Appearance
Amazon S3 — Advanced (Bản gốc slide / Original slide)
1. S3 — Chuyển đổi Storage Class & Lifecycle Rules
- Có thể chuyển object giữa các storage class
- Object ít truy cập → chuyển sang Standard-IA
- Object archive, không cần truy cập nhanh → chuyển sang Glacier hoặc Glacier Deep Archive
- Việc chuyển đổi có thể tự động hoá bằng Lifecycle Rules
Lifecycle Rules gồm 2 loại action:
- Transition Actions — cấu hình object chuyển sang storage class khác
- Ví dụ: chuyển sang Standard-IA sau 60 ngày kể từ khi tạo
- Chuyển sang Glacier để archive sau 6 tháng
- Expiration Actions — cấu hình object hết hạn (xoá) sau một khoảng thời gian
- Ví dụ: access log file tự xoá sau 365 ngày
- Có thể dùng để xoá version cũ (nếu bật versioning)
- Có thể dùng để xoá multi-part upload chưa hoàn tất
Rule có thể tạo theo prefix (ví dụ s3://mybucket/mp3/*) hoặc theo object tag (ví dụ Department: Finance).
- Objects can transition between storage classes
- Infrequently accessed objects → move to Standard IA
- Archive objects you don't need fast access to → move to Glacier or Glacier Deep Archive
- Moving objects can be automated using Lifecycle Rules
Lifecycle Rules have 2 kinds of actions:
- Transition Actions — configure objects to transition to another storage class
- E.g., move to Standard IA class 60 days after creation
- Move to Glacier for archiving after 6 months
- Expiration actions — configure objects to expire (delete) after some time
- E.g., access log files can be set to delete after 365 days
- Can be used to delete old versions of files (if versioning is enabled)
- Can be used to delete incomplete Multi-Part uploads
Rules can be created for a certain prefix (e.g., s3://mybucket/mp3/*) or for certain object Tags (e.g., Department: Finance).
2. Lifecycle Rules — Ví dụ thực hành (Scenarios)
Scenario 1:
Ứng dụng của bạn trên EC2 tạo ảnh thumbnail sau khi ảnh đại diện được upload lên S3. Thumbnail có thể tạo lại dễ dàng và chỉ cần giữ 60 ngày. Ảnh gốc cần lấy được ngay trong 60 ngày đó, sau đó user có thể chờ tới 6 giờ. Thiết kế thế nào?
- Ảnh gốc để ở Standard, kèm lifecycle chuyển sang Glacier sau 60 ngày
- Thumbnail để ở One-Zone IA, kèm lifecycle expire (xoá) sau 60 ngày
Scenario 2:
Quy định công ty yêu cầu khôi phục object đã xoá ngay lập tức trong 30 ngày (dù hiếm khi xảy ra). Sau đó, và trong tối đa 365 ngày, object xoá cần khôi phục được trong vòng 48 giờ.
- Bật S3 Versioning để object "đã xoá" thực chất chỉ bị ẩn bởi delete marker và có thể khôi phục
- Chuyển các "noncurrent version" sang Standard IA
- Sau đó chuyển tiếp "noncurrent version" sang Glacier Deep Archive
Scenario 1:
Your application on EC2 creates image thumbnails after profile photos are uploaded to S3. Thumbnails can be easily recreated, and only need to be kept for 60 days. Source images should be retrievable immediately for these 60 days, and afterwards the user can wait up to 6 hours. How would you design this?
- Source images on Standard, with a lifecycle transitioning them to Glacier after 60 days
- Thumbnails on One-Zone IA, with a lifecycle to expire (delete) them after 60 days
Scenario 2:
A company rule states deleted S3 objects should be recoverable immediately for 30 days (although this may happen rarely). After this time, and for up to 365 days, deleted objects should be recoverable within 48 hours.
