CloudTrail log bucket public access needs review

Remove public permissions from audit-log storage while preserving log delivery.

Description

CloudTrail logs can contain sensitive audit information such as account activity and API calls. Remove public permissions from the log bucket and review actual bucket and object access together.

A public READ bucket ACL permits object listing; it does not by itself grant read access to every log object. Actual permissions also depend on object ACLs, bucket policies, Object Ownership and Block Public Access.

Potential impact

  • Exposed object names or listings can help reveal the structure of an environment.
  • If log-object read access is also public, account activity and operational information can be disclosed.

Remediation

  • Remove public ACLs and unnecessary public bucket policies, and retain S3 Block Public Access.
  • Configure required log-delivery and reader permissions in policies before disabling ACLs where possible. Restrict CloudTrail service writes, including an aws:SourceArn condition for the relevant trail ARN.
  • Verify that logs continue to arrive and only approved auditors can read the objects they need.

Examples

These are comparison excerpts for an existing ACL-enabled environment. New S3 buckets disable ACLs by default and do not accept public ACL requests. Supply a unique bucket name and the CloudTrail delivery bucket policy separately.

Before

hcl
resource "aws_cloudtrail" "cloudtrail" {
  name           = "tf-trail-foobar"
  s3_bucket_name = aws_s3_bucket.log_bucket.id
}

resource "aws_s3_bucket" "log_bucket" {
  bucket = "my-tf-test-bucket"
  acl    = "public-read"
}

This requests a public READ bucket ACL. If effective, it permits listing; review log-object content access separately.

After

hcl
resource "aws_cloudtrail" "cloudtrail" {
  name           = "tf-trail-foobar"
  s3_bucket_name = aws_s3_bucket.log_bucket.id
}

resource "aws_s3_bucket" "log_bucket" {
  bucket = "my-tf-test-bucket"
  acl    = "private"
}

This removes public permissions from the bucket ACL. Also review bucket and object policies and Block Public Access while preserving CloudTrail delivery permissions.

References