Description
ignore_public_acls prevents S3 from using public ACL grants for access control, even when a public ACL is present. While block_public_acls blocks new public ACL requests, this option also suppresses existing public ACL grants.
Effective permissions depend on other blocking settings and Object Ownership. ACLs do not grant permissions on a bucket where they are disabled, so this option alone does not establish public exposure.
Potential impact
- Effective public ACL grants can continue to allow unintended users access.
- Unnecessary read grants can expose object contents or the list of objects within a bucket.
Remediation
- Set
ignore_public_acls = trueso public ACL grants are not used for access control. - Also review
block_public_aclsand remove unnecessary public ACLs. Ignoring a public ACL does not delete the stored ACL. - Disable ACLs through Object Ownership if they are unnecessary. Review other permissions, including bucket policies, separately.
Examples
These examples compare the option that ignores public ACL grants. New-bucket defaults disable ACLs, and account-level or other blocking settings may also apply. Replace the bucket name with your actual name.
Before
resource "aws_s3_bucket" "example" {
bucket = "example"
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.example.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = false
}
After
resource "aws_s3_bucket" "example" {
bucket = "example"
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.example.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
}
Explanation:
The second example ignores public ACL grants. It does not delete existing ACLs or block permissions granted by bucket policies, so also verify effective access.