Skip to main content

Command Palette

Search for a command to run...

Amazon S3

AWS Simple Scalable Storage:

Updated
•30 min read•View as Markdown
P

As a associate system administrator I worked on Redhat Linux servers, including user management, permissions, services, and performance monitoring Automated routine administrative tasks using Bash scripting and cron jobs, reducing manual effort by ~30% I am aws certified sysops administrator and Google Certified Cloud Engineer. Determined to transition my career into cloud architect /Cloud Support role

Cheat Sheet :

  • S3 stores data as objects within buckets.

  • An object consists of a file and optionally any metadata that describes that file.

  • A key is a unique identifier for an object within a bucket.

  • Storage capacity is virtually unlimited.

Buckets

  • For each bucket, you can:

    • Control access to it (create, delete, and list objects in the bucket)

    • View access logs for it and its objects

    • Choose the geographical region where to store the bucket and its contents.

  • Bucket name must be a unique DNS-compliant name.

    • The name must be unique across all existing bucket names in Amazon S3.

    • After you create the bucket you cannot change the name.

    • The bucket name is visible in the URL that points to the objects that you’re going to put in your bucket.

  • By default, you can create up to 10,000 buckets in each of your AWS accounts (increased from the previous 100 limit).

    • You can request a quota increase up to 1 million buckets.

    • Creating up to 2,000 buckets is free; a small monthly fee applies for each additional bucket beyond 2,000.

  • You can’t change its Region after creation.

  • Directory Buckets: A new type of bucket used specifically for S3 Express One Zone to achieve single-digit millisecond latency.

  • You can host static websites by configuring your bucket for website hosting.

  • You can’t delete an S3 bucket using the Amazon S3 console if the bucket contains 100,000 or more objects. You can’t delete an S3 bucket using the AWS CLI if versioning is enabled.

Data Consistency Model

  • Strong Read-After-Write Consistency: Amazon S3 now provides strong consistency for all requests.

    • After a successful write (PUT) of a new object, or an overwrite or delete of an existing object, any subsequent read request (GET, HEAD, or LIST) immediately receives the latest version of the object.

    • This applies to all S3 operations in all Regions.

  • Eventual Consistency (Exceptions):

    • Bucket Configurations: Changes to bucket-level configurations (like enabling Versioning or Public Access Block) may take a short time to propagate across AWS.

    • Bucket Listing: If you delete a Bucket (not an object), it might still appear in the list of buckets for a short time.

Storage Classes

  • Storage Classes for Frequently Accessed Objects

    • S3 STANDARD for general-purpose storage of frequently accessed data.

    • S3 EXPRESS ONE ZONE is a high-performance, single AZ storage class designed to deliver consistent single-digit millisecond data access for frequently accessed data and latency-sensitive applications. It can improve data access speeds by 10x and reduce request costs by 50% compared to S3 Standard and scales to process millions of requests per minute (This class requires the use of Directory Buckets).

  • Storage Classes for Infrequently Accessed Objects

    • S3 STANDARD_IA for long-lived, but less frequently accessed data. It stores the object data redundantly across multiple geographically separated AZs.

    • S3 ONEZONE_IA stores the object data in only one AZ. Less expensive than STANDARD_IA, but data is not resilient to the physical loss of the AZ.

    • These two storage classes are suitable for objects larger than 128 KB that you plan to store for at least 30 days. If an object is less than 128 KB, Amazon S3 charges you for 128 KB. If you delete an object before the 30-day minimum, you are charged for 30 days.

  • Amazon S3 Intelligent Tiering

    • S3 Intelligent-Tiering is a storage class designed for customers who want to optimize storage costs automatically when data access patterns change, without performance impact or operational overhead.

    • S3 Intelligent-Tiering is the first cloud object storage class that delivers automatic cost savings by moving data between two access tiers — frequent access and infrequent access — when access patterns change, and is ideal for data with unknown or changing access patterns.

