如何自动加密Serverless Framework创建的CloudFormation S3存储桶?
Absolutely! You can enforce encryption and strict private access for both the S3 buckets Serverless Framework spins up for its own deployment artifacts and any S3 buckets you define in your CloudFormation templates through Serverless. Let’s break down how to handle both scenarios:
1. Encrypt Serverless's Own Deployment Bucket
Serverless automatically creates an S3 bucket to store your deployment packages (ZIP files) and CloudFormation templates by default. To ensure this bucket is encrypted and private, add the deploymentBucket configuration under the provider section in your serverless.yml:
provider: name: aws # Other provider settings... deploymentBucket: # Optional: Specify a custom bucket name (otherwise Serverless generates one) name: my-company-serverless-deployments # Enable server-side encryption (SSE-S3 with AES256, or use KMS below) serverSideEncryption: AES256 # Alternatively, use a custom KMS key: # serverSideEncryption: aws:kms # kmsKeyArn: arn:aws:kms:us-east-1:123456789012:key/your-kms-key-id # Enforce full public access block to keep the bucket private blockPublicAccess: true # Optional: Add tags for organization tags: Environment: production Service: serverless-deployments
This configuration ensures the deployment bucket uses server-side encryption and blocks all public access, aligning with your requirements.
2. Encrypt S3 Buckets Defined in Your CloudFormation Resources
For any S3 buckets you explicitly define in the resources section of your serverless.yml, you’ll need to add encryption and public access block settings directly to the bucket’s CloudFormation properties:
resources: Resources: MyApplicationDataBucket: Type: AWS::S3::Bucket Properties: BucketName: my-app-private-data-bucket # Enforce full public access restriction PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true # Enable server-side encryption BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: # Use SSE-S3 (AES256) SSEAlgorithm: AES256 # Or use a custom KMS key (uncomment below) # KMSMasterKeyID: arn:aws:kms:us-east-1:123456789012:key/your-key-id # Optional: Add a bucket policy to enforce HTTPS access MyBucketPolicy: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref MyApplicationDataBucket PolicyDocument: Version: "2012-10-17" Statement: - Effect: Deny Principal: "*" Action: "s3:*" Resource: !Sub "${MyApplicationDataBucket}/*" Condition: Bool: "aws:SecureTransport": false
The PublicAccessBlockConfiguration ensures no public access is allowed, while BucketEncryption enables automatic encryption for all objects stored in the bucket. The optional bucket policy adds an extra layer of security by requiring HTTPS for all access.
Bonus: Enforce These Settings Across Your Team
If you want to make sure these encryption and privacy rules are followed for all deployments in your team:
- Commit the
deploymentBucketconfiguration to yourserverless.ymlso it’s applied automatically on everysls deploy. - Use AWS Service Control Policies (SCPs) at the organization or OU level to enforce that all S3 buckets must have encryption enabled and public access blocked, regardless of deployment tooling.
内容的提问来源于stack exchange,提问作者Ahsan

