EFS file system policy access needs review

Allow only approved clients and the file system operations they need.

Description

An overly broad EFS file system policy can let unnecessary clients read or write files. Actual access also depends on network connectivity to a mount target, IAM permissions and file permissions.

Reducing a file system policy grant can leave permissions from other IAM policies in place, so review them together.

Potential impact

  • Unnecessary read permissions can expose file contents.
  • Misused write or root access can cause file modification, deletion or service disruption.

Remediation

  • Allow approved principals only the ClientMount, ClientWrite and ClientRootAccess actions they need.
  • Configure the EFS mount helper for IAM authorization and TLS, and use access points to restrict access where needed.
  • Review security groups, file permissions and other IAM grants, and test that intended access works while unnecessary access is denied.

Examples

These excerpts change the policy on the same file system. Define the referenced file system separately and replace the example user ARN with an approved principal.

Before

hcl
resource "aws_efs_file_system_policy" "example" {
  file_system_id = aws_efs_file_system.fs.id

  policy = <<POLICY
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "*"
      },
      "Resource": "${aws_efs_file_system.fs.arn}",
      "Action": [
        "elasticfilesystem:*"
      ]
    }
  ]
}
POLICY
}

This grants all AWS principals broad client actions on the file system. Network connectivity and file permissions also affect actual access.

After

hcl
resource "aws_efs_file_system_policy" "example" {
  file_system_id = aws_efs_file_system.fs.id

  policy = <<POLICY
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::111122223333:user/Carlos"
      },
      "Resource": "${aws_efs_file_system.fs.arn}",
      "Action": [
        "elasticfilesystem:ClientMount",
        "elasticfilesystem:ClientWrite"
      ],
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "true"
        }
      }
    }
  ]
}
POLICY
}

This statement grants the specified user mount and write access over TLS. It does not remove grants made by other policies.

References