- Enable S3 Versioning so "deleted objects" are actually hidden by a delete marker and can be recovered
- Transition the "noncurrent versions" to Standard IA
- Afterwards transition the "noncurrent versions" to Glacier Deep Archive
3. S3 Analytics — Storage Class Analysis
- Giúp quyết định khi nào nên chuyển object sang storage class phù hợp
- Có gợi ý (recommendation) cho Standard và Standard IA
- ⚠️ KHÔNG hoạt động cho One-Zone IA hoặc Glacier
- Report được cập nhật hằng ngày
- Cần 24–48 giờ để bắt đầu thấy dữ liệu phân tích
- Là bước đầu tốt để xây dựng (hoặc cải thiện) Lifecycle Rules!
- Helps you decide when to transition objects to the right storage class
- Recommendations for Standard and Standard IA
- Does NOT work for One-Zone IA or Glacier
- Report is updated daily
- 24 to 48 hours to start seeing data analysis
- A good first step to put together (or improve) Lifecycle Rules!
4. S3 — Requester Pays
- Thông thường, chủ bucket (owner) trả toàn bộ chi phí storage & data transfer
- Với Requester Pays bucket, người request (thay vì owner) trả chi phí request và download data
- Hữu ích khi muốn chia sẻ dataset lớn với account khác mà không tốn phí network
- Requester phải được xác thực trong AWS (không thể là anonymous)
- In general, bucket owners pay for all S3 storage and data transfer costs
- With Requester Pays buckets, the requester (instead of the owner) pays the cost of the request and data download
- Helpful when you want to share large datasets with other accounts
- The requester must be authenticated in AWS (cannot be anonymous)
5. S3 Event Notifications
- Sự kiện:
S3:ObjectCreated,S3:ObjectRemoved,S3:ObjectRestore,S3:Replication… - Có thể lọc theo tên object (ví dụ
*.jpg) - Use case: tạo thumbnail khi ảnh được upload lên S3
- Có thể tạo bao nhiêu "S3 event" tuỳ ý
- Đích đến: SNS, SQS, Lambda Function
- Thường gửi event trong vài giây, nhưng đôi khi có thể mất một phút hoặc hơn
IAM Permissions cho S3 Event Notifications:
- Mỗi đích đến (SNS/SQS/Lambda) cần có Resource (Access) Policy cho phép S3 gửi event tới nó
S3 Event Notifications với Amazon EventBridge:
- Mọi event từ S3 bucket đều đi qua Amazon EventBridge
- Cho phép advanced filtering bằng JSON rule (metadata, kích thước object, tên…)
- Nhiều đích đến hơn: Step Functions, Kinesis Streams/Firehose… (hơn 18 dịch vụ AWS làm destination)
- Có các khả năng của EventBridge: Archive, Replay Events, Reliable delivery
- Events:
S3:ObjectCreated,S3:ObjectRemoved,S3:ObjectRestore,S3:Replication… - Object name filtering possible (e.g.,
*.jpg) - Use case: generate thumbnails of images uploaded to S3
- Can create as many "S3 events" as desired
- Destinations: SNS, SQS, Lambda Function
- S3 event notifications typically deliver events in seconds, but can sometimes take a minute or longer
IAM Permissions for S3 Event Notifications:
- Each destination (SNS/SQS/Lambda) needs a Resource (Access) Policy allowing S3 to send events to it
S3 Event Notifications with Amazon EventBridge:
- All events from an S3 bucket go through Amazon EventBridge
- Enables advanced filtering with JSON rules (metadata, object size, name...)
