Description
An S3 bucket inventory identifies how stored data is used and who manages it. The existence of a bucket alone does not indicate a security problem.
Potential impact
Unlisted buckets may be missed in access-policy and data-retention reviews or incur unnecessary storage costs.
Remediation
Record each bucket’s owner and service, then check public-access blocking, encryption, versioning, logging, and lifecycle settings.
Examples
The examples add service and environment tags to a bucket. Tags do not replace access policies or data-protection settings.
Before
hcl
resource "aws_s3_bucket" "data" {
bucket = "example-data-bucket"
}
After
hcl
resource "aws_s3_bucket" "data" {
bucket = "example-data-bucket"
tags = {
Service = "data-platform"
Environment = "production"
}
}