Skip to content

Amazon S3 — Introduction (Bản gốc slide / Original slide)

1. Amazon S3 — Giới thiệu & Use Cases (Introduction & Use Cases)

  • Amazon S3 là một trong những building block chính của AWS
  • Được quảng bá là storage "scale vô hạn" (infinitely scaling)
  • Rất nhiều website dùng S3 làm nền tảng lưu trữ (backbone)
  • Rất nhiều dịch vụ AWS khác cũng tích hợp với S3

Use cases:

  • Backup & storage, Disaster Recovery
  • Archive (ví dụ: Nasdaq lưu 7 năm dữ liệu vào S3 Glacier)
  • Hybrid Cloud storage
  • Application hosting, Media hosting
  • Data lakes & big data analytics (ví dụ: Sysco chạy analytics trên dữ liệu để có business insight)
  • Software delivery
  • Static website
  • Amazon S3 is one of the main building blocks of AWS
  • Advertised as "infinitely scaling" storage
  • Many websites use S3 as their backbone
  • Many AWS services integrate with S3 as well

Use cases:

  • Backup & storage, Disaster Recovery
  • Archive (e.g., Nasdaq stores 7 years of data into S3 Glacier)
  • Hybrid Cloud storage
  • Application hosting, Media hosting
  • Data lakes & big data analytics (e.g., Sysco runs analytics on its data to gain business insights)
  • Software delivery
  • Static website

2. S3 — Buckets & Objects

S3 Buckets3://my-bucketmy_file.txtmy_folder1/another_folder/my_file.txt (key = prefix + name)Key = FULL paths3://my-bucket/my_file.txts3://my-bucket/my_folder1/another_folder/my_file.txt"Directory" is just a UI trick —keys are flat strings with "/"

Buckets:

  • S3 cho phép lưu object (file) vào "bucket" (giống thư mục)
  • Bucket được định nghĩa ở cấp Region
  • S3 trông như một dịch vụ global nhưng bucket thực chất được tạo trong một region cụ thể
  • Naming:
    • Shared Global Namespace — tên bucket phải duy nhất toàn cầu (trên mọi region, mọi account)
    • Account Regional Namespace — cho phép tái sử dụng cùng tên bucket ở các region khác nhau (tính năng mới hơn)
  • Ràng buộc đặt tên:
    • Không viết hoa, không dùng underscore
    • Không phải là một IP
    • Phải bắt đầu bằng chữ thường hoặc số
    • Không được bắt đầu bằng prefix xn--
    • Không được kết thúc bằng suffix -s3alias

Objects:

  • Object (file) có một Key — chính là đường dẫn đầy đủ (full path)
  • Key = prefix + tên object
  • Không có khái niệm "thư mục" thực sự trong bucket (dù UI khiến ta nghĩ vậy) — chỉ là các key rất dài chứa dấu /
  • Giá trị của object là nội dung (body):
    • Kích thước tối đa 50TB (50,000GB)
    • Nếu upload > 5GB phải dùng "multi-part upload"
  • Ngoài ra object còn có: Metadata (key/value text), Tags (tối đa 10 cặp Unicode key/value — hữu ích cho security/lifecycle), Version ID (nếu bật versioning)

Buckets:

  • S3 lets you store objects (files) in "buckets" (like directories)
  • Buckets are defined at the Region level
  • S3 looks like a global service, but buckets are actually created in a specific region
  • Naming:
    • Shared Global Namespace — must have a globally unique name (across all regions, all accounts)
    • Account Regional Namespace — allows "reuse" of the same bucket name across regions (newer feature)
  • Naming constraints:
    • No uppercase, no underscore
    • Not an IP
    • Must start with a lowercase letter or number
    • Must NOT start with the prefix xn--
    • Must NOT end with the suffix -s3alias

Objects:

  • Objects (files) have a Key — the FULL path
  • Key = prefix + object name
  • There's no real "directory" concept within buckets (although the UI tricks you into thinking otherwise) — just keys with very long names containing /
  • Object values are the content of the body:
    • Max. object size is 50TB (50,000GB)
    • If uploading more than 5GB, must use "multi-part upload"
  • Objects also carry: Metadata (text key/value pairs), Tags (up to 10 Unicode key/value pairs — useful for security/lifecycle), Version ID (if versioning is enabled)

