Our bucket policy let the office in and locked out every server we own
In June our security team asked for the bucket holding signed contracts to be reachable only from the office and from our own network. I wrote the bucket policy in Terraform: deny every S3 action unless the request's aws:SourceIp is one of the office ranges or one of the two public addresses of our NAT gateways. I tested it from my laptop in the office and from an instance in a private subnet, and both worked. The plan was reviewed and the apply was green on a Wednesday. On Friday morning the contracts service failed every upload and every download with access denied, from an explicit deny.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in