    • S3 Intelligent-Tiering monitors access patterns and moves objects that have not been accessed for 30 consecutive days to the Infrequent Access tier. If objects haven’t been accessed for 90 consecutive days, they are moved to the Archive Instant Access tier (which still provides millisecond access).

      • If an object in the infrequent or archive instant access tier is accessed later, it is automatically moved back to the Frequent Access tier.
    • S3 Intelligent-Tiering supports optional asynchronous archive capabilities. You can configure it so that after 90 days (Archive Access) or 180 consecutive days of no access, it is moved to the Deep Archive Access tier.

    • There are no retrieval fees in S3 Intelligent-Tiering.

  • Tutorials dojo strip

  • S3 GLACIER

    • For long-term archive

    • S3 Glacier provides the following storage classes: S3 Glacier Instant Retrieval, S3 Glacier Flexible Retrieval, and S3 Glacier Deep Archive.

    • Archived objects in Flexible Retrieval and Deep Archive are not available for real-time access. You must first restore the objects before you can access them.

    • You can now specify Glacier Flexible Retrieval or Deep Archive as the storage class at the time you create/upload an object (via API/Console).

    • Retrieval Options

      • Expedited – allows you to quickly access your data when occasional urgent requests for a subset of archives are required. For all but the largest archived objects, data accessed are typically made available within 1–5 minutes. There are two types of Expedited retrievals: On-Demand requests are similar to EC2 On-Demand instances and are available most of the time. Provisioned requests are guaranteed to be available when you need them.

      • Standard – allows you to access any of your archived objects within several hours. Standard retrievals typically complete within 3–5 hours. This is the default option for retrieval requests that do not specify the retrieval option.

      • Bulk – Glacier’s lowest-cost retrieval option, enabling you to retrieve large amounts, even petabytes, of data inexpensively in a day. Bulk retrievals typically complete within 5–12 hours.

    • For S3 Standard, S3 Standard-IA, and Glacier storage classes, your objects are automatically stored across multiple devices spanning a minimum of three Availability Zones.

 

S3 Standard

S3 Express One Zone**

S3 intelligent-Tiering *

Designed for durability

99.999999999%

(11 9’ s)

Designed for availability

99.99%

99.95%

99.99%

Availability SLA

99.9%

99.9%

99%

Availability Zones 

>=3

1

>=3

Minimum capacity charge per object

N/A

512 KB

N/A

Minimum storage duration charge

N/A

1 hour

30 days

Retrieval fee

N/A

N/A

N/A

First byte latency

milliseconds

single-digit milliseconds

milliseconds

Storage type

Object

Object

Object

Lifecycle transitions 

Yes

No

Yes

 

S3 Standard-IA 

S3 One Zone-IA **

S3 Glacier Instant Retrieval

Designed for durability

99.999999999%

(11 9’ s)

Designed for availability

99.99%

99.5%

99.9%

Availability SLA

99%

99%

99%

Availability Zones 

>=3

1

>=3

Minimum capacity charge per object

128KB

128KB

128KB

Minimum storage duration charge

30 days

30 days

90 days

Retrieval fee

per GB retrieved

per GB retrieved

per GB retrieved

First byte latency

milliseconds

milliseconds

milliseconds

Storage type

Object

Object

Object

Lifecycle transitions 

Yes

Yes

Yes

 

S3 Glacier Flexible Retrieval

S3 Glacier Deep Archive

 

Designed for durability

99.999999999%

(11 9’ s) 

Designed for availability

99.99%

99.99%

 

Availability SLA

99%

99.9%

 

Availability Zones 

>=3

>=3

 

Minimum capacity charge per object

40KB

40 KB

 

Minimum storage duration charge

90 days

180 days

 

Retrieval fee

per GB retrieved

per GB retrieved

 

First byte latency

minutes or hours

hours

 

Storage type

Object

Object

 

Lifecycle transitions 

Yes

Yes

 

  • Amazon S3 Glacier Instant Retrieval

    • A storage class for long-lived data that are rarely accessed and must be retrieved in milliseconds.

