Terraform AWS S3 Bucket
S3 buckets with versioning, default encryption, public access blocks, bucket policies, access logging, lifecycle rules, replication, event notifications, and optional object lock controls.
Controls enforced
These compliance controls are checked at terraform plan time.
- S3 buckets should not use ACLs for user access control(low effort)
- S3 buckets should have cross-region replication enabled(medium effort)
- S3 buckets should have default encryption enabled(low effort)
- S3 buckets should have default encryption enabled using KMS(low effort)
- S3 buckets should have event notifications enabled(low effort)
- S3 buckets should have lifecycle policies configured(low effort)
- S3 buckets should have logging enabled(low effort)
- S3 buckets should have MFA delete enabled(medium effort)
- S3 buckets should not be accessible to all authenticated users(low effort)
- S3 bucket Object Lock should use COMPLIANCE retention mode
- S3 buckets should have object lock enabled(low effort)
- S3 buckets should have policies that prohibit public access(low effort)
- S3 buckets should restrict cross-account permissions(medium effort)
- S3 buckets should prohibit public read access(low effort)
- S3 buckets should prohibit public write access(low effort)
- S3 buckets should have static website hosting disabled(low effort)
- S3 buckets with versioning enabled should have lifecycle policies configured(low effort)
- S3 buckets should have versioning enabled(low effort)
- S3 public access should be blocked at account level(low effort)
- S3 public access should be blocked at bucket level(low effort)
Quick start
View this module on the compliance.tf registry — versions, inputs, and outputs →
See the Get Started guide and Registry Endpoints for details on how to customize the module for your requirements.
Migration from upstream
Already using terraform-aws-modules? Change only the source URL:
module "s3-bucket" {
source = "terraform-aws-modules/s3-bucket/aws"
version = ">= 5.0.0"
}module "s3-bucket" {
source = "soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws"
version = ">= 5.0.0"
}Same arguments. Same outputs. Controls are checked at terraform plan. See the Migration Guide for step-by-step instructions.
Reversibility
No lock-in. Switch back by reverting the source URL:
module "s3-bucket" {
source = "terraform-aws-modules/s3-bucket/aws"
}Run terraform init -upgrade. Terraform state is unchanged — same resource addresses, same provider, no compliance.tf-specific resources. Controls you already applied remain in AWS.
Mapped compliance frameworks
Framework coverage
Which controls from this module are active under each framework endpoint.
● enforced by default · ○ not activated by this endpoint
Known Terraform limitations
Separately from the controls above, some things people ask this module for cannot be implemented by any module in any registry - they are limits of Terraform itself. Known limitations for this module lists the recurring ones: what causes each, the native workaround in full, and - where one exists - the opt-in Operational Rule that removes the need for a fork.