General information about bucket policies
You can configure bucket access through a bucket policy. A policy consists of rules that allow or deny actions on a resource (a bucket or a group of objects) for all or selected users. The main principle is that once a bucket policy is created, everything that is not allowed is denied.
A bucket policy works for any authorized access. Authorized access is considered viewing and managing buckets and their objects via the control panel and API. Unauthorized access is considered requests to objects in public buckets via the bucket public domain or custom domains.
The Bucket Policy has a maximum size limit of 20 KB.
A bucket policy can apply to any user granted access to storage according to the role model, and also defines access for users with the s3.user, s3.bucket.user, and object_storage_user roles. Learn more about the interaction between the role model and bucket policies in the Manage access to S3 guide.
Bucket policies can be managed by the Account Owner and users with the member role. If a user with the member role has the Projects scope of access selected, the corresponding project must be added to their permissions.
You can create bucket policies and manage them in the control panel or via the S3 API in accordance with the requirements for the policy structure.
Bucket Policy structure
The Bucket Policy has a JSON structure. Example policy:
{
"Id": "my-bucket-policy",
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowObjectDeletion",
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Action": [
"s3:DeleteObject"
],
"Resource": [
"arn:aws:s3:::bucket-name",
"arn:aws:s3:::bucket-name/*",
"arn:aws:s3:::bucket-name/${aws:userid}/*"
],
"Condition": {
"StringEquals": {
"aws:UserAgent": [
"storage-test-user-agent"
]
}
}
},
{
"Effect": "Deny",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucket-name/*"
}
]
}
Policy content:
Rules
There are two types of rules: allow (Allow) and deny (Deny).
The allow or deny applies to the actions, resources, and users added to the rule.
If a policy contains several rules, they are applied as follows:
- if at least one allow rule is met, access will be allowed;
- if at least one deny rule is met, access will be denied;
- if both allow and deny rules are met, access will be denied;
- if no rules are met, access will be denied.
Users
The rule applies to requests from principals (users):
- to authorized requests from specific users, user IDs are specified (you can view the service user ID in the control panel);
- to all authorized requests, indicated by the
*symbol.
You can add control panel users as principals only when configuring a policy via the control panel.
Resources
Resources are a bucket or a set of objects to which the rule applies. You can only specify resources associated with the bucket for which the policy is being configured.
Resources can be specified in the following formats:
arn:aws:s3:::<bucket-name>— bucket resource, you can specify only one resource in this format (the bucket for which the policy is being configured). The resource will work for actions related to bucket configuration and does not apply to its objects;arn:aws:s3:::<bucket-name>/<prefix>— bucket object resource, where<prefix>is the prefix for objects to which the rule will apply. If you specify*, all bucket objects will be included in the resources;arn:aws:s3:::<bucket-name>/${<variable-name>}— bucket object resource, where<variable-name>is the name of a substitution variable (key) that acts as a prefix.
Actions
If you specify *, all actions will be included in the rule.
Conditions
A condition determines when the rule will work. A condition consists of a key, operator, and value.
If evaluating the condition returns true, the condition is met.
Keys
A single key can be used in several conditions. A key can be assigned several values.
Operators
Operators compare values from the resource request with the value specified in the key value in the condition.
Numbers
Strings
Date and time
IP addresses
Bool
IfExists
Null
The number from the request is compared with the number specified in the condition.