Bucket Policies

Bucket Policies and Public Access Settings

Visitors must read objects anonymously, and Block Public Access stands in the way: four switches, all on for new buckets by default, two for ACLs and two for policies (BlockPublicPolicy refuses a public policy, RestrictPublicBuckets ignores one). The template relaxes only the policy pair and grants s3:GetObject alone:

infra/booknest-web.yaml: public access settings and a read-only public policyYAML
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        IgnorePublicAcls: true
        BlockPublicPolicy: false
        RestrictPublicBuckets: false
  FrontEndBucketPolicy:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref FrontEndBucket
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Sid: PublicReadForWebsite
            Effect: Allow
            Principal: "*"
            Action: s3:GetObject
            Resource: !Sub ${FrontEndBucket.Arn}/*

The resource ends in /*, the objects, so visitors can neither list keys nor write. Account-level Block Public Access overrides every bucket; with it on, AWS 24 rejects this policy with AccessDenied and the stack fails. cfn-guard's guard rule buckets_block_public_access fails here too, by design: public buckets should be reviewed exceptions.