Review S3 public ACL blocking

Block public ACL grants that are not required.

Description

block_public_acls rejects new ACL requests that grant public permissions. Without this protection, an incorrect ACL can broaden access on a bucket where ACLs are enabled.

One bucket setting does not determine effective public access. Check stricter account-level or other Block Public Access settings and whether Object Ownership disables ACLs.

Potential impact

  • An effective public ACL can allow unintended users to access a bucket or object.
  • Unnecessary read grants can expose backups, logs, or documents.

Remediation

  • Set block_public_acls = true in aws_s3_bucket_public_access_block.
  • Also review ignore_public_acls to suppress existing public ACL grants. Blocking new public ACLs does not remove existing ACLs.
  • Disable ACLs through Object Ownership when they are unnecessary, and review other permissions, including bucket policies.

Examples

The examples compare one bucket-level option. New-bucket defaults disable ACLs, and restrictions at other levels may also apply, so the first setting alone does not establish public exposure. Replace the bucket name with your actual name.

Before

hcl
resource "aws_s3_bucket" "example" {
  bucket = "example"
}

resource "aws_s3_bucket_public_access_block" "example" {
  bucket = aws_s3_bucket.example.id

  block_public_acls   = false
  block_public_policy = true
  ignore_public_acls  = false
}

After

hcl
resource "aws_s3_bucket" "example" {
  bucket = "example"
}

resource "aws_s3_bucket_public_access_block" "example" {
  bucket = aws_s3_bucket.example.id

  block_public_acls   = true
  block_public_policy = true
  ignore_public_acls  = false
}

Explanation:

The second example blocks new public ACL requests. Because ignore_public_acls = false remains, review existing public ACL grants and other access paths separately.

References