    • When your data is accessed only once every quarter, you can save costs on storage compared to using S3 Standard-IA.

    • The data stored in S3 Glacier Instant Retrieval storage class is resilient in the event of the destruction of one entire Availability Zone.

  • Amazon S3 Glacier Flexible Retrieval

    • A storage class for storing archive data that is accessed once or twice per year.

    • S3 Glacier Flexible Retrieval provides the most cost-effective retrieval options, with access times ranging from minutes to hours and free bulk retrievals.

  • Amazon S3 Glacier Deep Archive

    • An Amazon S3 storage class that provides secure and durable object storage for long-term retention of data that is accessed rarely in a year.

    • S3 Glacier Deep Archive offers the lowest cost storage in the cloud, at prices lower than storing and maintaining data in on-premises magnetic tape libraries or archiving data offsite.

    • All objects stored in the S3 Glacier Deep Archive storage class are replicated and stored across at least three geographically-dispersed Availability Zones, protected by 99.999999999% durability, and can be restored within 12 hours (Standard) or 48 hours (Bulk).

  • Amazon S3 on Outposts

    • Amazon S3 on Outposts uses S3 APIs to deliver object storage to an on-premises AWS Outposts environment.

    • The data is encrypted with SSE-C and SSE-S3 and redundantly stored across Outposts servers.

    • With AWS DataSync, you can automate data transfer between Outposts and AWS Regions.

    • You can use access points to access any object in an Outposts bucket.

    • Supports S3 lifecycle rules.

S3 API

  • REST: Use standard HTTP requests to create, fetch, and delete buckets and objects. You can use S3 virtual hosting to address a bucket in a REST API call by using the HTTP Host header.

  • SOAP: Support for SOAP over HTTP is deprecated, but it is still available over HTTPS. However, new Amazon S3 features will not be supported for SOAP. AWS recommends using either the REST API or the AWS SDKs.

Bucket Configurations

Subresources

Description

location

Specify the AWS Region where you want S3 to create the bucket.

policy and ACL

(access control list)

All your resources are private by default. 

ACLs are now disabled by default for new buckets (Setting: Bucket Owner Enforced). Use Bucket Policies for access control instead.

cors

(cross-origin resource sharing)

You can configure your bucket to allow cross-origin requests. CORS defines a way for client web applications that are loaded in one domain to interact with resources in a different domain.

website

You can configure your bucket for static website hosting.

logging

Logging enables you to track requests for access to your bucket. Each access log record provides details about a single access request, such as the requester, bucket name, request time, request action, response status, and error code, if any.

event notification

You can enable your bucket to send you notifications of specified bucket events. Now supports sending events directly to Amazon EventBridge.

versioning

AWS recommends VERSIONING AS A BEST PRACTICE to recover objects from being deleted or overwritten by mistake.

lifecycle

You can define lifecycle rules for objects in your bucket that have a well-defined lifecycle.

replication

Automatic, asynchronous copying of objects. Now supports Cross-Region (CRR) and Same-Region (SRR).

tagging

S3 provides the tagging subresource to store and manage tags on a bucket. AWS generates a cost allocation report with usage and costs aggregated by your tags.

requestPayment

By default, the AWS account that creates the bucket (the bucket owner) pays for downloads from the bucket. The bucket owner can specify that the person requesting the download will be charged for the download.

transfer acceleration

Transfer Acceleration enables fast, easy, and secure transfers of files over long distances between your client and an S3 bucket. It takes advantage of Amazon CloudFront’s globally distributed edge locations.

object-lock

Configure WORM (Write Once, Read Many) protection.

inventory

Get daily or weekly reports listing your objects and their metadata.

Amazon S3 Objects

  • Are private by default. Grant permissions to other users.

  • Each S3 object has data, a key, and metadata.

