Review public exposure of an AWS S3 static website

Limit static website content and permissions to the intended public scope

Description

An S3 static website may intentionally serve public content. Website configuration alone does not make objects public, but public read permissions can make content available through the website endpoint. That endpoint does not support HTTPS.

Potential impact

Overbroad public permissions may expose files beyond the intended website, while HTTP traffic is vulnerable to interception or modification.

Remediation

Remove unused website configuration and revoke public permissions. If a site is needed, separate its public content and provide HTTPS. For a private bucket behind CloudFront, use the S3 REST origin with appropriate origin access control.

Examples

These excerpts remove the website configuration and apply S3 Block Public Access. Also review existing bucket policies and other access permissions.

Before

hcl
resource "aws_s3_bucket" "website_bucket" {
  bucket = "s3-website-test.hashicorp.com"
}

resource "aws_s3_bucket_website_configuration" "website" {
  bucket = aws_s3_bucket.website_bucket.id

  index_document {
    suffix = "index.html"
  }

  error_document {
    key = "error.html"
  }
}

After

hcl
resource "aws_s3_bucket" "website_bucket" {
  bucket = "s3-website-test.hashicorp.com"
}

resource "aws_s3_bucket_public_access_block" "website_bucket" {
  bucket = aws_s3_bucket.website_bucket.id

  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}

References