Description
OSS access logs record requests to buckets and objects. Without collected logs, there is less evidence for investigating past access and errors.
Potential impact
Tracing suspicious access, data changes, or operational failures can become more difficult.
Remediation
Specify a destination bucket and prefix in the logging block. Use a separate bucket in the same account and region, and manage its access permissions and retention.
Examples
The examples add logging to the same bucket. Logging and public access are separate settings; restrict the ACL too if public reads are unnecessary.
Before
hcl
resource "alicloud_oss_bucket" "bucket" {
bucket = "bucket-170309-acl"
acl = "public-read"
}
After
hcl
resource "alicloud_oss_bucket" "bucket" {
bucket = "bucket-170309-acl"
logging {
target_bucket = alicloud_oss_bucket.bucket_target.id
target_prefix = "log/"
}
}