  • You cannot modify object metadata after object is uploaded.

  • Two kinds of metadata

    • System metadata

Name

Description

Can User Modify the Value?

Date

Current date and time.

No

Content-Length

Object size in bytes.

No

Last-Modified

Object creation date or the last modified date, whichever is the latest.

No

Content-MD5

The base64-encoded 128-bit MD5 digest of the object.

No

x-amz-server-side-encryption

Indicates whether server-side encryption is enabled for the object, and whether that encryption is from the AWS Key Management Service (SSE-KMS) or from AWS managed encryption (SSE-S3).

Yes

x-amz-version-id

Object version. When you enable versioning on a bucket, Amazon S3 assigns a version number to objects added to the bucket.

No

x-amz-delete-marker

In a bucket that has versioning enabled, this Boolean marker indicates whether the object is a delete marker.

No

x-amz-storage-class

Storage class used for storing the object.

Yes

x-amz-website-redirect-location

Redirects requests for the associated object to another object in the same bucket or an external URL.

Yes

x-amz-server-side-encryption-aws-kms-key-id

If x-amz-server-side-encryption is present and has the value of aws:kms, this indicates the ID of the AWS Key Management Service (AWS KMS) master encryption key that was used for the object.

Yes

x-amz-server-side-encryption-customer-algorithm

Indicates whether server-side encryption with customer-provided encryption keys (SSE-C) is enabled.

Yes

    • User-defined metadata – key-value pair that you provide (e.g., x-amz-meta-project: secret).
  • Large Object Support: S3 now supports single objects up to 50 TB (increased from the previous 5 TB limit). For objects greater than 5 GB, you must use the multipart upload API.

  • S3 now supports additional checksums (SHA-1, SHA-256, CRC32, CRC32C) for data integrity verification during upload.

  • S3 Object Lambda supports the HeadObject, ListObjects, and ListObjectsV2 operations.

  • Conditional Writes

    • S3 supports conditional writes (using HTTP headers like If-None-Match or If-Match). This allows you to ensure an object is only uploaded if it doesn’t already exist, or if the current version matches a specific ETag, preventing accidental overwrites.
  • Tagging

    • You can associate up to 10 tags with an object. Tags associated with an object must have unique tag keys.

    • A tag key can be up to 128 Unicode characters in length and tag values can be up to 256 Unicode characters in length.

    • Key and values are case sensitive.

  • Object Delete

    • Deleting Objects from a Version-Enabled Bucket

      • Specify a non-versioned delete request – specify only the object’s key, and not the version ID.

      • Specify a versioned delete request – specify both the key and also a version ID.

    • Deleting Objects from an MFA-Enabled Bucket

      • If you provide an invalid MFA token, the request always fails.

      • If you are not deleting a versioned object, and you don’t provide an MFA token, the delete succeeds.

  • Object Lock

    • Prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely.

    • Objection retention options:

      • Retention period – object remains locked until the retention period expires.

      • Legal hold – object remains locked until you explicitly remove it.

    • Object Lock works only in versioned buckets and can now be enabled on existing buckets.

  • Object Ownership

    • Bucket Owner Enforced (Default): ACLs are disabled. The bucket owner owns all objects, regardless of who uploaded them.
  • S3 Select

    • S3 Select is an Amazon S3 capability designed to pull out only the data you need from an object, which can dramatically improve the performance and reduce the cost of applications that need to access data in S3.

    • Amazon S3 Select works on objects stored in CSV and JSON format, Apache Parquet format, JSON Arrays, and BZIP2 compression for CSV and JSON objects.

    • CloudWatch Metrics for S3 Select lets you monitor S3 Select usage for your applications. These metrics are available at 1-minute intervals and lets you quickly identify and act on operational issues.

  • Lifecycle Management

    • A lifecycle configuration is a set of rules that define actions that is applied to a group of objects.
AWS Training Amazon S3 2
      • Transition actions—Define when objects transition to another storage class. For S3-IA and S3-One-Zone, the objects must be stored at least 30 days in the current storage class before you can transition them to another class.

