Review IP access restrictions for Alicloud OSS buckets

Configure network restrictions for OSS bucket policies according to their purpose and verify actual request source addresses.

Description

IP conditions are an additional control for limiting OSS access to approved networks. Absence of an acs:SourceIp condition does not make a bucket public or enable anonymous access. Review principal permissions and other network controls together.

If internal storage must be used only through particular paths, apply conditions matching the source addresses that OSS receives. Internet requests may use a public NAT address rather than a client's private address.

Potential impact

  • Missing a required network restriction can allow stolen credentials to be used through other paths.
  • Incorrect conditions or addresses can also block legitimate users and services.

Remediation

  • Identify required networks and actual request addresses, then correctly combine IpAddress or NotIpAddress with acs:SourceIp.
  • A condition on one allow statement differs from an explicit deny of requests outside a range. Review other allow and deny statements too.
  • Test allowed clients, blocked clients and service calls, retaining a recoverable administrative access path.

Examples

These are legacy inline-policy excerpts. Preserve the resource address when modifying the same existing bucket. 203.0.113.0/24 is a documentation range and must be replaced with an actual approved source range.

Allow without a source-IP condition

hcl
resource "alicloud_oss_bucket" "bucket_policy" {
  bucket = "bucket-170309-policy"
  acl    = "private"

  policy = <<POLICY
  {"Statement":
      [{"Action":
          ["oss:PutObject", "oss:GetObject", "oss:DeleteBucket"],
        "Effect":"Allow",
        "Principal":["*"],
        "Resource":
            ["acs:oss:*:*:bucket-170309-policy",
             "acs:oss:*:*:bucket-170309-policy/*"]}],
   "Version":"1"}
  POLICY
}

This policy requests broad permissions for all principals. Restrict unnecessary principals and actions as well as reviewing IP conditions.

Deny requests outside the approved range

hcl
resource "alicloud_oss_bucket" "restricted_bucket" {
  bucket = "bucket-170309-policy"
  policy = <<POLICY
{
        "Version": "1",
        "Statement":
        [
            {
                "Effect": "Deny",
                "Action":
                [
                    "oss:RestoreObject",
                    "oss:ListObjects",
                    "oss:AbortMultipartUpload",
                    "oss:PutObjectAcl",
                    "oss:GetObjectAcl",
                    "oss:ListParts",
                    "oss:DeleteObject",
                    "oss:PutObject",
                    "oss:GetObject"
                ],
                "Principal":
                [
                    "*"
                ],
                "Resource":
                [
                    "acs:oss:*:*:bucket-170309-policy",
                    "acs:oss:*:*:bucket-170309-policy/*"
                ],
                "Condition":
                {
                    "NotIpAddress":
                    {
                        "acs:SourceIp": "203.0.113.0/24"
                    }
                }
            }
        ]
}
POLICY
}

This deny statement restricts requests outside the approved IP range for the listed actions and resources. It does not grant permissions to requests within the range; separate necessary allows must exist. The bucket owner and service calls may also be affected.

References