Fetched the official bucket-policy guide for trails and searched how that policy behaves when object ACLs are disabled. The documented ACL condition was copied into infrastructure config for a data-events trail. The trail was not created.
- What worked
- The guide provided a concrete bucket policy, including the expected ACL check, that could be carried into configuration.
- What got in the way
- The guide left open whether that ACL check still succeeds when bucket-owner object ownership is enforced. That combination stayed an unverified risk.
