S3 Flashcards
S3 Server Side Encryption Types
SSE-S3
S3 manages encryption keys.
Free
SSE-C
Customer manages encryption keys.
SSE-KMS
AWS Key Management Service (KMS) manages the encryption keys.
Audit trail of when your key is used, and by whom.
AWS Object Size Limit
0 bytes to 5 terabytes
AWS S3 Scope
Region-wise
S3 Storage Classes - 6 Types
Standard
Standard Infrequent Access (Standard IA)
Intelligent Tiering
One Zone Infrequent Access (One Zone IA)
S3 Glacier
S3 Glacier Deep Archive
S3 Storage Class - Standard
Durability
Availability
Failures sustainability
Durability : 11 - Nines
Availability : 99.99%
Failures sustainability : Two aviability zones (AZ)
S3 Storage Class - Standard Infrequent Access (Standard IA)
Durability
Availability
Failures sustainability
Saving :
Durability : 11 - Nines
Availability : 99.9%
Failures sustainability : One aviability zone (AZ)
Saving : ? on storage costs
S3 Storage Class - One Zone-Infrequent Access (S3 One Zone-IA)
Durability
Availability
Failures sustainability
Saving :
Durability : 11 - Nines
Availability : 99.5%
Failures sustainability : 1 AZ
Saving : 20% less than S3 Standard-Infrequent Access
S3 Storage Class - S3 Intelligent-Tiering
Durability
Availability
Failures sustainability
Saving :
Durability : 11 - Nines
Availability : 99.9%
Failures sustainability :
Saving : 40% on storage costs
S3 Archive Standard - Glacier
3 Types
Amazon S3 Glacier Instant Retrieval
Amazon S3 Glacier Flexible Retrieval (Formerly S3 Glacier)
Amazon S3 Glacier Deep Archive
S3 Archive Standard :
Amazon S3 Glacier Instant Retrieval
Durability
Availability
Retrieval Time
Cost
Durability : 11 Nines
Availability : 99.9%
Retrieval Time : milliseconds
Cost : 68% on storage costs compared to using the S3 Standard-Infrequent Access (S3 Standard-IA)
S3 Archive Standard :
Amazon S3 Glacier Flexible Retrieval
Durability
Availability
Failure :
Retrieval Time
Cost
Durability : 11 Nines
Availability : 99.99%
Failure : one entire Availability Zone destruction
Retrieval Time : Configurable retrieval times, from minutes to hours
Cost : 10% lower cost (than S3 Glacier Instant Retrieval)
Amazon S3 Glacier Deep Archive
Durability
Availability
Failure :
Retrieval Time
Cost
Durability :
Availability : 99.99%
Failure : Stored in 3 areas
Retrieval Time : 12 hrs or 48 hrs
Cost : lowest-cost storage class
Object Lock & Glacier Lock
Both adopts WORM
(Write Once - Read Many Times)
Objects : Blocks object version deletion for a predetermined time
Glacier : Locks the policy for future edits
AWS S3 Replication - Two Types
SRR - CRR
Same Region: Same Region Replication (SRR)
Different Region: Cross-Region Replication (CRR)
AWS S3 Replication - points
Versioning
Accounts
Copying mode
IAM requirements
Must enabling versioning in source and destination
Buckets can be different accounts
Copying is asynchronous
Must give proper IAM permissions to S3
Retention Period and Legal Hold
Retention Period
- Governance mode
- Compliance mode
Legal Hold
Lock has no expiration until the hold is removed
Lock feature must be enabled during the bucket creation only
Governance mode
Users can’t overwrite or delete an object version or alter its lock settings unless they have special permissions
With governance mode, you protect objects against being deleted by most users, but you can still grant some users permission to alter the retention settings or delete the object if necessary.
Compliance mode
Protected object version can’t be overwritten or deleted by any user, including the root user in your AWS account.