Files

115 lines
3.8 KiB
Markdown

As part of the data migration process, the Nautilus DevOps team is actively creating several S3 buckets on AWS using Terraform. They plan to utilize both private and public S3 buckets to store the relevant data. Given the ongoing migration of other infrastructure to AWS, it is logical to consolidate data storage within the AWS environment as well.
Create an S3 bucket using Terraform with the following details:
1) The name of the S3 bucket must be xfusion-s3-6464.
2) The S3 bucket must block all public access, making it a private bucket.
The Terraform working directory is /home/bob/terraform. Create the main.tf file (do not create a different .tf file) to accomplish this task.
Notes:
Use Terraform to provision the S3 bucket.
Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.
Ensure the resources are created in the us-east-1 region.
The bucket must have block public access enabled to restrict any public access.
## Solution
# Private S3 Bucket — `xfusion-s3-6464`
Terraform solution to provision a fully private S3 bucket in `us-east-1`, with all public access blocked.
## `main.tf`
```hcl
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 6.0"
}
}
}
provider "aws" {
region = "us-east-1"
}
resource "aws_s3_bucket" "xfusion" {
bucket = "xfusion-s3-6464"
}
resource "aws_s3_bucket_public_access_block" "xfusion" {
bucket = aws_s3_bucket.xfusion.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}
```
## How to run
```bash
cd /home/bob/terraform
terraform init
terraform apply -auto-approve
```
## How it works
### `aws_s3_bucket`
Creates the bucket itself. The `bucket` argument sets the globally-unique name
(`xfusion-s3-6464`) exactly as required. Provider region `us-east-1` places it in
the correct region. On its own a modern bucket is already private by default, but
the task explicitly wants **Block Public Access enabled**, which is a separate
resource.
### `aws_s3_bucket_public_access_block`
This is the resource that actually satisfies the requirement. It manages the four
independent Block Public Access (BPA) switches on the bucket. Setting all four to
`true` guarantees the bucket can never be exposed publicly — regardless of what ACL
or bucket policy someone later attaches.
| Flag | `true` means |
|------|--------------|
| `block_public_acls` | Reject any **new** request that would apply a public ACL. |
| `ignore_public_acls` | Ignore any public ACLs **already** on the bucket/objects. |
| `block_public_policy` | Reject any **new** bucket policy that grants public access. |
| `restrict_public_buckets` | If a public policy somehow exists, only allow access to the bucket owner / AWS services — cross-account and anonymous access is denied. |
The distinction that trips people up: `block_*` flags act at *write* time (they
stop you from adding public grants), while `ignore_*` / `restrict_*` flags act at
*evaluation* time (they neutralize public grants that are already present). Turning
on all four covers both directions, which is why "block **all** public access" maps
to every flag being `true`.
### Why no ACL / ownership resources here
Unlike the public-bucket case, a private bucket needs **no** `aws_s3_bucket_acl` or
`aws_s3_bucket_ownership_controls`. AWS defaults new buckets to `BucketOwnerEnforced`
(ACLs disabled) and applies BPA — both of which push toward *private*. We're moving
with the defaults, not against them, so the config stays minimal.
## Verify
```bash
aws s3api get-public-access-block --bucket xfusion-s3-6464 \
--query 'PublicAccessBlockConfiguration'
```
Expected output — all four `true`:
```json
{
"BlockPublicAcls": true,
"IgnorePublicAcls": true,
"BlockPublicPolicy": true,
"RestrictPublicBuckets": true
}
```