S3

Object storage over HTTP(S). Objects (≤ 5 TB) live in buckets (globally unique names, region-scoped). Flat namespace — “folders” are key prefixes.

Durability & Availability

  • 11 9s durability across all classes. Standard availability 99.99%; IA 99.9%; One Zone-IA 99.5%.
  • Strong read-after-write consistency for PUT/GET/LIST.

Storage Classes

Reference

ClassAvailabilityMin durationUse case
Standard99.99%—Frequently accessed, low latency
Standard-IA99.9%30 daysInfrequent, rapid when needed (backups, DR)
One Zone-IA99.5%30 daysRe-creatable / secondary backups (single AZ)
Intelligent-Tiering99.9%—Unknown/changing access — auto-tiers, no retrieval fees
Glacier Instant Retrieval99.9%90 daysArchive, ms retrieval, ~quarterly access
Glacier Flexible Retrieval99.99%90 daysArchive, minutes-to-hours retrieval
Glacier Deep Archive99.99%180 daysLowest cost, 12–48 h retrieval, compliance archive
  • Glacier retrieval: Instant — ms · Flexible — Expedited 1–5 min, Standard 3–5 h, Bulk 5–12 h (free) · Deep Archive — Standard 12 h, Bulk 48 h.
  • Intelligent-Tiering: Frequent → Infrequent (30 d) → Archive Instant (90 d); optional Archive/Deep Archive tiers. Small monitoring fee, no retrieval charge.
  • Lifecycle rules transition and expire objects (and old versions, incomplete multipart uploads) on a schedule, scoped by prefix or tag. Don’t move data by hand.

Versioning & Replication

  • Versioning is bucket-level; once on it can be suspended, never removed. DELETE writes a delete marker; prior version stays recoverable. Add MFA Delete for permanent deletes.
  • Replication (CRR / SRR) is async and needs versioning on both sides. Only new objects replicate — S3 Batch Replication for existing ones.

Encryption & Security

  • SSE-S3 (default, AES-256) · SSE-KMS (audit trail + access control; watch KMS quotas) · DSSE-KMS · SSE-C.
  • Block Public Access on by default at account and bucket level — the guardrail that matters.
  • Access via bucket policies (resource) and IAM policies (identity); ACLs are legacy. Access Points for shared datasets, presigned URLs for time-limited object access, Object Lock for WORM.

Other Features

  • Event notifications → SQS, SNS, Lambda, EventBridge.
  • Transfer Acceleration via CloudFront edges; multipart upload above ~100 MB (single PUT max 5 GB).
  • S3 Select — SQL over one CSV/JSON/Parquet object. Requester Pays.

Snippets

# Sync a local dir to a bucket (delete removed files)
aws s3 sync ./dist s3://my-bucket/ --delete
 
# Presign a download URL valid for 1 hour
aws s3 presign s3://my-bucket/report.pdf --expires-in 3600
 
# Enable default encryption (SSE-KMS)
aws s3api put-bucket-encryption --bucket my-bucket \
  --server-side-encryption-configuration '{
    "Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"aws:kms"}}]}'
 
# Bucket names only
aws s3api list-buckets --query 'Buckets[].Name' --output text

Enforce TLS with a bucket policy:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "DenyInsecureTransport",
    "Effect": "Deny",
    "Principal": "*",
    "Action": "s3:*",
    "Resource": ["arn:aws:s3:::my-bucket", "arn:aws:s3:::my-bucket/*"],
    "Condition": { "Bool": { "aws:SecureTransport": "false" } }
  }]
}