AWS Glossary
Amazon S3
Amazon Simple Storage Service — scalable object storage for any amount of data, used for backups, data lakes, static websites, and application assets.
AI & assistant-friendly summary
This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.
Summary
Amazon Simple Storage Service — scalable object storage for any amount of data, used for backups, data lakes, static websites, and application assets.
Key Facts
- •Amazon Simple Storage Service — scalable object storage for any amount of data, used for backups, data lakes, static websites, and application assets
- •S3 underpins backups, static sites, data lakes, ML datasets, and application assets
- •Access is HTTPS-native (`s3://` or REST APIs); authorization combines IAM, bucket policies, ACLs (legacy), and optional VPC endpoints for private traffic
- •S3 Intelligent-Tiering** automates tier movement for unpredictable access
- •Lifecycle policies, versioning, replication (CRR/SRR), Object Lock (WORM), and Event Notifications integrate S3 into event-driven and compliance architectures
Entity Definitions
- Lambda
- Lambda is an AWS service relevant to amazon s3.
- EC2
- EC2 is an AWS service relevant to amazon s3.
- S3
- S3 is an AWS service relevant to amazon s3.
- DynamoDB
- DynamoDB is an AWS service relevant to amazon s3.
- CloudFront
- CloudFront is an AWS service relevant to amazon s3.
- IAM
- IAM is an AWS service relevant to amazon s3.
- VPC
- VPC is an AWS service relevant to amazon s3.
- SQS
- SQS is an AWS service relevant to amazon s3.
- SNS
- SNS is an AWS service relevant to amazon s3.
- ElastiCache
- ElastiCache is an AWS service relevant to amazon s3.
- cost optimization
- cost optimization is a cloud computing concept relevant to amazon s3.
- compliance
- compliance is a cloud computing concept relevant to amazon s3.
Related Content
- AWS CLOUD COST OPTIMIZATION SERVICES— Related service
- FINOPS CONSULTING— Related service
- AWS DATA ANALYTICS— Related service
Definition
Amazon Simple Storage Service (S3) is AWS’s object store: buckets hold objects (up to 5 TB each) addressed by keys, with 11-nines durability for Standard storage across multiple Availability Zones. S3 underpins backups, static sites, data lakes, ML datasets, and application assets. Access is HTTPS-native (s3:// or REST APIs); authorization combines IAM, bucket policies, ACLs (legacy), and optional VPC endpoints for private traffic.
Beyond Standard, storage classes trade cost for retrieval latency and AZ scope. S3 Intelligent-Tiering automates tier movement for unpredictable access. Specialized bucket types in 2026 extend S3 into analytics and AI: S3 Tables (managed Apache Iceberg), S3 Vectors (embedding storage), and S3 Express One Zone (single-AZ, millisecond latency). Lifecycle policies, versioning, replication (CRR/SRR), Object Lock (WORM), and Event Notifications integrate S3 into event-driven and compliance architectures.
| Storage class | Access pattern | Retrieval |
|---|---|---|
| S3 Standard | Frequent | Milliseconds |
| Intelligent-Tiering | Unknown/changing | Milliseconds |
| Standard-IA / One Zone-IA | Infrequent | Milliseconds |
| Glacier Instant / Flexible / Deep Archive | Archive | Minutes to hours |
When to use it
- Durable object storage for any size — media, logs, backups, artifacts, and data lake landing zones.
- Static website hosting, CDN origins (CloudFront), and user-generated content with pre-signed upload URLs.
- Event-driven pipelines via S3 Event Notifications → Lambda, SQS, or SNS on
PutObject. - Compliance retention with versioning + Object Lock for WORM and legal hold requirements.
When not to use it
- POSIX file semantics or shared mutable files — use EFS, FSx, or block storage on EC2.
- Low-latency random read/write on small keys at OLTP rates — DynamoDB or ElastiCache fit better.
- Single-digit-ms latency for millions of small objects without Express One Zone — Standard S3 optimizes for throughput and durability, not microsecond tail latency.
Tips
- Enable S3 Block Public Access at the account level; grant access with IAM roles and bucket policies, not
"Principal": "*". - Turn on versioning for buckets that hold irreplaceable data — deletes become delete markers, not permanent loss.
- Default new buckets to SSE-KMS with a customer managed key when you need CloudTrail audit of decrypt events per object class.
- Implement lifecycle rules early: as of July 16, 2026, objects may transition from Standard to Standard-IA / One Zone-IA on day 0 (no 30-day Standard residency requirement) — but IA classes still bill a 30-day minimum storage duration per object if deleted or re-transitioned early.
- Expire incomplete multipart uploads after 7 days; transition cold prefixes to Glacier tiers when retrieval tolerance allows.
- Use S3 Inventory + Storage Lens quarterly to find Standard objects that have not been read in 90+ days — prime candidates for Intelligent-Tiering or IA.
Gotchas
- Serious: A misconfigured bucket policy exposing
ListBucket+GetObjectto the internet is still a top AWS breach pattern — Block Public Access does not fix intentional overly broad policies. - Serious: Cross-Region Replication does not replicate delete markers unless configured — DR drills that assume bidirectional mirror semantics fail silently.
- Regular: Request costs dominate for small-object-heavy workloads — billions of LIST operations on prefix-heavy buckets burn budget faster than storage GB-months.
- Regular: Strong read-after-write consistency applies globally now, but list operations still lag behind highly concurrent write/delete patterns in some analytics jobs — design idempotent consumers.
- Regular: Day-0 IA transition eligibility ≠ zero minimum-duration charges — Standard-IA and One Zone-IA still enforce 30-day billing minimums; model churn before moving volatile prefixes.
- Regular: Replacing an object without versioning increments storage silently if old versions accumulate — lifecycle rules must include noncurrent version expiration.
Official references
- S3 security best practices — encryption, access points, and logging.
- S3 Lifecycle configuration — transitions and expirations.
Related FactualMinds content
Related Services
AWS Cost Optimization & FinOps Consulting
AWS cost optimization and FinOps consulting from FactualMinds — reduce spend by 20-40% with expert right-sizing and strategy.
FinOps Consulting — AWS Cloud Cost Governance
FinOps consulting — cloud cost governance, savings plans strategy, reserved instances, and continuous optimization.
AWS Data Analytics Services — Glue, Athena & QuickSight
AWS data analytics services — scalable data warehouse, ETL/ELT pipelines, real-time analytics, and business intelligence.
Need help with this topic?
Our AWS-certified team implements, audits, and optimizes these services in production — from Bedrock RAG pipelines to multi-account landing zones.
