Access All Buckets Without Delete Access
AWS S3: Access All Buckets Without Delete Access
This tutorial shows how to give an IAM user access to all S3 buckets in the AWS account for listing, reading and uploading objects, while preventing delete operations.
What the Policy Allows
- View all S3 buckets
- List objects in all buckets
- Download and read objects
- Upload and overwrite objects
- View object versions
- Use common S3 console functions
What the Policy Blocks
- Delete an S3 bucket
- Delete an object
- Delete an object version
- Abort a multipart upload
IAM Policy
Use this identity-based policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "S3ConsoleAccess",
"Effect": "Allow",
"Action": [
"s3:ListAllMyBuckets",
"s3:GetAccountPublicAccessBlock",
"s3:GetBucketAcl",
"s3:GetBucketLocation",
"s3:GetBucketPolicyStatus",
"s3:GetBucketPublicAccessBlock",
"s3:ListAccessPoints"
],
"Resource": "*"
},
{
"Sid": "S3BucketReadWrite",
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:ListBucketVersions",
"s3:ListBucketMultipartUploads"
],
"Resource": "arn:aws:s3:::*"
},
{
"Sid": "S3ObjectReadWrite",
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:GetObjectVersion",
"s3:GetObjectAcl",
"s3:GetObjectTagging",
"s3:PutObject",
"s3:PutObjectAcl",
"s3:PutObjectTagging",
"s3:ListMultipartUploadParts"
],
"Resource": "arn:aws:s3:::*/*"
},
{
"Sid": "ExplicitlyDenyBucketDelete",
"Effect": "Deny",
"Action": [
"s3:DeleteBucket"
],
"Resource": "arn:aws:s3:::*"
},
{
"Sid": "ExplicitlyDenyObjectDelete",
"Effect": "Deny",
"Action": [
"s3:DeleteObject",
"s3:DeleteObjectVersion",
"s3:AbortMultipartUpload"
],
"Resource": "arn:aws:s3:::*/*"
}
]
}How to Add the Policy
Open AWS Console → IAM → Users → Your User → Permissions → Add permissions → Create inline policy.
Select the JSON editor, paste the policy, review it, and save it.
Test the Access
List all buckets:
aws s3 lsList objects:
aws s3 ls s3://YOUR-BUCKET-NAME/Upload an object:
aws s3 cp test.txt s3://YOUR-BUCKET-NAME/test.txtDownload an object:
aws s3 cp s3://YOUR-BUCKET-NAME/test.txt .Test delete access:
aws s3 rm s3://YOUR-BUCKET-NAME/test.txtThe delete command should return AccessDenied.
Important
PutObject allows overwriting an existing object with the same key. This policy prevents deletion, but it does not make objects immutable.
For common S3 console access, AWS documents permissions such as ListAllMyBuckets, GetBucketLocation, GetBucketAcl, GetBucketPolicyStatus, GetBucketPublicAccessBlock, GetAccountPublicAccessBlock and ListAccessPoints.
Suggested category: AWS
Discussion (0)