AWS - Storage - Rebuild-InProgress
S3
- S3 is object based storage on AWS cloud. Objects are files like videos, pictures etc.
- 0byte to 5TB size files can be uploaded.
- There is no limit on upload.
- Files are stored in buckets.
- S3 is universal namespace (two same name bucket can't exist globally), so each bucket name must be unique.
- S3 url syntax https://S3-<region name>.amazonaws.com/<bucketname>.
- Putting new object on S3 gives read after write consistency (no delay in read).
- For any update or deletion of object propagation of change will take time.
- S3 fundamentals are Key(name), Value(data), VersionID, Metadata, ACLs
- Write/Upload to S3 is notified by HTTP-200 message.
- Faster upload of larger files can be done using multipart upload tool.
S3 storage classes/Tier
- S3 (durable, immediately available, frequently accessed).
- S3-IA (durable, immediately available, infrequently accessed).
- S3-Reduced redundancy object (data that can be quickly reproducible from backup, like thumbnail etc).
- Glacier-Archive data, where once request raised to access data it takes 3-5hours for response.
S3 Versioning
- By default, it is disabled.
- Once enabled, we can suspend it.
- First upload will not have any versionID associated, once versioning enabled versionID gets associated with every update of object. On suspension of versioning first uploaded object gets updated on every update.
- Versioning allows MFA authentication deletes.
- Cross region replication requires versioning to be in enabled state on source and destination bucket.
S3 object lifecycle management
- Can be used in conjunction with versioning or independent.
- Can be applied to current or previous versions.
- Following options to choose from
- Transition to S3-IA : 128KB minimum size and 30 days after creation date of object it can be moved to S3-IA.
- Archive to glacier storage : 60 days after creation of object or 30days after moving to S3-IA.
- Permanent deletion.
Security
- By default, all newly created buckets are private.
- Access control to your buckets using
- Bucket policies.
- Access control lists.
- Setting up bucket access logs.
Encryption
- Data (object) in transit
- SSL/TLS (HTTPS)
- Data at rest
- Server side encryption
- SSE-S3 (AES-256)
- SSE-KMS (Key management service, envelope key, audit trail)
- SSE-C (Customer provided encryption key)
- Client side encryption
- Encrypt your own data and upload.
Comments
Post a Comment