AWS S3 bucket inventory

Document bucket purpose and responsibility for stored data.

Description

An S3 bucket inventory identifies how stored data is used and who manages it. The existence of a bucket alone does not indicate a security problem.

Potential impact

Unlisted buckets may be missed in access-policy and data-retention reviews or incur unnecessary storage costs.

Remediation

Record each bucket’s owner and service, then check public-access blocking, encryption, versioning, logging, and lifecycle settings.

Examples

The examples add service and environment tags to a bucket. Tags do not replace access policies or data-protection settings.

Before

hcl
resource "aws_s3_bucket" "data" {
  bucket = "example-data-bucket"
}

After

hcl
resource "aws_s3_bucket" "data" {
  bucket = "example-data-bucket"

  tags = {
    Service     = "data-platform"
    Environment = "production"
  }
}

References