Review S3 public ACL suppression

Check protection that prevents public ACL grants from authorizing access.

Description

ignore_public_acls prevents S3 from using public ACL grants for access control, even when a public ACL is present. While block_public_acls blocks new public ACL requests, this option also suppresses existing public ACL grants.

Effective permissions depend on other blocking settings and Object Ownership. ACLs do not grant permissions on a bucket where they are disabled, so this option alone does not establish public exposure.

Potential impact

  • Effective public ACL grants can continue to allow unintended users access.
  • Unnecessary read grants can expose object contents or the list of objects within a bucket.

Remediation

  • Set ignore_public_acls = true so public ACL grants are not used for access control.
  • Also review block_public_acls and remove unnecessary public ACLs. Ignoring a public ACL does not delete the stored ACL.
  • Disable ACLs through Object Ownership if they are unnecessary. Review other permissions, including bucket policies, separately.

Examples

These examples compare the option that ignores public ACL grants. New-bucket defaults disable ACLs, and account-level or other blocking settings may also apply. Replace the bucket name with your actual name.

Before

hcl
resource "aws_s3_bucket" "example" {
  bucket = "example"
}

resource "aws_s3_bucket_public_access_block" "example" {
  bucket = aws_s3_bucket.example.id

  block_public_acls   = true
  block_public_policy = true
  ignore_public_acls  = false
}

After

hcl
resource "aws_s3_bucket" "example" {
  bucket = "example"
}

resource "aws_s3_bucket_public_access_block" "example" {
  bucket = aws_s3_bucket.example.id

  block_public_acls   = true
  block_public_policy = true
  ignore_public_acls  = true
}

Explanation:

The second example ignores public ACL grants. It does not delete existing ACLs or block permissions granted by bucket policies, so also verify effective access.

References