Skip to content

Commit b624566

Browse files
authored
[IT-4074] Enable access flags for S3 buckets (#341)
Security hub says we should enable per bucket access flags when creating buckets to make sure they are private.
1 parent a9f7e0d commit b624566

File tree

2 files changed

+10
-0
lines changed

2 files changed

+10
-0
lines changed

templates/s3/sc-s3-encrypted-ra.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,11 @@ Resources:
3737
UpdateReplacePolicy: Retain
3838
Properties:
3939
BucketName: !If [HasBucketName, !Ref BucketName, !Ref 'AWS::NoValue']
40+
PublicAccessBlockConfiguration:
41+
BlockPublicAcls: true
42+
BlockPublicPolicy: true
43+
IgnorePublicAcls: true
44+
RestrictPublicBuckets: true
4045
BucketEncryption:
4146
ServerSideEncryptionConfiguration:
4247
- ServerSideEncryptionByDefault:

templates/s3/sc-s3-synapse-ra.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,11 @@ Resources:
4747
UpdateReplacePolicy: Retain
4848
Properties:
4949
BucketName: !If [HasBucketName, !Ref BucketName, !Ref 'AWS::NoValue']
50+
PublicAccessBlockConfiguration:
51+
BlockPublicAcls: true
52+
BlockPublicPolicy: true
53+
IgnorePublicAcls: true
54+
RestrictPublicBuckets: true
5055
BucketEncryption:
5156
ServerSideEncryptionConfiguration:
5257
- ServerSideEncryptionByDefault:

0 commit comments

Comments
 (0)