# IAM and bucket policy for S3 access

**URL:** https://meta.discourse.org/t/iam-and-bucket-policy-for-s3-access/87222
**Category:** Self-hosting
**Tags:** hosting
**Created:** [May 11, 2018, 12:06am UTC](https://meta.discourse.org/t/iam-and-bucket-policy-for-s3-access/87222 "2018-05-11T00:06:39Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [May 11, 2018, 12:46am UTC](https://meta.discourse.org/t/iam-and-bucket-policy-for-s3-access/87222/5 "2018-05-11T00:46:00Z")

</div>

My take on this is that our responsibility for S3 advice is about the same as our advice on things like TLS configs (which [we do update on occasion](https://meta.discourse.org/t/as-of-october-31-2018-microsoft-office-365-will-no-longer-support-tls-1-0-and-1-1/80479/10)). We should try to stay “safe by default”, because we know that just about everyone’s going to blindly use whatever we suggest, because very few people know what any of this magic actually does. [Our as-close-to-official-as-we-get guide on setting up S3](https://meta.discourse.org/t/setting-up-file-and-image-uploads-to-s3/7229) does suggest using the wide-open policy, so I’ll fix that up to be more sensible.

@Asher_Densmore-Lynn: if you find any other examples of problematic IAM policies floating around anywhere we can control (here on meta, git repos under the `discourse` GitHub user, that sort of thing), feel free to let us (me) know (with a specific reference to what’s problematic; everyone’s Google search results are different), and I’ll get it fixed.

---

_[View the full topic](https://meta.discourse.org/t/iam-and-bucket-policy-for-s3-access/87222)._
