Review S3 object server-side encryption settings

Check effective S3 object encryption, upload settings and key requirements together.

Description

S3 objects can contain configuration files, backups and static assets that need protection. Check that the encryption mode and key actually applied to objects meet organizational requirements.

New S3 objects currently receive server-side encryption by default. Uploads without server_side_encryption use the bucket’s default encryption, so omitting this option does not imply unencrypted storage. An explicitly requested upload encryption mode can differ from the bucket default.

Potential impact

Default AES256 alone may not meet requirements for KMS keys or key control. Earlier unencrypted objects are not automatically encrypted by changing a default setting. Encryption does not replace object read permissions or public-access controls.

Remediation

  • Check bucket default encryption alongside the actual object encryption mode and key.
  • Use AES256 or aws:kms with the required key according to organizational policy. Review upload policies so explicit AES256 does not bypass a bucket’s KMS requirement.
  • Plan encrypted copies of existing unencrypted objects, and verify data and version retention and read access. Grant only required KMS permissions.

Examples

Replace the bucket name with a globally unique value and provide the index.html file to upload. These examples compare explicit upload encryption with bucket defaults; they are not complete examples for environments requiring a customer managed KMS key.

Use bucket default encryption

hcl
resource "aws_s3_bucket" "artifact_bucket" {
  bucket = "examplebuckettftest"

  versioning {
    enabled = true
  }
}

resource "aws_s3_bucket_object" "artifact_file" {
  key    = "someobject"
  bucket = aws_s3_bucket.artifact_bucket.id
  source = "index.html"
}

No separate upload encryption is specified, so the bucket default applies. This does not mean that a new object is stored in plaintext.

Explicitly request SSE-S3

hcl
resource "aws_s3_bucket" "artifact_bucket" {
  bucket = "examplebuckettftest"

  versioning {
    enabled = true
  }
}

resource "aws_s3_bucket_object" "artifact_file" {
  key                    = "someobject"
  bucket                 = aws_s3_bucket.artifact_bucket.id
  source                 = "index.html"
  server_side_encryption = "AES256"
}

This explicitly requests AES256 for the upload. It chooses SSE-S3 even if the bucket defaults to KMS, so verify that this meets organizational key requirements.

References