Skip to content

Commit e615ac8

Browse files
authored
Block public access to Artifact/AccessLogs Buckets (#977)
* Block public access to Artifact/AccessLogs Buckets --------- authored-by: Fbzioui
1 parent b907697 commit e615ac8

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

src/rpdk/core/data/managed-upload-infrastructure.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,11 @@ Resources:
2626
LoggingConfiguration:
2727
DestinationBucketName: !Ref AccessLogsBucket
2828
LogFilePrefix: ArtifactBucket
29+
PublicAccessBlockConfiguration:
30+
BlockPublicAcls: true
31+
BlockPublicPolicy: true
32+
IgnorePublicAcls: true
33+
RestrictPublicBuckets: true
2934

3035
AccessLogsBucket:
3136
Type: AWS::S3::Bucket
@@ -42,6 +47,11 @@ Resources:
4247
ExpirationInDays: 3653
4348
VersioningConfiguration:
4449
Status: Enabled
50+
PublicAccessBlockConfiguration:
51+
BlockPublicAcls: true
52+
BlockPublicPolicy: true
53+
IgnorePublicAcls: true
54+
RestrictPublicBuckets: true
4555

4656
ArtifactCopyPolicy:
4757
Type: AWS::S3::BucketPolicy

0 commit comments

Comments
 (0)