Description
S3 objects can contain configuration files, backups and static assets that need protection. Check that the encryption mode and key actually applied to objects meet organizational requirements.
New S3 objects currently receive server-side encryption by default. Uploads without server_side_encryption use the bucket’s default encryption, so omitting this option does not imply unencrypted storage. An explicitly requested upload encryption mode can differ from the bucket default.
Potential impact
Default AES256 alone may not meet requirements for KMS keys or key control. Earlier unencrypted objects are not automatically encrypted by changing a default setting. Encryption does not replace object read permissions or public-access controls.
Remediation
- Check bucket default encryption alongside the actual object encryption mode and key.
- Use
AES256oraws:kmswith the required key according to organizational policy. Review upload policies so explicitAES256does not bypass a bucket’s KMS requirement. - Plan encrypted copies of existing unencrypted objects, and verify data and version retention and read access. Grant only required KMS permissions.
Examples
Replace the bucket name with a globally unique value and provide the index.html file to upload. These examples compare explicit upload encryption with bucket defaults; they are not complete examples for environments requiring a customer managed KMS key.
Use bucket default encryption
resource "aws_s3_bucket" "artifact_bucket" {
bucket = "examplebuckettftest"
versioning {
enabled = true
}
}
resource "aws_s3_bucket_object" "artifact_file" {
key = "someobject"
bucket = aws_s3_bucket.artifact_bucket.id
source = "index.html"
}
No separate upload encryption is specified, so the bucket default applies. This does not mean that a new object is stored in plaintext.
Explicitly request SSE-S3
resource "aws_s3_bucket" "artifact_bucket" {
bucket = "examplebuckettftest"
versioning {
enabled = true
}
}
resource "aws_s3_bucket_object" "artifact_file" {
key = "someobject"
bucket = aws_s3_bucket.artifact_bucket.id
source = "index.html"
server_side_encryption = "AES256"
}
This explicitly requests AES256 for the upload. It chooses SSE-S3 even if the bucket defaults to KMS, so verify that this meets organizational key requirements.