![](data:image/svg+xml,%3Csvg%20xmlns='http://www.w3.org/2000/svg'%20viewBox='0%200%20560%20556'%3E%3C/svg%3E align="center")

      • Expiration actions—Define when objects expire. S3 deletes expired objects on your behalf.

Default Data Integrity Protections

  • S3 verifies data integrity during uploads using cyclic redundancy check (CRC) based checksums stored in metadata. This ensures that transmitted data is unaltered and maintains consistency.

  • Checksums are available for integrity verification during future access or downloads.

  • It automatically detects and repairs any data corruption that may occur during upload, storage, or retrieval.

  • Customers can access reports detailing the verification process to monitor the health and status of their stored data.

  • This feature applies to all Amazon S3 storage classes, including S3 Standard, S3 Intelligent-Tiering, S3 One Zone-IA, and others.

  • The data integrity protection is included at no extra cost to customers.

Amazon S3 Metadata

  • It allows customers to access and manage additional metadata information associated with objects. This gives users a deeper understanding of their stored data, enabling more precise management.

  • Introduces automated, queryable metadata updated in near real-time to streamline data discovery and AI/ML application workflows.

  • Allows users to tag, search, and organize objects based on metadata attributes.

  • Provides APIs for metadata queries, enabling integration with analytics and monitoring tools.

  • Improves lifecycle management processes.

  • Automatically captures and stores metadata for objects in general-purpose S3 buckets in fully managed Apache Iceberg tables, enabling efficient data discovery and querying. These tables are called metadata tables.

  • Types of Metadata:

    • System-defined – Object’s creation time, storage class, etc.

    • Custom – Tags and user-defined metadata added during object upload.

    • Event – Metadata about updates, deletions, and AWS account actions.

  • Storage and Integration

    • Metadata tables are stored in S3 Table Buckets optimized for tabular data.

    • These tables can be queried using Amazon Athena, Amazon EMR, Amazon Redshift, Apache Spark, Apache Trino, and any other application that supports the Apache Iceberg format by using the AWS Glue Iceberg REST endpoint, the Amazon S3 Tables Iceberg REST endpoint, or the Amazon S3 Tables Catalog for Apache Iceberg client catalog.

    • Metadata tables can be integrated with AWS Glue Data Catalog for seamless querying and dashboard creation in Amazon QuickSight.

Amazon S3 Tables

  • S3 Tables are designed to store tabular data, including daily purchase transactions, streaming sensor data, and ad impressions.

  • S3 Tables are stored in a new bucket named table bucket that stores tables as subresources.

  • Table buckets support storing tables in the Apache Iceberg format, optimized for analytics workloads with increased transactions and query throughput.

  • Reduces the complexity of managing large data lakes by integrating directly with analytics frameworks.

  • Improves data querying efficiency for machine learning and analytics applications

Features of S3 Tables

  • Purpose-built storage for tables

    • S3 Table buckets are designed specifically for tables, offering higher transactions per second (TPS) and better query throughput compared to general-purpose S3 buckets, while maintaining durability, availability, and scalability.
  • Built-in support for Apache Iceberg

    • Tables are stored in Apache Iceberg format, which supports querying via standard SQL and optimizes query performance with features like schema evolution, partition evolution, and transaction support for data consistency and reliability.
  • Automated table optimization

    • S3 automatically performs maintenance operations like compaction, snapshot management, and unreferenced file removal, improving query performance and reducing storage costs. Customizable maintenance configurations are available for tables and buckets.
  • S3 Tables Intelligent-Tiering

    • S3 Tables now supports the Intelligent-Tiering storage class, which automatically optimizes costs by moving objects between three access tiers (Frequent, Infrequent, and Archive Instant Access) based on usage, with no impact on query performance.
  • Automatic Replication

    • Supports automatic, asynchronous replication of Apache Iceberg tables across AWS Regions and accounts. It replicates the complete table structure, snapshots, and metadata to ensure consistent read replicas for low-latency global access.
  • Access management and security

    • Access control for table buckets and individual tables is managed through AWS Identity and Access Management (IAM) and Service Control Policies. S3 Tables uses a distinct s3tables namespace, allowing for tailored policies. Public access settings are always enabled and cannot be disabled.

