Description
restrict_public_buckets limits access to a bucket with a public policy to AWS service principals and authorized users in its account. It can block both public access and specific cross-account grants contained in that public policy.
While block_public_policy blocks new public policies, this option restricts access where a public policy already exists. Effective access also depends on the policy and blocking settings at other levels, so one option does not determine public exposure.
Potential impact
- A public policy can grant access to unintended accounts or users.
- Unnecessary read permissions can expose data, and other granted operations may allow changes.
Remediation
- Set
restrict_public_buckets = trueat the account and bucket levels where public access is unnecessary. - Narrow existing public policies to the required principals, operations, and resources, and test actual requests so needed cross-account access remains available.
- Review other S3 Block Public Access options, ACLs, and bucket policies together.
Examples
These excerpts compare an account-level setting. Use your actual account ID and a bucket in the same account. The bucket policy and blocking settings at other levels are omitted.
Before
resource "aws_s3_account_public_access_block" "example" {
account_id = 250924516109
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.public_bucket.id
block_public_acls = false
block_public_policy = false
ignore_public_acls = false
restrict_public_buckets = false
}
After
resource "aws_s3_account_public_access_block" "example" {
account_id = 250924516109
restrict_public_buckets = true
}
resource "aws_s3_bucket_public_access_block" "example" {
bucket = aws_s3_bucket.public_bucket.id
block_public_acls = false
block_public_policy = false
ignore_public_acls = false
restrict_public_buckets = false
}
Explanation:
The second example restricts access to buckets with public policies at the account level. The bucket’s restrict_public_buckets = false does not relax that restriction. Check existing cross-account workflows and other access controls as well.