You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何自动加密Serverless Framework创建的CloudFormation S3存储桶?

Encrypting & Securing S3 Buckets Created by Serverless Framework

Absolutely! You can enforce encryption and strict private access for both the S3 buckets Serverless Framework spins up for its own deployment artifacts and any S3 buckets you define in your CloudFormation templates through Serverless. Let’s break down how to handle both scenarios:

1. Encrypt Serverless's Own Deployment Bucket

Serverless automatically creates an S3 bucket to store your deployment packages (ZIP files) and CloudFormation templates by default. To ensure this bucket is encrypted and private, add the deploymentBucket configuration under the provider section in your serverless.yml:

provider:
  name: aws
  # Other provider settings...
  deploymentBucket:
    # Optional: Specify a custom bucket name (otherwise Serverless generates one)
    name: my-company-serverless-deployments
    # Enable server-side encryption (SSE-S3 with AES256, or use KMS below)
    serverSideEncryption: AES256
    # Alternatively, use a custom KMS key:
    # serverSideEncryption: aws:kms
    # kmsKeyArn: arn:aws:kms:us-east-1:123456789012:key/your-kms-key-id
    # Enforce full public access block to keep the bucket private
    blockPublicAccess: true
    # Optional: Add tags for organization
    tags:
      Environment: production
      Service: serverless-deployments

This configuration ensures the deployment bucket uses server-side encryption and blocks all public access, aligning with your requirements.

2. Encrypt S3 Buckets Defined in Your CloudFormation Resources

For any S3 buckets you explicitly define in the resources section of your serverless.yml, you’ll need to add encryption and public access block settings directly to the bucket’s CloudFormation properties:

resources:
  Resources:
    MyApplicationDataBucket:
      Type: AWS::S3::Bucket
      Properties:
        BucketName: my-app-private-data-bucket
        # Enforce full public access restriction
        PublicAccessBlockConfiguration:
          BlockPublicAcls: true
          BlockPublicPolicy: true
          IgnorePublicAcls: true
          RestrictPublicBuckets: true
        # Enable server-side encryption
        BucketEncryption:
          ServerSideEncryptionConfiguration:
            - ServerSideEncryptionByDefault:
                # Use SSE-S3 (AES256)
                SSEAlgorithm: AES256
                # Or use a custom KMS key (uncomment below)
                # KMSMasterKeyID: arn:aws:kms:us-east-1:123456789012:key/your-key-id
    # Optional: Add a bucket policy to enforce HTTPS access
    MyBucketPolicy:
      Type: AWS::S3::BucketPolicy
      Properties:
        Bucket: !Ref MyApplicationDataBucket
        PolicyDocument:
          Version: "2012-10-17"
          Statement:
            - Effect: Deny
              Principal: "*"
              Action: "s3:*"
              Resource: !Sub "${MyApplicationDataBucket}/*"
              Condition:
                Bool:
                  "aws:SecureTransport": false

The PublicAccessBlockConfiguration ensures no public access is allowed, while BucketEncryption enables automatic encryption for all objects stored in the bucket. The optional bucket policy adds an extra layer of security by requiring HTTPS for all access.

Bonus: Enforce These Settings Across Your Team

If you want to make sure these encryption and privacy rules are followed for all deployments in your team:

  • Commit the deploymentBucket configuration to your serverless.yml so it’s applied automatically on every sls deploy.
  • Use AWS Service Control Policies (SCPs) at the organization or OU level to enforce that all S3 buckets must have encryption enabled and public access blocked, regardless of deployment tooling.

内容的提问来源于stack exchange,提问作者Ahsan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 17:12:44