    • AWS has updated the AmazonS3TablesFullAccess managed policy to include permissions for these new features (replication configuration and storage class management).

  • Integration with AWS analytics services

    • Table buckets can be automatically integrated with AWS analytics services (e.g., Amazon Athena, Amazon Redshift, Amazon QuickSight) via the S3 console. Integration with the AWS Glue Data Catalog enables seamless analytics.
      Note: This integration is currently in preview and subject to change.

Storage Browser for Amazon S3

  • An open-source component for integrating a graphical interface into web applications, enabling end users to interact with Amazon S3 data. It allows authorized users to browse, upload, download, copy, and delete data directly from the application.

  • Includes LIST, GET, PUT, COPY, UPLOAD, and DELETE for file management in S3.

  • Ensures high throughput data transfer, faster load times, and maintains data integrity during uploads via checksum validation. Only authorized data is displayed to users.

  • Storage Browser can be tailored to match the design and branding of your existing application.

  • Designed for web and intranet applications built on the React framework.

  • Supports all S3 storage classes except for S3 Glacier Flexible Retrieval, S3 Glacier Deep Archive, and certain Intelligent-Tiering tiers.

Amazon S3 Pricing

  • S3 charges you only for what you actually use, with no hidden fees and no overage charges

  • No charge for creating a bucket, but only for storing objects in the bucket and for transferring objects in and out of the bucket.

Charge

Comments

Storage

You pay for storing objects in your S3 buckets. The rate you’re charged depends on your objects’ size, how long you stored the objects during the month, and the storage class.

Requests

You pay for requests, for example, GET requests, made against your S3 buckets and objects. This includes lifecycle requests. The rates for requests depend on what kind of request you’re making.

Retrievals

You pay for retrieving objects that are stored in STANDARD_IA, ONEZONE_IA, and GLACIER storage.

Early Deletes

If you delete an object stored in STANDARD_IA, ONEZONE_IA, or GLACIER storage before the minimum storage commitment has passed, you pay an early deletion fee for that object.

Storage Management

You pay for the storage management features that are enabled on your account’s buckets.

Bandwidth

You pay for all bandwidth into and out of S3, except for the following:

  • Data transferred in from the internet

  • Data transferred out to an Amazon EC2 instance, when the instance is in the same AWS Region as the S3 bucket

  • Data transferred out to Amazon CloudFront

You also pay a fee for any data transferred using Amazon S3 Transfer Acceleration.

Amazon S3 Networking

  • Hosted-style access

  • Path-style access

    • In a path-style URL, the endpoint you use must match the Region in which the bucket resides.

    • Deprecated: AWS is phasing out support for path-style access for new buckets. Virtual hosted-style is the recommended method.

    • Format:

  • Zonal Endpoints (Directory Buckets)

  • Customize S3 URLs with CNAMEs

    • The bucket name must be the same as the CNAME.
  • Amazon S3 Transfer Acceleration enables fast, easy, and secure transfers of files over long distances between your client and an S3 bucket. It takes advantage of Amazon CloudFront’s globally distributed edge locations.

  • Transfer Acceleration cannot be disabled completely once enabled; it can only be suspended.

  • Transfer Acceleration URL is: bucket.s3-accelerate.amazonaws.com

Amazon S3 Security

  • Policies contain the following:

    • Resources – buckets and objects

    • Actions – set of operations

    • Effect – can be either allow or deny. Need to explicitly grant allow to a resource.

    • Principal – the account, service or user who is allowed access to the actions and resources in the statement.