- More destinations: Step Functions, Kinesis Streams/Firehose… (18+ AWS services as destinations)
- EventBridge capabilities: Archive, Replay Events, Reliable delivery
6. S3 — Baseline Performance
- S3 tự động scale theo request rate cao, latency 100–200 ms
- Ứng dụng có thể đạt ít nhất 3,500 PUT/COPY/POST/DELETE hoặc 5,500 GET/HEAD request/giây cho mỗi prefix trong bucket
- Không giới hạn số lượng prefix trong một bucket
- Ví dụ (object path → prefix):
bucket/folder1/sub1/file→ prefix/folder1/sub1/bucket/folder1/sub2/file→ prefix/folder1/sub2/bucket/1/file→ prefix/1/bucket/2/file→ prefix/2/
- Nếu chia đều read trên 4 prefix, có thể đạt 22,000 request/giây cho GET và HEAD
- S3 automatically scales to high request rates, latency 100–200 ms
- Your application can achieve at least 3,500 PUT/COPY/POST/DELETE or 5,500 GET/HEAD requests per second per prefix in a bucket
- No limits on the number of prefixes in a bucket
- Example (object path → prefix):
bucket/folder1/sub1/file→/folder1/sub1/bucket/folder1/sub2/file→/folder1/sub2/bucket/1/file→/1/bucket/2/file→/2/
- If you spread reads evenly across 4 prefixes, you can achieve 22,000 requests per second for GET and HEAD
7. S3 Performance — Upload & Download
Multi-Part upload:
- Khuyến nghị cho file > 100MB, bắt buộc cho file > 5GB
- Giúp song song hoá (parallelize) việc upload → tăng tốc transfer
S3 Transfer Acceleration:
- Tăng tốc độ transfer bằng cách gửi file tới AWS Edge Location gần nhất, sau đó edge forward data về S3 bucket ở region đích qua mạng backbone riêng của AWS (nhanh hơn public Internet)
- Tương thích với multi-part upload
S3 Byte-Range Fetches:
- Song song hoá GET bằng cách request các khoảng byte (byte range) cụ thể
- Tăng khả năng chịu lỗi (resilience) khi có sự cố
- Có thể dùng để tăng tốc download (chia file thành nhiều phần tải song song)
- Hoặc dùng để lấy một phần dữ liệu (ví dụ chỉ lấy phần header đầu file)
Multi-Part upload:
- Recommended for files > 100MB, must use for files > 5GB
- Can help parallelize uploads (speed up transfers)
S3 Transfer Acceleration:
- Increases transfer speed by sending the file to the nearest AWS Edge Location, which then forwards the data to the S3 bucket in the target region over AWS's private backbone (faster than the public Internet)
- Compatible with multi-part upload
S3 Byte-Range Fetches:
- Parallelize GETs by requesting specific byte ranges
- Better resilience in case of failures
- Can be used to speed up downloads (splitting the file into parallel parts)
- Or to retrieve only partial data (e.g., just the header of a file)
8. S3 Batch Operations
- Thực hiện bulk operation trên các object đã có sẵn trong S3 chỉ với một request, ví dụ:
- Sửa metadata & thuộc tính object
- Copy object giữa các bucket
- Mã hoá object chưa mã hoá
- Sửa ACL, tag
- Restore object từ S3 Glacier
- Gọi Lambda function để thực hiện hành động tuỳ chỉnh trên từng object
- Một job gồm: danh sách object, action cần thực hiện, và tham số tuỳ chọn
- S3 Batch Operations tự quản lý retry, theo dõi tiến trình, gửi thông báo hoàn tất, tạo report…
- Có thể dùng S3 Inventory để lấy danh sách object, rồi dùng Athena để query/lọc object trước khi chạy Batch Operation
- Perform bulk operations on existing S3 objects with a single request, e.g.:
- Modify object metadata & properties
- Copy objects between S3 buckets
- Encrypt un-encrypted objects
- Modify ACLs, tags
- Restore objects from S3 Glacier
- Invoke a Lambda function to perform a custom action on each object
- A job consists of a list of objects, the action to perform, and optional parameters
- S3 Batch Operations manages retries, tracks progress, sends completion notifications, generates reports…
- You can use S3 Inventory to get the object list, and use Athena to query and filter objects before running the Batch Operation
9. S3 — Storage Lens
- Hiểu, phân tích và tối ưu storage trên toàn bộ AWS Organization
