Harden S3: codify PublicAccessBlockConfiguration on payment buckets (#49)

Add PublicAccessBlockConfiguration (BlockPublicAcls, IgnorePublicAcls,
BlockPublicPolicy, RestrictPublicBuckets all true) to PaymentsCsvBucket
and PayrollEmailBucket. Codifies the already-private runtime state
(account-level and bucket-level S3 BPA already enabled). Zero functional
change; clears checkov CKV_AWS_53/54/55/56.
This commit is contained in:
Adam Moussa 2026-06-17 14:43:41 -04:00 • committed by GitHub
parent c55e241c4a
commit 91dc0f2829
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -162,6 +162,11 @@ Resources:
Type: AWS::S3::Bucket Type: AWS::S3::Bucket
Properties: Properties:
BucketName: !Sub seahaven-payments-csv-${AWS::AccountId} BucketName: !Sub seahaven-payments-csv-${AWS::AccountId}
PublicAccessBlockConfiguration:
BlockPublicAcls: true
IgnorePublicAcls: true
BlockPublicPolicy: true
RestrictPublicBuckets: true
DashboardTable: DashboardTable:
Type: AWS::DynamoDB::Table Type: AWS::DynamoDB::Table
@ -190,6 +195,11 @@ Resources:
Type: AWS::S3::Bucket Type: AWS::S3::Bucket
Properties: Properties:
BucketName: !Sub seahaven-payroll-emails-${AWS::AccountId} BucketName: !Sub seahaven-payroll-emails-${AWS::AccountId}
PublicAccessBlockConfiguration:
BlockPublicAcls: true
IgnorePublicAcls: true
BlockPublicPolicy: true
RestrictPublicBuckets: true
LifecycleConfiguration: LifecycleConfiguration:
Rules: Rules:
- Id: ExpireEmails - Id: ExpireEmails