  • Resource Based Policies

    • Bucket Policies

      • Provides centralized access control to buckets and objects based on a variety of conditions, including S3 operations, requesters, resources, and aspects of the request (e.g., IP address).

      • Can either add or deny permissions across all (or a subset) of objects within a bucket.

      • IAM users need additional permissions from root account to perform bucket operations.

      • Bucket policies are limited to 20 KB in size.

    • Access Control Lists

      • A list of grants identifying grantee and permission granted.

      • ACLs use an S3–specific XML schema.

      • You can grant permissions only to other AWS accounts, not to users in your account.

      • You cannot grant conditional permissions, nor explicitly deny permissions.

      • Object ACLs are limited to 100 granted permissions per ACL.

      • ACLs are now disabled by default for new buckets (Setting: Bucket Owner Enforced). AWS recommends using Bucket Policies instead.

      • The only recommended use case for the bucket ACL is to grant write permissions to the S3 Log Delivery group.

AWS Training Amazon S3 3
  • Amazon S3 Access Grants

    • A simplified access management feature that maps identities in directories (like Active Directory, Azure AD, or Okta) directly to S3 datasets.

    • Removes the need to manage complex IAM roles for every user or application.

    • Automatically grants temporary credentials to authenticated users based on their corporate identity.

  • Attribute-Based Access Control (ABAC)

    • S3 supports ABAC, allowing you to control access based on tags attached to users/roles and tags attached to S3 resources (Buckets/Objects).

    • Example: A user with the Department=Finance tag can automatically access any S3 object with the Department=Finance tag.

    • Reduces the need to constantly update IAM policies when new resources or users are added.

  • User Policies

    • AWS IAM (see AWS Security and Identity Services)

      • IAM User Access Keys

      • Temporary Security Credentials

AWS Training Amazon S3 4
  • Versioning

    • Use versioning to keep multiple versions of an object in one bucket.

    • Versioning protects you from the consequences of unintended overwrites and deletions.

    • You can also use versioning to archive objects so you have access to previous versions.

    • Since versioning is disabled by default, need to EXPLICITLY enable.

    • When you PUT an object in a versioning-enabled bucket, the non-current version is not overwritten.

AWS Training Amazon S3 5
    • When you DELETE an object, all versions remain in the bucket and Amazon S3 inserts a delete marker.
AWS Training Amazon S3 6
  • Free AWS Courses

    • Performing a simple GET Object request when the current version is a delete marker returns a 404 Not Found error. You can, however, GET a non-current version of an object by specifying its version ID.
AWS Training Amazon S3 7
    • You can permanently delete an object by specifying the version you want to delete. Only the owner of an Amazon S3 bucket can permanently delete a version.

    • Amazon S3 on Outposts buckets has three versioning states: Unversioned, Enabled and Suspended.

      • When you enable S3 Versioning for an S3 on the Outposts bucket, it can never be set to unversioned, but you can set the state to suspend versioning.
  • Backup

    • You can use AWS Backup to define a central backup policy to protect your Amazon S3 data.

      • Continuous backups and Periodic backups

      • Automated backup scheduling and retention

      • Restore backups

Encryption

    • Server-side Encryption using

      • Amazon S3-Managed Keys (SSE-S3): Now the default encryption for all buckets.

      • AWS KMS-Managed Keys (SSE-KMS): Provides audit trails via CloudTrail.

      • Dual-layer Server-Side Encryption with AWS KMS keys (DSSE-KMS): Applies two layers of encryption for compliance standards.

      • Customer-Provided Keys (SSE-C): You manage the keys; AWS manages the crypto.

