Description
block_public_policy rejects requests to apply bucket policies that allow public access. Without this protection, an incorrect policy can grant unwanted external access.
Effective access also depends on the bucket policy and other controls. S3 applies the most restrictive applicable account, bucket, and other Block Public Access settings, so one bucket option does not establish public exposure.
Potential impact
- An incorrect public policy can allow external access.
- Unnecessary read permissions can expose backups, logs, or internal documents.
Remediation
- Set
block_public_policy = trueat the account and bucket levels where public policies are unnecessary. - Review existing public policies and remove unwanted grants. This option does not delete or change the effect of policies already in place.
- Limit intentional public access to required operations and resources, and check the remaining Block Public Access options and effective access.
Examples
These excerpts compare an account-level setting. Replace the account ID and provide a bucket in that account. Other blocking settings and the actual bucket policy are omitted.
Before
resource "aws_s3_account_public_access_block" "example" {
account_id = 250924516109
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.public_bucket.id
block_public_acls = false
block_public_policy = false
ignore_public_acls = false
restrict_public_buckets = false
}
After
resource "aws_s3_account_public_access_block" "example" {
account_id = 250924516109
block_public_policy = true
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.public_bucket.id
block_public_acls = false
block_public_policy = false
ignore_public_acls = false
restrict_public_buckets = false
}
Explanation:
The second example blocks public bucket policy requests at the account level. The bucket’s block_public_policy = false does not relax that restriction. Review existing policies and the remaining Block Public Access options separately.