- Phát hiện anomaly, xác định cơ hội tiết kiệm chi phí, áp dụng best practice bảo vệ dữ liệu trên toàn Organization (metric hoạt động & sử dụng trong 30 ngày)
- Tổng hợp dữ liệu theo Organization, account cụ thể, region, bucket, hoặc prefix
- Dùng dashboard mặc định hoặc tự tạo dashboard riêng
- Có thể cấu hình export metric hằng ngày ra một S3 bucket (định dạng CSV, Parquet)
Default Dashboard:
- Trực quan hoá insight & xu hướng tổng hợp cho cả metric miễn phí lẫn nâng cao
- Hiển thị dữ liệu Multi-Region và Multi-Account
- Được cấu hình sẵn bởi Amazon S3
- Không thể xoá, nhưng có thể tắt (disable)
Các nhóm Metrics:
- Summary Metrics — insight tổng quan (StorageBytes, ObjectCount…) — tìm bucket/prefix tăng nhanh nhất hoặc không dùng tới
- Cost-Optimization Metrics — tối ưu chi phí (NonCurrentVersionStorageBytes, IncompleteMultipartUploadStorageBytes…) — tìm multipart upload dở dang > 7 ngày, object nên chuyển sang class rẻ hơn
- Data-Protection Metrics — bảo vệ dữ liệu (VersioningEnabledBucketCount, MFADeleteEnabledBucketCount, SSEKMSEnabledBucketCount, CrossRegionReplicationRuleCount…)
- Access-management Metrics — insight về S3 Object Ownership
- Event Metrics — insight về S3 Event Notifications
- Performance Metrics — insight về S3 Transfer Acceleration
- Activity Metrics — cách storage được request (AllRequests, GetRequests, PutRequests, ListRequests, BytesDownloaded…)
- Detailed Status Code Metrics — insight theo HTTP status code (200OKStatusCount, 403ForbiddenErrorCount, 404NotFoundErrorCount…)
Free vs. Paid:
| Free Metrics | Advanced Metrics & Recommendations | |
|---|---|---|
| Chi phí | Tự động miễn phí cho mọi khách hàng | Trả phí thêm |
| Số lượng metric | ~28 usage metrics | Thêm: Activity, Advanced Cost Optimization, Advanced Data Protection, Status Code |
| Khác | CloudWatch Publishing (xem metric trên CloudWatch miễn phí), Prefix Aggregation | |
| Lưu trữ dữ liệu để query | 14 ngày | 15 tháng |
- Understand, analyze, and optimize storage across the entire AWS Organization
- Discover anomalies, identify cost efficiencies, apply data protection best practices across the whole Organization (30 days of usage & activity metrics)
- Aggregate data for Organization, specific accounts, regions, buckets, or prefixes
- Default dashboard or create your own dashboards
- Can be configured to export metrics daily to an S3 bucket (CSV, Parquet)
Default Dashboard:
- Visualizes summarized insights and trends for both free and advanced metrics
- Shows Multi-Region and Multi-Account data
- Preconfigured by Amazon S3
- Can't be deleted, but can be disabled
Metric groups:
- Summary Metrics — general insights (StorageBytes, ObjectCount…) — identify fastest-growing (or unused) buckets/prefixes
- Cost-Optimization Metrics — (NonCurrentVersionStorageBytes, IncompleteMultipartUploadStorageBytes…) — find multipart uploads incomplete > 7 days, objects that could move to lower-cost classes
- Data-Protection Metrics — (VersioningEnabledBucketCount, MFADeleteEnabledBucketCount, SSEKMSEnabledBucketCount, CrossRegionReplicationRuleCount…)
- Access-management Metrics — insights for S3 Object Ownership
- Event Metrics — insights for S3 Event Notifications
- Performance Metrics — insights for S3 Transfer Acceleration
- Activity Metrics — how storage is requested (AllRequests, GetRequests, PutRequests, ListRequests, BytesDownloaded…)
- Detailed Status Code Metrics — insights per HTTP status code (200OKStatusCount, 403ForbiddenErrorCount, 404NotFoundErrorCount…)
Free vs. Paid:
| Free Metrics | Advanced Metrics & Recommendations | |
|---|---|---|
| Cost | Automatically available for all customers | Additional paid |
| Metric count | ~28 usage metrics | Adds: Activity, Advanced Cost Optimization, Advanced Data Protection, Status Code |
| Extras | CloudWatch Publishing (free), Prefix Aggregation | |
| Query retention | 14 days | 15 months |