    • Client-side Encryption using

      • AWS KMS customer-managed key

      • client-side master key

  • MFA Delete

    • MFA delete grants additional authentication for either of the following operations:

      • Change the versioning state of your bucket

      • Permanently delete an object version

    • MFA Delete requires two forms of authentication together:

      • Your security credentials

      • The concatenation of a valid serial number, a space, and the six-digit code displayed on an approved authentication device

  • Cross-Account Access

    • You can provide another AWS account access to an object that is stored in an Amazon Simple Storage Service (Amazon S3) bucket. These are the methods on how to grant cross-account access to objects that are stored in your own Amazon S3 bucket:

      • Resource-based policies and AWS Identity and Access Management (IAM) policies for programmatic-only access to S3 bucket objects

      • Resource-based Access Control List (ACL) and IAM policies for programmatic-only access to S3 bucket objects

      • Cross-account IAM roles for programmatic and console access to S3 bucket objects

    • You can create cross-account Access Points using the S3 console or the AWS CLI.

    • Supports failover controls for S3 Multi-Region access points.

  • Requester Pays Buckets

    • Bucket owners pay for all of the Amazon S3 storage and data transfer costs associated with their bucket. To save on costs, you can enable the Requester Pays feature so the requester will pay the cost of the request and the data download from the bucket instead of the bucket owner. Take note that the bucket owner always pays the cost of storing data.

Amazon S3 Monitoring

    • Automated monitoring tools to watch S3:

      • Amazon CloudWatch Alarms – Watch a single metric over a time period that you specify, and perform one or more actions based on the value of the metric relative to a given threshold over a number of time periods.

      • AWS CloudTrail Log Monitoring – Share log files between accounts, monitor CloudTrail log files in real time by sending them to CloudWatch Logs, write log processing applications in Java, and validate that your log files have not changed after delivery by CloudTrail.

    • Monitoring with CloudWatch

      • Daily Storage Metrics for Buckets ‐ You can monitor bucket storage using CloudWatch, which collects and processes storage data from S3 into readable, daily metrics.

      • Request metrics ‐ You can choose to monitor S3 requests to quickly identify and act on operational issues. The metrics are available at 1 minute intervals after some latency to process.

    • You can have a maximum of 1000 metrics configurations per bucket.

    • Supported event activities that occur in S3 are recorded in a CloudTrail event along with other AWS service events in Event history.

  • Website Hosting

    • Enable website hosting in your bucket Properties.

    • Your static website is available via the region-specific website endpoint.

    • You must make the objects that you want to serve publicly readable by writing a bucket policy that grants everyone s3:GetObject permission.

Key Difference

REST API Endpoint

Website Endpoint

Access control

Supports both public and private content.

Supports only publicly readable content.

Error message handling

Returns an XML-formatted error response.

Returns an HTML document.

Redirection support

Not applicable

Supports both object-level and bucket-level redirects.

Requests supported

Supports all bucket and object operations

Supports only GET and HEAD requests on objects.

Responses to GET and HEAD requests at the root of a bucket

Returns a list of the object keys in the bucket.

Returns the index document that is specified in the website configuration.

Secure Sockets Layer (SSL) support

Supports SSL connections.

Does not support SSL connections.

S3 Events Notification

  • Replication (Cross-Region & Same-Region)

    • Supports both Cross-Region Replication (CRR) and Same-Region Replication (SRR).

    • Enables automatic, asynchronous copying of objects across buckets in different AWS Regions.

    • When to use:

      • Comply with compliance requirements

      • Minimize latency

      • Increase operational efficiency

      • Maintain object copies under different ownership

      • Aggregate logs into a single bucket (SRR)

    • Requirements:

      • Both source and destination buckets must have versioning enabled.

      • S3 must have permissions to replicate objects from the source bucket to the destination bucket on your behalf.

    • Only the following are replicated:

      • Objects created after you add a replication configuration.

      • Both unencrypted objects and objects encrypted using Amazon S3 managed keys (SSE-S3) or AWS KMS managed keys (SSE-KMS), although you must explicitly enable the option to replicate objects encrypted using KMS keys. The replicated copy of the object is encrypted using the same type of server-side encryption that was used for the source object.

      • Object metadata.