Open ifeach opened 2 years ago
Hi @ifeach - We was affected by this wrong CFN drift result as well, once we set ObjectOwnership
for AWS::S3::Bucket
. I heard from ServiceTeam that a fix in this area had been deployed. Now our stack with S3-Buckets + ObjectOwnership are IN_SYNC.
May you can re-test on your side as well (maybe also regarding this ReplicationConfiguration - I doesn't have a stack with this setting here on my end).
Same issue here, also with other settings:
"PublicAccessBlockConfiguration"
(blockPublicAccess
in CDK)"VersioningConfiguration"
(versioned
in CDK)The aformentioned settings were confirmed using s3 console, but were not picked up by:
After removing the offending settings, deploying the change, and then adding the settings again and deploying again (using cdk), the stack is now in sync, with all expected settings.
Not sure if it matters, but, the bucket is old, created in 2017.
Name of the resource
AWS::S3::Bucket
Resource Name
No response
Issue Description
CloudFormation falsely reports drift when a bucket is created with ObjectOwnership property. The actual property of the bucket shows the ObjectOwnership property set but CFN drift does not reflect this thereby causing a false positive.
A similar behavior can be seen when a bucket is created with the ReplicationConfiguration V2 (includes "Priority" and "Filter" and "DeleteMarkerReplication" parameters). CloudFormation shows a false positive as it returns the actual properties of the bucket missing some of the S3 bucket properties such as the Filters, DeleteMarkerReplication and Priority. Because of this the stack shows a drift as though these properties have been removed.
Expected Behavior
Accurately return the actual resource properties so that it matches the stack template
Observed Behavior
Inaccurate drift result
Test Cases
Create an S3 bucket with either the ReplicationConfiguration or ObjectOwnership properties or both and after stack creation, run a drift check, CFN returns a false positive
Other Details
No response