S3
Object storage over HTTP(S). Objects (≤ 5 TB) live in buckets (globally unique names, region-scoped). Flat namespace — “folders” are key prefixes.
Durability & Availability
- 11 9s durability across all classes. Standard availability 99.99%; IA 99.9%; One Zone-IA 99.5%.
- Strong read-after-write consistency for PUT/GET/LIST.
Storage Classes
| Class | Availability | Min duration | Use case |
|---|---|---|---|
| Standard | 99.99% | — | Frequently accessed, low latency |
| Standard-IA | 99.9% | 30 days | Infrequent, rapid when needed (backups, DR) |
| One Zone-IA | 99.5% | 30 days | Re-creatable / secondary backups (single AZ) |
| Intelligent-Tiering | 99.9% | — | Unknown/changing access — auto-tiers, no retrieval fees |
| Glacier Instant Retrieval | 99.9% | 90 days | Archive, ms retrieval, ~quarterly access |
| Glacier Flexible Retrieval | 99.99% | 90 days | Archive, minutes-to-hours retrieval |
| Glacier Deep Archive | 99.99% | 180 days | Lowest cost, 12–48 h retrieval, compliance archive |
- Glacier retrieval: Instant — ms · Flexible — Expedited 1–5 min, Standard 3–5 h, Bulk 5–12 h (free) · Deep Archive — Standard 12 h, Bulk 48 h.
- Intelligent-Tiering: Frequent → Infrequent (30 d) → Archive Instant (90 d); optional Archive/Deep Archive tiers. Small monitoring fee, no retrieval charge.
- Lifecycle rules transition and expire objects (and old versions, incomplete multipart uploads) on a schedule, scoped by prefix or tag. Don’t move data by hand.
Versioning & Replication
- Versioning is bucket-level; once on it can be suspended, never removed.
DELETEwrites a delete marker; prior version stays recoverable. Add MFA Delete for permanent deletes. - Replication (CRR / SRR) is async and needs versioning on both sides. Only new objects replicate — S3 Batch Replication for existing ones.
Encryption & Security
- SSE-S3 (default, AES-256) · SSE-KMS (audit trail + access control; watch KMS quotas) · DSSE-KMS · SSE-C.
- Block Public Access on by default at account and bucket level — the guardrail that matters.
- Access via bucket policies (resource) and IAM policies (identity); ACLs are legacy. Access Points for shared datasets, presigned URLs for time-limited object access, Object Lock for WORM.
Other Features
- Event notifications → SQS, SNS, Lambda, EventBridge.
- Transfer Acceleration via CloudFront edges; multipart upload above ~100 MB (single PUT max 5 GB).
- S3 Select — SQL over one CSV/JSON/Parquet object. Requester Pays.
Snippets
# Sync a local dir to a bucket (delete removed files)
aws s3 sync ./dist s3://my-bucket/ --delete
# Presign a download URL valid for 1 hour
aws s3 presign s3://my-bucket/report.pdf --expires-in 3600
# Enable default encryption (SSE-KMS)
aws s3api put-bucket-encryption --bucket my-bucket \
--server-side-encryption-configuration '{
"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"aws:kms"}}]}'
# Bucket names only
aws s3api list-buckets --query 'Buckets[].Name' --output textEnforce TLS with a bucket policy:
{
"Version": "2012-10-17",
"Statement": [{
"Sid": "DenyInsecureTransport",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": ["arn:aws:s3:::my-bucket", "arn:aws:s3:::my-bucket/*"],
"Condition": { "Bool": { "aws:SecureTransport": "false" } }
}]
}