3. S3 — Security Overview (Bảo mật tổng quan)

Resource-Based (Bucket Policy / ACL)Anonymous visitorBucket PolicyAllows Public AccessBucket PolicyAllows Cross-AccountIAM User (other account)User-Based (IAM Policies / Roles)IAM UserIAM PolicyEC2EC2 RoleS3 Bucket
  • User-Based:
    • IAM Policies — chỉ định API call nào được phép cho một IAM user cụ thể
  • Resource-Based:
    • Bucket Policies — rule áp dụng cho toàn bucket, cấu hình từ S3 console, cho phép cross-account
    • Object Access Control List (ACL) — chi tiết hơn, ở mức từng object (có thể tắt)
    • Bucket Access Control List (ACL) — ít dùng hơn (có thể tắt)
  • Quy tắc quan trọng: một IAM principal có thể truy cập object S3 nếu:
    • IAM permission của user CHO PHÉP, HOẶC resource policy CHO PHÉP
    • không có DENY tường minh nào
  • Encryption: mã hoá object trong S3 bằng encryption key (xem phần S3 — Security)
  • User-Based:
    • IAM Policies — which API calls should be allowed for a specific IAM user
  • Resource-Based:
    • Bucket Policies — bucket-wide rules from the S3 console — allows cross-account access
    • Object Access Control List (ACL) — finer grain, per object (can be disabled)
    • Bucket Access Control List (ACL) — less common (can be disabled)
  • Key rule: an IAM principal can access an S3 object if:
    • The user's IAM permissions ALLOW it OR the resource policy ALLOWS it
    • AND there's no explicit DENY
  • Encryption: encrypt objects in S3 using encryption keys (see the S3 — Security part)

4. S3 Bucket Policies

  • JSON-based policy gồm:
    • Resources: bucket và object
    • Effect: Allow / Deny
    • Actions: tập hợp API được Allow/Deny
    • Principal: account/user áp dụng policy
  • Dùng S3 bucket policy để:
    • Cấp quyền public cho bucket
    • Bắt buộc mã hoá object khi upload
    • Cấp quyền cho account khác (Cross-Account)

4 kiểu truy cập S3 thường gặp (xem sơ đồ mục 3):

  1. Public Access — Bucket Policy cho phép anonymous visitor (ví dụ static website)
  2. IAM User Access — IAM Policy gắn cho IAM user
  3. EC2 Instance Access — dùng IAM Role gắn vào EC2 instance
  4. Cross-Account Access — Bucket Policy cho phép IAM user ở account khác
  • JSON based policy, containing:
    • Resources: buckets and objects
    • Effect: Allow / Deny
    • Actions: set of API calls to Allow/Deny
    • Principal: the account/user the policy applies to
  • Use an S3 bucket policy to:
    • Grant public access to the bucket
    • Force objects to be encrypted at upload
    • Grant access to another account (Cross-Account)

4 common S3 access patterns (see diagram in section 3):

  1. Public Access — Bucket Policy allows an anonymous visitor (e.g., static website)
  2. IAM User Access — IAM Policy attached to an IAM user
  3. EC2 Instance Access — using an IAM Role attached to the EC2 instance
  4. Cross-Account Access — Bucket Policy allows an IAM user in another account

5. Bucket settings for Block Public Access

  • Các setting này được tạo ra để ngăn rò rỉ dữ liệu công ty (data leak)
  • Nếu bạn biết chắc bucket không bao giờ nên public, hãy để các setting này bật (ON)
  • Có thể cấu hình ở cấp account (áp dụng cho toàn bộ bucket)
  • These settings were created to prevent company data leaks
  • If you know your bucket should never be public, leave these ON
  • Can be set at the account level

6. Amazon S3 — Static Website Hosting

  • S3 có thể host static website và truy cập được qua Internet
  • URL của website (tuỳ region):
    • http://bucket-name.s3-website-aws-region.amazonaws.com
    • hoặc http://bucket-name.s3-website.aws-region.amazonaws.com
  • Nếu gặp lỗi 403 Forbidden, kiểm tra lại bucket policy đã cho phép public read hay chưa
  • S3 can host static websites and have them accessible on the Internet
  • The website URL (depending on region):
    • http://bucket-name.s3-website-aws-region.amazonaws.com
    • or http://bucket-name.s3-website.aws-region.amazonaws.com
  • If you get a 403 Forbidden error, make sure the bucket policy allows public reads!

7. Amazon S3 — Versioning

  • Có thể version hoá file trong S3, bật ở cấp bucket
  • Upload cùng một key sẽ tạo version mới: 1, 2, 3…
  • Best practice: nên bật versioning cho bucket vì:
    • Bảo vệ khỏi xoá nhầm (unintended delete) — có thể khôi phục version cũ
    • Dễ dàng rollback về version trước
  • Lưu ý:
    • File nào chưa được version hoá trước khi bật versioning sẽ có version null
    • Tạm dừng (suspend) versioning KHÔNG xoá các version đã có trước đó
  • You can version your files in S3, enabled at the bucket level
  • Uploading to the same key creates a new version: 1, 2, 3…
  • Best practice: version your buckets because it:
    • Protects against unintended deletes (ability to restore a version)
    • Allows easy rollback to a previous version
  • Notes:
    • Any file not versioned prior to enabling versioning will have version null
    • Suspending versioning does NOT delete previous versions

8. Amazon S3 — Replication (CRR & SRR)

S3 Bucket(eu-west-1) — sourceS3 Bucket(us-east-2) — destinationasynchronous replicationVersioning must be enabled on BOTH buckets
  • Phải bật Versioning trên cả bucket nguồn và bucket đích
  • Cross-Region Replication (CRR) — replicate sang region khác
  • Same-Region Replication (SRR) — replicate trong cùng region
  • Bucket nguồn/đích có thể ở account AWS khác nhau
  • Việc copy diễn ra bất đồng bộ (asynchronous)
  • Phải cấp đúng IAM permission cho S3 để thực hiện replication
  • Use cases:
    • CRR — compliance, giảm latency truy cập, replicate xuyên account
    • SRR — tổng hợp log, replicate live giữa account production và test

Lưu ý về Replication:

  • Sau khi bật Replication, chỉ object MỚI mới được replicate
  • Muốn replicate object đã tồn tại từ trước, dùng S3 Batch Replication (replicate cả object cũ lẫn object bị lỗi replication)
  • Với thao tác DELETE:
    • Có thể replicate delete marker từ nguồn sang đích (tuỳ chọn)
    • Xoá có kèm version ID KHÔNG được replicate (để tránh xoá độc hại/malicious deletes)
  • Không có "chaining" replication: nếu bucket 1 replicate sang bucket 2, và bucket 2 replicate sang bucket 3, thì object tạo mới ở bucket 1 KHÔNG được replicate tới bucket 3
  • Must enable Versioning in both source and destination buckets
  • Cross-Region Replication (CRR) — replicate to a different region
  • Same-Region Replication (SRR) — replicate within the same region
  • Buckets can be in different AWS accounts
  • Copying is asynchronous
  • Must give proper IAM permissions to S3
  • Use cases:
    • CRR — compliance, lower latency access, replication across accounts
    • SRR — log aggregation, live replication between production and test accounts

Replication notes:

  • After enabling Replication, only new objects are replicated
  • Optionally, replicate existing objects using S3 Batch Replication (replicates existing objects and objects that failed replication)
  • For DELETE operations:
    • Can replicate delete markers from source to target (optional)
    • Deletions with a version ID are NOT replicated (to avoid malicious deletes)
  • There is no "chaining" of replication: if bucket 1 replicates into bucket 2, which replicates into bucket 3, objects created in bucket 1 are NOT replicated to bucket 3

9. S3 Storage Classes — Tổng quan (Overview)

  • Amazon S3 Standard – General Purpose
  • Amazon S3 Standard-Infrequent Access (IA)
  • Amazon S3 One Zone-Infrequent Access
  • Amazon S3 Glacier Instant Retrieval
  • Amazon S3 Glacier Flexible Retrieval
  • Amazon S3 Glacier Deep Archive
  • Amazon S3 Intelligent-Tiering
  • Amazon S3 Express One Zone
  • Có thể chuyển giữa các class thủ công hoặc dùng S3 Lifecycle configuration
  • Amazon S3 Standard – General Purpose
  • Amazon S3 Standard-Infrequent Access (IA)
  • Amazon S3 One Zone-Infrequent Access
  • Amazon S3 Glacier Instant Retrieval
  • Amazon S3 Glacier Flexible Retrieval
  • Amazon S3 Glacier Deep Archive
  • Amazon S3 Intelligent-Tiering
  • Amazon S3 Express One Zone
  • Can move between classes manually or using S3 Lifecycle configurations

10. S3 Durability & Availability

Durability (độ bền dữ liệu):

  • 99.999999999% (11 số 9) độ bền của object, trải trên nhiều AZ
  • Nếu lưu 10,000,000 object, trung bình chỉ mất 1 object mỗi 10,000 năm
  • Giống nhau cho MỌI storage class

Availability (tính sẵn sàng):

  • Đo mức độ service luôn sẵn sàng phục vụ
  • Khác nhau tuỳ storage class
  • Ví dụ: S3 Standard có 99.99% availability = không khả dụng khoảng 53 phút/năm

Durability:

  • High durability (99.999999999%, 11 9's) of objects across multiple AZ
  • If you store 10,000,000 objects, you can expect on average to lose a single object every 10,000 years
  • Same for all storage classes

Availability:

  • Measures how readily available a service is
  • Varies depending on storage class
  • Example: S3 Standard has 99.99% availability = not available 53 minutes a year

11. S3 Standard — General Purpose

  • 99.99% Availability
  • Dùng cho dữ liệu truy cập thường xuyên
  • Độ trễ thấp, throughput cao
  • Chịu được 2 sự cố facility đồng thời
  • Use cases: Big Data analytics, ứng dụng mobile & gaming, phân phối nội dung…
  • 99.99% Availability
  • Used for frequently accessed data
  • Low latency and high throughput
  • Sustains 2 concurrent facility failures
  • Use cases: Big Data analytics, mobile & gaming applications, content distribution…

12. S3 Storage Classes — Infrequent Access

Dùng cho dữ liệu ít truy cập nhưng cần lấy nhanh khi cần; chi phí thấp hơn Standard.

  • S3 Standard-IA
    • 99.9% Availability
    • Use cases: Disaster Recovery, backups
  • S3 One Zone-IA
    • Độ bền cao (99.999999999%) nhưng chỉ trong MỘT AZ — mất dữ liệu nếu AZ bị phá huỷ
    • 99.5% Availability
    • Use cases: lưu bản sao backup phụ (secondary) của dữ liệu on-premises, hoặc dữ liệu có thể tạo lại được

For data that is less frequently accessed, but requires rapid access when needed; lower cost than S3 Standard.

  • S3 Standard-IA
    • 99.9% Availability
    • Use cases: Disaster Recovery, backups
  • S3 One Zone-IA
    • High durability (99.999999999%) in a single AZ — data lost when AZ is destroyed
    • 99.5% Availability
    • Use cases: storing secondary backup copies of on-premises data, or data you can recreate

13. Amazon S3 Glacier Storage Classes

  • Storage object chi phí thấp dành cho archiving/backup
  • Giá = chi phí lưu trữ + chi phí truy xuất (retrieval)
ClassTốc độ truy xuấtMin. storage duration
S3 Glacier Instant RetrievalMili-giây — phù hợp dữ liệu truy cập 1 lần/quý90 ngày
S3 Glacier Flexible Retrieval (trước là "S3 Glacier")Expedited (1–5 phút), Standard (3–5 giờ), Bulk (5–12 giờ — miễn phí)90 ngày
S3 Glacier Deep Archive (lưu trữ dài hạn)Standard (12 giờ), Bulk (48 giờ)180 ngày
  • Low-cost object storage meant for archiving/backup
  • Pricing = storage cost + retrieval cost
ClassRetrieval speedMin. storage duration
S3 Glacier Instant RetrievalMillisecond — great for data accessed once a quarter90 days
S3 Glacier Flexible Retrieval (formerly "S3 Glacier")Expedited (1–5 min), Standard (3–5 hrs), Bulk (5–12 hrs — free)90 days
S3 Glacier Deep Archive (long-term storage)Standard (12 hrs), Bulk (48 hrs)180 days

14. S3 Intelligent-Tiering

  • Chỉ tính phí giám sát & auto-tiering hằng tháng nhỏ
  • Tự động chuyển object giữa các Access Tier dựa trên usage pattern
  • Không tính phí retrieval
  • Các tier:
    • Frequent Access tier (tự động) — mặc định
    • Infrequent Access tier (tự động) — object không truy cập trong 30 ngày
    • Archive Instant Access tier (tự động) — object không truy cập trong 90 ngày
    • Archive Access tier (tuỳ chọn) — cấu hình từ 90 tới 700+ ngày
    • Deep Archive Access tier (tuỳ chọn) — cấu hình từ 180 tới 700+ ngày
  • Small monthly monitoring and auto-tiering fee
  • Moves objects automatically between Access Tiers based on usage
  • No retrieval charges
  • Tiers:
    • Frequent Access tier (automatic) — default tier
    • Infrequent Access tier (automatic) — objects not accessed for 30 days
    • Archive Instant Access tier (automatic) — objects not accessed for 90 days
    • Archive Access tier (optional) — configurable from 90 to 700+ days
    • Deep Archive Access tier (optional) — configurable from 180 to 700+ days

15. S3 Storage Classes — So sánh (Comparison)

StandardIntelligent-TieringStandard-IAOne Zone-IAGlacier InstantGlacier FlexibleGlacier Deep Archive
Durability99.999999999% (11 9's) cho tất cả class
Availability99.99%99.9%99.9%99.5%99.9%99.99%99.99%
Availability SLA99.9%99%99%99%99%99.9%99.9%
Số AZ≥ 3≥ 3≥ 31≥ 3≥ 3≥ 3
Min. storage durationKhôngKhông30 ngày30 ngày90 ngày90 ngày180 ngày
Min. billable object sizeKhôngKhông128 KB128 KB128 KB40 KB40 KB
Phí retrievalKhôngKhôngTheo GBTheo GBTheo GBTheo GBTheo GB
StandardIntelligent-TieringStandard-IAOne Zone-IAGlacier InstantGlacier FlexibleGlacier Deep Archive
Durability99.999999999% (11 9's) for all classes
Availability99.99%99.9%99.9%99.5%99.9%99.99%99.99%
Availability SLA99.9%99%99%99%99%99.9%99.9%
Availability Zones≥ 3≥ 3≥ 31≥ 3≥ 3≥ 3
Min. storage durationNoneNone30 days30 days90 days90 days180 days
Min. billable object sizeNoneNone128 KB128 KB128 KB40 KB40 KB
Retrieval feeNoneNonePer GBPer GBPer GBPer GBPer GB

16. S3 Storage Classes — So sánh giá (Price Comparison, minh hoạ / illustrative — us-east-1)

⚠️ Bảng dưới mang tính minh hoạ (giá AWS thay đổi theo thời gian) — chỉ để nắm thứ tự chi phí tương đối giữa các storage class.

StandardIntelligent-TieringStandard-IAOne Zone-IAGlacier InstantGlacier FlexibleGlacier Deep Archive
Storage (per GB/tháng)Cao nhấtThấp – Cao (tự động tối ưu)Trung bìnhThấp hơn Standard-IAThấpRất thấpThấp nhất
RetrievalMiễn phíMiễn phíTheo GBTheo GBTheo GB (đắt hơn IA)Theo GB + tốc độ (Expedited đắt nhất)Theo GB + tốc độ (Standard/Bulk)
Retrieval timeNgay lập tứcNgay lập tứcNgay lập tứcNgay lập tứcMili-giâyPhút → giờ12–48 giờ
Monitoring costKhôngCó (nhỏ, theo 1000 object)KhôngKhôngKhôngKhôngKhông

⚠️ The table below is illustrative (AWS pricing changes over time) — just to grasp the relative cost ordering across storage classes.

StandardIntelligent-TieringStandard-IAOne Zone-IAGlacier InstantGlacier FlexibleGlacier Deep Archive
Storage (per GB/month)HighestLow – High (auto-optimized)MediumLower than Standard-IALowVery lowLowest
RetrievalFreeFreePer GBPer GBPer GB (pricier than IA)Per GB + speed (Expedited priciest)Per GB + speed (Standard/Bulk)
Retrieval timeInstantInstantInstantInstantMillisecondsMinutes → hours12–48 hours
Monitoring costNoneYes (small, per 1000 objects)NoneNoneNoneNoneNone

17. S3 Express One Zone

  • Storage class hiệu năng cao, single AZ
  • Object lưu trong Directory Bucket (bucket nằm trong một AZ duy nhất)
  • Xử lý hàng trăm nghìn request/giây với độ trễ mili-giây một chữ số
  • Hiệu năng tới 10x tốt hơn S3 Standard (và giảm 50% chi phí)
  • Độ bền cao (99.999999999%) và availability 99.95%
  • Có thể đặt storage cùng AZ với compute để giảm latency
  • Use cases: ứng dụng nhạy cảm độ trễ, ứng dụng nặng dữ liệu, huấn luyện AI/ML, mô hình tài chính, xử lý media, HPC…
  • Tích hợp tốt nhất với: SageMaker Model Training, Athena, EMR, Glue…
  • High performance, single Availability Zone storage class
  • Objects stored in a Directory Bucket (bucket in a single AZ)
  • Handles 100,000s requests per second with single-digit millisecond latency
  • Up to 10x better performance than S3 Standard (50% lower costs)
  • High Durability (99.999999999%) and Availability (99.95%)
  • Can co-locate storage and compute in the same AZ (reduces latency)
  • Use cases: latency-sensitive apps, data-intensive apps, AI & ML training, financial modeling, media processing, HPC…
  • Best integrated with: SageMaker Model Training, Athena, EMR, Glue…

Personal notes by thanhlt