Description
WRITE_ACP on a bucket ACL permits changes to that bucket's ACL. It differs from permission to upload objects or change their contents. Granting it to an account or group that does not need ACL administration can allow unintended permission changes. Identify whether the grantee is the bucket owner, an external account, or an S3 service group.
ACLs grant permissions to AWS accounts or predefined S3 groups, rather than directly to individual IAM users. A receiving account can delegate those permissions to its users. FULL_CONTROL also includes ACL administration, so review the full set of grants. New buckets default to BucketOwnerEnforced, which disables ACLs and uses policies to manage access.
Potential impact
- Unnecessary ACL administration can allow additional access grants or changes to existing permissions. The effect depends on the grantee, related policies, and Block Public Access.
- Incorrect ACL changes can interrupt legitimate access or log delivery. A grant to a particular service group is not a grant to all anonymous users.
Remediation
- Check each grantee's operational need and remove unnecessary
WRITE_ACP. Preserve the owner's required administrative access, and do not replace another grantee's permission with the broaderFULL_CONTROL. - Where possible, move ACL-dependent access to policies and disable ACLs with
BucketOwnerEnforced. First remove external grants from an existing bucket's ACL. - Prefer a bucket policy that grants the logging service the permissions needed for S3 server access logs. If ACL-based delivery must remain,
LogDeliveryneedsWRITEandREAD_ACP;WRITE_ACPis not a substitute for permission to upload logs.
Examples
These are alternative configurations for environments that must retain ACLs; do not apply both. Replace the bucket name with an available unique name. A source bucket and logging configuration are also required. For a new design, prefer disabled ACLs and a bucket policy.
Grant ACL administration to the logging group
data "aws_canonical_user_id" "current" {}
resource "aws_s3_bucket" "example" {
bucket = "my-tf-example-bucket"
}
resource "aws_s3_bucket_ownership_controls" "example" {
bucket = aws_s3_bucket.example.id
rule {
object_ownership = "BucketOwnerPreferred"
}
}
resource "aws_s3_bucket_acl" "example" {
depends_on = [aws_s3_bucket_ownership_controls.example]
bucket = aws_s3_bucket.example.id
access_control_policy {
grant {
grantee {
id = data.aws_canonical_user_id.current.id
type = "CanonicalUser"
}
permission = "FULL_CONTROL"
}
grant {
grantee {
type = "Group"
uri = "http://acs.amazonaws.com/groups/s3/LogDelivery"
}
permission = "WRITE_ACP"
}
owner {
id = data.aws_canonical_user_id.current.id
}
}
}
LogDelivery is the S3 log delivery group, not all anonymous users. This configuration grants it unnecessary ACL administration but omits the WRITE and READ_ACP permissions required for log delivery.
ACL permissions needed for log delivery
data "aws_canonical_user_id" "current" {}
resource "aws_s3_bucket" "example" {
bucket = "my-tf-example-bucket"
}
resource "aws_s3_bucket_ownership_controls" "example" {
bucket = aws_s3_bucket.example.id
rule {
object_ownership = "BucketOwnerPreferred"
}
}
resource "aws_s3_bucket_acl" "example" {
depends_on = [aws_s3_bucket_ownership_controls.example]
bucket = aws_s3_bucket.example.id
access_control_policy {
grant {
grantee {
id = data.aws_canonical_user_id.current.id
type = "CanonicalUser"
}
permission = "FULL_CONTROL"
}
grant {
grantee {
type = "Group"
uri = "http://acs.amazonaws.com/groups/s3/LogDelivery"
}
permission = "WRITE"
}
grant {
grantee {
type = "Group"
uri = "http://acs.amazonaws.com/groups/s3/LogDelivery"
}
permission = "READ_ACP"
}
owner {
id = data.aws_canonical_user_id.current.id
}
}
}
The owner retains FULL_CONTROL, while the logging group receives only WRITE and READ_ACP. Object Ownership and the explicit dependency ensure that ACLs are enabled first. This demonstrates permissions, not a complete logging configuration. Source and destination buckets must be in the same account and Region; also check destination encryption and the other log-delivery requirements.