From 91dc0f282964e3c519f2462808a2d3a8d62d4d42 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 17 Jun 2026 14:43:41 -0400 Subject: [PATCH] Harden S3: codify PublicAccessBlockConfiguration on payment buckets (#49) Add PublicAccessBlockConfiguration (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets all true) to PaymentsCsvBucket and PayrollEmailBucket. Codifies the already-private runtime state (account-level and bucket-level S3 BPA already enabled). Zero functional change; clears checkov CKV_AWS_53/54/55/56. --- template.yaml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/template.yaml b/template.yaml index 5496e93..c351ba8 100644 --- a/template.yaml +++ b/template.yaml @@ -162,6 +162,11 @@ Resources: Type: AWS::S3::Bucket Properties: BucketName: !Sub seahaven-payments-csv-${AWS::AccountId} + PublicAccessBlockConfiguration: + BlockPublicAcls: true + IgnorePublicAcls: true + BlockPublicPolicy: true + RestrictPublicBuckets: true DashboardTable: Type: AWS::DynamoDB::Table @@ -190,6 +195,11 @@ Resources: Type: AWS::S3::Bucket Properties: BucketName: !Sub seahaven-payroll-emails-${AWS::AccountId} + PublicAccessBlockConfiguration: + BlockPublicAcls: true + IgnorePublicAcls: true + BlockPublicPolicy: true + RestrictPublicBuckets: true LifecycleConfiguration: Rules: - Id: ExpireEmails