Skip to content

Conversation

@RealOrangeOne
Copy link
Member

There were some issues with the previous format, where the condition would be applied strangely and somewhat selectively. I couldn't reproduce them, but doing the policies this way is probably better.

This uses explicit "Deny" policies, which should be easier to understand, since they're applied before any other policies, making them simpler to manage.

Policies taken from https://github.com/terraform-aws-modules/terraform-aws-s3-bucket/blob/f90d8a385e4c70afd048e8997dcccf125b362236/main.tf#L965 and https://github.com/terraform-aws-modules/terraform-aws-s3-bucket/blob/f90d8a385e4c70afd048e8997dcccf125b362236/main.tf#L934

@RealOrangeOne RealOrangeOne requested a review from tomusher June 18, 2025 13:45
@RealOrangeOne RealOrangeOne force-pushed the harden-https-requirement branch from a27fb9a to d6ee06a Compare June 18, 2025 13:47
@tomusher
Copy link
Member

tomusher commented Jan 5, 2026

Looks good to me!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants