Review restrictions on public S3 buckets

Restrict unwanted external access to buckets with public policies.

Description

restrict_public_buckets limits access to a bucket with a public policy to AWS service principals and authorized users in its account. It can block both public access and specific cross-account grants contained in that public policy.

While block_public_policy blocks new public policies, this option restricts access where a public policy already exists. Effective access also depends on the policy and blocking settings at other levels, so one option does not determine public exposure.

Potential impact

  • A public policy can grant access to unintended accounts or users.
  • Unnecessary read permissions can expose data, and other granted operations may allow changes.

Remediation

  • Set restrict_public_buckets = true at the account and bucket levels where public access is unnecessary.
  • Narrow existing public policies to the required principals, operations, and resources, and test actual requests so needed cross-account access remains available.
  • Review other S3 Block Public Access options, ACLs, and bucket policies together.

Examples

These excerpts compare an account-level setting. Use your actual account ID and a bucket in the same account. The bucket policy and blocking settings at other levels are omitted.

Before

hcl
resource "aws_s3_account_public_access_block" "example" {
  account_id = 250924516109
}

resource "aws_s3_bucket_public_access_block" "example" {
  bucket                  = aws_s3_bucket.public_bucket.id
  block_public_acls       = false
  block_public_policy     = false
  ignore_public_acls      = false
  restrict_public_buckets = false
}

After

hcl
resource "aws_s3_account_public_access_block" "example" {
  account_id               = 250924516109
  restrict_public_buckets  = true
}

resource "aws_s3_bucket_public_access_block" "example" {
  bucket                  = aws_s3_bucket.public_bucket.id
  block_public_acls       = false
  block_public_policy     = false
  ignore_public_acls      = false
  restrict_public_buckets = false
}

Explanation:

The second example restricts access to buckets with public policies at the account level. The bucket’s restrict_public_buckets = false does not relax that restriction. Check existing cross-account workflows and other access controls as well.

References