Deny non-SDK and "NotIPAddress" in AWS S3 bucket policy

Viewed 38

everyone. I have a situation in which I want a web application to add / update files to an S3 bucket, and then have only specified IPs be able to read these files. My web application uses AWS SDK to access the S3 bucket and upload files. So, in other words, I want SDK and specified IPs access to the bucket, and otherwise deny access.

I tried doing this through the S3 bucket policy but was unable to make it work. My latest attempt at the policy is as follows:

{
  "Version": "2012-10-17",
  "Id": "MyPolicy",
  "Statement": [
    {
      "Sid": "MyPolicy",
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": [
        "arn:aws:s3:::my-bucket",
        "arn:aws:s3:::my-bucket/*"
      ],
      "Condition": {
        "StringNotLike": {
          "aws:SourceIp": [
            "11.11.11.111/32",
            "22.22.22.222/32",
            "333.333.33.333/32",
            "444.444.44.444/32"
          ],
          "aws:SourceAccount": [
            "123456789012"
          ]
        }
      }
    }
  ]
}

This did not work, however, as it blocked even the bucket owner / root account from accessing files. Any help is appreciated, thanks in advance!

0 Answers
Related