Description
block_public_acls rejects new ACL requests that grant public permissions. Without this protection, an incorrect ACL can broaden access on a bucket where ACLs are enabled.
One bucket setting does not determine effective public access. Check stricter account-level or other Block Public Access settings and whether Object Ownership disables ACLs.
Potential impact
- An effective public ACL can allow unintended users to access a bucket or object.
- Unnecessary read grants can expose backups, logs, or documents.
Remediation
- Set
block_public_acls = trueinaws_s3_bucket_public_access_block. - Also review
ignore_public_aclsto suppress existing public ACL grants. Blocking new public ACLs does not remove existing ACLs. - Disable ACLs through Object Ownership when they are unnecessary, and review other permissions, including bucket policies.
Examples
The examples compare one bucket-level option. New-bucket defaults disable ACLs, and restrictions at other levels may also apply, so the first setting alone does not establish public exposure. Replace the bucket name with your actual name.
Before
resource "aws_s3_bucket" "example" {
bucket = "example"
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.example.id
block_public_acls = false
block_public_policy = true
ignore_public_acls = false
}
After
resource "aws_s3_bucket" "example" {
bucket = "example"
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.example.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = false
}
Explanation:
The second example blocks new public ACL requests. Because ignore_public_acls = false remains, review existing public ACL grants and other access paths separately.