1-policy/*"
        ]
    }
  ],
   "Version":"1"}
  POLICY
}

The owner and empty-bucket restrictions still apply to oss:DeleteBucket. The accompanying oss:PutObject grants object upload permission, so restrict it to required uploaders while accounting for controls such as Block Public Access.

Listing-only grant

hcl
resource "alicloud_oss_bucket" "bucket-policy2" {
  bucket = "bucket-2-policy"
  acl    = "private"

  policy = <<POLICY
  {"Statement": [
    {
        "Action": [
            "oss:ListObjects"
        ],
        "Effect": "Allow",
        "Principal": [
            "*"
        ],
        "Resource": [
            "acs:oss:*:*:bucket-2-policy"
        ]
    }
  ],
   "Version":"1"}
  POLICY
}

This statement grants oss:ListObjects rather than deletion permissions. It does not remove deletion rights granted by other policies, and effective public listing can expose object names. Confirm that public listing is required too.

References