Preventing Deletion of an Amazon S3 Bucket Using a Resource-Based Policy

30 minutes
  • 3 Learning Objectives

About this Hands-on Lab

In this hands-on lab, you are a software engineer working for a new startup that is launching an online bookstore for rare and antique books. The founder, Kia, needs your help with protecting her data.Since her technical lead is out sick, she’s calling on you for assistance. In order to protect the book data stored in S3, you will use a resource-based policy in AWS Identity & Access Management (IAM), to prevent an Amazon S3 bucket from being deleted.

Learning Objectives

Successfully complete this lab by achieving the following learning objectives:

Use the AWS Policy Generator to Generate a Resource Policy
  1. Navigate to AWS Policy Generator.
  2. Set the following values:
    • Type of Policy: S3 Bucket Policy
    • Effect: Deny
    • Principal: *
    • Actions: DeleteBucket
    • ARN: *
  3. Click Add Statement.
  4. Click Generate Policy.
  5. Copy the policy to the clipboard.
Attach a Resource Policy to an S3 Bucket
  1. Log in to the AWS Management Console.
  2. Navigate to S3.
  3. Create a new bucket, and add the policy generated earlier to the Permissions tab.
  4. Copy the bucket ARN number.
  5. In the bucket policy, update the "Resource" and replace "*" with the copied bucket ARN number.
  6. Click Save changes.
Test the Resource Policy
  1. Navigate back to S3.
  2. Select the created S3 bucket from the list and click Delete.
  3. Enter the bucket name and click Delete bucket. Was the bucket deleted?
  4. Select the lab-provided S3 bucket from the list and click Delete.
  5. Enter the bucket name and click Delete bucket. Was the lab-provided bucket deleted?

Additional Resources

Make sure you are using the US-EAST-1 region.

What are Hands-on Labs

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?