Skip to content

(s3): SSL should be enforced by default #18283

@dontirun

Description

@dontirun

Description

SSL should be enforced by default if not using static web hosting

Use Case

As noted here, it's a best practice to use HTTPs communication for S3 buckets. I think it's a sensible default to have this feature be opt-out vs opt-in with logic to keep this disabled for static web hosting

Proposed Solution

  1. Enable SSL by default for buckets without static web hosting enabled
  2. Disable by default for buckets with static web hosting enabled

Other information

No response

Acknowledge

  • I may be able to implement this feature request
  • This feature might incur a breaking change

Metadata

Metadata

Assignees

No one assigned

    Labels

    @aws-cdk/aws-s3Related to Amazon S3closed-for-stalenessThis issue was automatically closed because it hadn't received any attention in a while.effort/smallSmall work item – less than a day of effortfeature-requestA feature should be added or improved.p2

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions