Description
IP conditions are an additional control for limiting OSS access to approved networks. Absence of an acs:SourceIp condition does not make a bucket public or enable anonymous access. Review principal permissions and other network controls together.
If internal storage must be used only through particular paths, apply conditions matching the source addresses that OSS receives. Internet requests may use a public NAT address rather than a client's private address.
Potential impact
- Missing a required network restriction can allow stolen credentials to be used through other paths.
- Incorrect conditions or addresses can also block legitimate users and services.
Remediation
- Identify required networks and actual request addresses, then correctly combine
IpAddressorNotIpAddresswithacs:SourceIp. - A condition on one allow statement differs from an explicit deny of requests outside a range. Review other allow and deny statements too.
- Test allowed clients, blocked clients and service calls, retaining a recoverable administrative access path.
Examples
These are legacy inline-policy excerpts. Preserve the resource address when modifying the same existing bucket. 203.0.113.0/24 is a documentation range and must be replaced with an actual approved source range.
Allow without a source-IP condition
resource "alicloud_oss_bucket" "bucket_policy" {
bucket = "bucket-170309-policy"
acl = "private"
policy = <<POLICY
{"Statement":
[{"Action":
["oss:PutObject", "oss:GetObject", "oss:DeleteBucket"],
"Effect":"Allow",
"Principal":["*"],
"Resource":
["acs:oss:*:*:bucket-170309-policy",
"acs:oss:*:*:bucket-170309-policy/*"]}],
"Version":"1"}
POLICY
}
This policy requests broad permissions for all principals. Restrict unnecessary principals and actions as well as reviewing IP conditions.
Deny requests outside the approved range
resource "alicloud_oss_bucket" "restricted_bucket" {
bucket = "bucket-170309-policy"
policy = <<POLICY
{
"Version": "1",
"Statement":
[
{
"Effect": "Deny",
"Action":
[
"oss:RestoreObject",
"oss:ListObjects",
"oss:AbortMultipartUpload",
"oss:PutObjectAcl",
"oss:GetObjectAcl",
"oss:ListParts",
"oss:DeleteObject",
"oss:PutObject",
"oss:GetObject"
],
"Principal":
[
"*"
],
"Resource":
[
"acs:oss:*:*:bucket-170309-policy",
"acs:oss:*:*:bucket-170309-policy/*"
],
"Condition":
{
"NotIpAddress":
{
"acs:SourceIp": "203.0.113.0/24"
}
}
}
]
}
POLICY
}
This deny statement restricts requests outside the approved IP range for the listed actions and resources. It does not grant permissions to requests within the range; separate necessary allows must exist. The bucket owner and service calls may also be affected.