Permission Boundary Check
Rule Details
Parameter |
Description |
---|---|
Rule Name |
obs-bucket-policy-not-more-permissive |
Identifier |
obs-bucket-policy-not-more-permissive |
Description |
If an OBS bucket has a policy that allows more permissions than the specified policy, this bucket is noncompliant. |
Tag |
obs, access-analyzer-verified |
Trigger Type |
Configuration change |
Filter Type |
obs.buckets |
Configure Rule Parameters |
controlPolicy: the provided policy that defines the permission boundary. |
Application Scenarios
A bucket policy applies to the configured OBS bucket and objects in the bucket. You can use bucket policies to control the access of IAM users or other account to your OBS buckets. You are advised to apply the principle of least privilege to ensure that a bucket policy only grants necessary permissions for certain tasks.
Solution
You can modify policies for noncompliant buckets through the visual editor or the JSON view to restrict access from other objects than the authorized ones.
Rule Logic
- If an OBS bucket policy allows more permissions than the specified controlPolicy, this bucket is noncompliant.
- If an OBS bucket policy does not allow more permissions than the specified controlPolicy, this bucket is compliant.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot