Alicloud OSS bucket has no access logging

Retain access records for the bucket and its objects.

Description

OSS access logs record requests to buckets and objects. Without collected logs, there is less evidence for investigating past access and errors.

Potential impact

Tracing suspicious access, data changes, or operational failures can become more difficult.

Remediation

Specify a destination bucket and prefix in the logging block. Use a separate bucket in the same account and region, and manage its access permissions and retention.

Examples

The examples add logging to the same bucket. Logging and public access are separate settings; restrict the ACL too if public reads are unnecessary.

Before

hcl
resource "alicloud_oss_bucket" "bucket" {
  bucket = "bucket-170309-acl"
  acl    = "public-read"
}

After

hcl
resource "alicloud_oss_bucket" "bucket" {
  bucket = "bucket-170309-acl"

  logging {
    target_bucket = alicloud_oss_bucket.bucket_target.id
    target_prefix = "log/"
  }
}

References