Description
An overly broad EFS file system policy can let unnecessary clients read or write files. Actual access also depends on network connectivity to a mount target, IAM permissions and file permissions.
Reducing a file system policy grant can leave permissions from other IAM policies in place, so review them together.
Potential impact
- Unnecessary read permissions can expose file contents.
- Misused write or root access can cause file modification, deletion or service disruption.
Remediation
- Allow approved principals only the ClientMount, ClientWrite and ClientRootAccess actions they need.
- Configure the EFS mount helper for IAM authorization and TLS, and use access points to restrict access where needed.
- Review security groups, file permissions and other IAM grants, and test that intended access works while unnecessary access is denied.
Examples
These excerpts change the policy on the same file system. Define the referenced file system separately and replace the example user ARN with an approved principal.
Before
resource "aws_efs_file_system_policy" "example" {
file_system_id = aws_efs_file_system.fs.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Resource": "${aws_efs_file_system.fs.arn}",
"Action": [
"elasticfilesystem:*"
]
}
]
}
POLICY
}
This grants all AWS principals broad client actions on the file system. Network connectivity and file permissions also affect actual access.
After
resource "aws_efs_file_system_policy" "example" {
file_system_id = aws_efs_file_system.fs.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::111122223333:user/Carlos"
},
"Resource": "${aws_efs_file_system.fs.arn}",
"Action": [
"elasticfilesystem:ClientMount",
"elasticfilesystem:ClientWrite"
],
"Condition": {
"Bool": {
"aws:SecureTransport": "true"
}
}
}
]
}
POLICY
}
This statement grants the specified user mount and write access over TLS. It does not remove grants made by other policies.