Appearance
Amazon S3 — Introduction (Bản gốc slide / Original slide)
1. Amazon S3 — Giới thiệu & Use Cases (Introduction & Use Cases)
- Amazon S3 là một trong những building block chính của AWS
- Được quảng bá là storage "scale vô hạn" (infinitely scaling)
- Rất nhiều website dùng S3 làm nền tảng lưu trữ (backbone)
- Rất nhiều dịch vụ AWS khác cũng tích hợp với S3
Use cases:
- Backup & storage, Disaster Recovery
- Archive (ví dụ: Nasdaq lưu 7 năm dữ liệu vào S3 Glacier)
- Hybrid Cloud storage
- Application hosting, Media hosting
- Data lakes & big data analytics (ví dụ: Sysco chạy analytics trên dữ liệu để có business insight)
- Software delivery
- Static website
- Amazon S3 is one of the main building blocks of AWS
- Advertised as "infinitely scaling" storage
- Many websites use S3 as their backbone
- Many AWS services integrate with S3 as well
Use cases:
- Backup & storage, Disaster Recovery
- Archive (e.g., Nasdaq stores 7 years of data into S3 Glacier)
- Hybrid Cloud storage
- Application hosting, Media hosting
- Data lakes & big data analytics (e.g., Sysco runs analytics on its data to gain business insights)
- Software delivery
- Static website
2. S3 — Buckets & Objects
Buckets:
- S3 cho phép lưu object (file) vào "bucket" (giống thư mục)
- Bucket được định nghĩa ở cấp Region
- S3 trông như một dịch vụ global nhưng bucket thực chất được tạo trong một region cụ thể
- Naming:
- Shared Global Namespace — tên bucket phải duy nhất toàn cầu (trên mọi region, mọi account)
- Account Regional Namespace — cho phép tái sử dụng cùng tên bucket ở các region khác nhau (tính năng mới hơn)
- Ràng buộc đặt tên:
- Không viết hoa, không dùng underscore
- Không phải là một IP
- Phải bắt đầu bằng chữ thường hoặc số
- Không được bắt đầu bằng prefix
xn-- - Không được kết thúc bằng suffix
-s3alias
Objects:
- Object (file) có một Key — chính là đường dẫn đầy đủ (full path)
- Key = prefix + tên object
- Không có khái niệm "thư mục" thực sự trong bucket (dù UI khiến ta nghĩ vậy) — chỉ là các key rất dài chứa dấu
/ - Giá trị của object là nội dung (body):
- Kích thước tối đa 50TB (50,000GB)
- Nếu upload > 5GB phải dùng "multi-part upload"
- Ngoài ra object còn có: Metadata (key/value text), Tags (tối đa 10 cặp Unicode key/value — hữu ích cho security/lifecycle), Version ID (nếu bật versioning)
Buckets:
- S3 lets you store objects (files) in "buckets" (like directories)
- Buckets are defined at the Region level
- S3 looks like a global service, but buckets are actually created in a specific region
- Naming:
- Shared Global Namespace — must have a globally unique name (across all regions, all accounts)
- Account Regional Namespace — allows "reuse" of the same bucket name across regions (newer feature)
- Naming constraints:
- No uppercase, no underscore
- Not an IP
- Must start with a lowercase letter or number
- Must NOT start with the prefix
xn-- - Must NOT end with the suffix
-s3alias
Objects:
- Objects (files) have a Key — the FULL path
- Key = prefix + object name
- There's no real "directory" concept within buckets (although the UI tricks you into thinking otherwise) — just keys with very long names containing
/ - Object values are the content of the body:
- Max. object size is 50TB (50,000GB)
- If uploading more than 5GB, must use "multi-part upload"
- Objects also carry: Metadata (text key/value pairs), Tags (up to 10 Unicode key/value pairs — useful for security/lifecycle), Version ID (if versioning is enabled)
3. S3 — Security Overview (Bảo mật tổng quan)
- User-Based:
- IAM Policies — chỉ định API call nào được phép cho một IAM user cụ thể
- Resource-Based:
- Bucket Policies — rule áp dụng cho toàn bucket, cấu hình từ S3 console, cho phép cross-account
- Object Access Control List (ACL) — chi tiết hơn, ở mức từng object (có thể tắt)
- Bucket Access Control List (ACL) — ít dùng hơn (có thể tắt)
- Quy tắc quan trọng: một IAM principal có thể truy cập object S3 nếu:
- IAM permission của user CHO PHÉP, HOẶC resource policy CHO PHÉP
- VÀ không có DENY tường minh nào
- Encryption: mã hoá object trong S3 bằng encryption key (xem phần S3 — Security)
- User-Based:
- IAM Policies — which API calls should be allowed for a specific IAM user
- Resource-Based:
- Bucket Policies — bucket-wide rules from the S3 console — allows cross-account access
- Object Access Control List (ACL) — finer grain, per object (can be disabled)
- Bucket Access Control List (ACL) — less common (can be disabled)
- Key rule: an IAM principal can access an S3 object if:
- The user's IAM permissions ALLOW it OR the resource policy ALLOWS it
- AND there's no explicit DENY
- Encryption: encrypt objects in S3 using encryption keys (see the S3 — Security part)
4. S3 Bucket Policies
- Là JSON-based policy gồm:
- Resources: bucket và object
- Effect: Allow / Deny
- Actions: tập hợp API được Allow/Deny
- Principal: account/user áp dụng policy
- Dùng S3 bucket policy để:
- Cấp quyền public cho bucket
- Bắt buộc mã hoá object khi upload
- Cấp quyền cho account khác (Cross-Account)
4 kiểu truy cập S3 thường gặp (xem sơ đồ mục 3):
- Public Access — Bucket Policy cho phép anonymous visitor (ví dụ static website)
- IAM User Access — IAM Policy gắn cho IAM user
- EC2 Instance Access — dùng IAM Role gắn vào EC2 instance
- Cross-Account Access — Bucket Policy cho phép IAM user ở account khác
- JSON based policy, containing:
- Resources: buckets and objects
- Effect: Allow / Deny
- Actions: set of API calls to Allow/Deny
- Principal: the account/user the policy applies to
- Use an S3 bucket policy to:
- Grant public access to the bucket
- Force objects to be encrypted at upload
- Grant access to another account (Cross-Account)
4 common S3 access patterns (see diagram in section 3):
- Public Access — Bucket Policy allows an anonymous visitor (e.g., static website)
- IAM User Access — IAM Policy attached to an IAM user
- EC2 Instance Access — using an IAM Role attached to the EC2 instance
- Cross-Account Access — Bucket Policy allows an IAM user in another account
5. Bucket settings for Block Public Access
- Các setting này được tạo ra để ngăn rò rỉ dữ liệu công ty (data leak)
- Nếu bạn biết chắc bucket không bao giờ nên public, hãy để các setting này bật (ON)
- Có thể cấu hình ở cấp account (áp dụng cho toàn bộ bucket)
- These settings were created to prevent company data leaks
- If you know your bucket should never be public, leave these ON
- Can be set at the account level
6. Amazon S3 — Static Website Hosting
- S3 có thể host static website và truy cập được qua Internet
- URL của website (tuỳ region):
http://bucket-name.s3-website-aws-region.amazonaws.com- hoặc
http://bucket-name.s3-website.aws-region.amazonaws.com
- Nếu gặp lỗi 403 Forbidden, kiểm tra lại bucket policy đã cho phép public read hay chưa
- S3 can host static websites and have them accessible on the Internet
- The website URL (depending on region):
http://bucket-name.s3-website-aws-region.amazonaws.com- or
http://bucket-name.s3-website.aws-region.amazonaws.com
- If you get a 403 Forbidden error, make sure the bucket policy allows public reads!
7. Amazon S3 — Versioning
- Có thể version hoá file trong S3, bật ở cấp bucket
- Upload cùng một key sẽ tạo version mới: 1, 2, 3…
- Best practice: nên bật versioning cho bucket vì:
- Bảo vệ khỏi xoá nhầm (unintended delete) — có thể khôi phục version cũ
- Dễ dàng rollback về version trước
- Lưu ý:
- File nào chưa được version hoá trước khi bật versioning sẽ có version
null - Tạm dừng (suspend) versioning KHÔNG xoá các version đã có trước đó
- File nào chưa được version hoá trước khi bật versioning sẽ có version
- You can version your files in S3, enabled at the bucket level
- Uploading to the same key creates a new version: 1, 2, 3…
- Best practice: version your buckets because it:
- Protects against unintended deletes (ability to restore a version)
- Allows easy rollback to a previous version
- Notes:
- Any file not versioned prior to enabling versioning will have version
null - Suspending versioning does NOT delete previous versions
- Any file not versioned prior to enabling versioning will have version
8. Amazon S3 — Replication (CRR & SRR)
- Phải bật Versioning trên cả bucket nguồn và bucket đích
- Cross-Region Replication (CRR) — replicate sang region khác
- Same-Region Replication (SRR) — replicate trong cùng region
- Bucket nguồn/đích có thể ở account AWS khác nhau
- Việc copy diễn ra bất đồng bộ (asynchronous)
- Phải cấp đúng IAM permission cho S3 để thực hiện replication
- Use cases:
- CRR — compliance, giảm latency truy cập, replicate xuyên account
- SRR — tổng hợp log, replicate live giữa account production và test
Lưu ý về Replication:
- Sau khi bật Replication, chỉ object MỚI mới được replicate
- Muốn replicate object đã tồn tại từ trước, dùng S3 Batch Replication (replicate cả object cũ lẫn object bị lỗi replication)
- Với thao tác DELETE:
- Có thể replicate delete marker từ nguồn sang đích (tuỳ chọn)
- Xoá có kèm version ID KHÔNG được replicate (để tránh xoá độc hại/malicious deletes)
- Không có "chaining" replication: nếu bucket 1 replicate sang bucket 2, và bucket 2 replicate sang bucket 3, thì object tạo mới ở bucket 1 KHÔNG được replicate tới bucket 3
- Must enable Versioning in both source and destination buckets
- Cross-Region Replication (CRR) — replicate to a different region
- Same-Region Replication (SRR) — replicate within the same region
- Buckets can be in different AWS accounts
- Copying is asynchronous
- Must give proper IAM permissions to S3
- Use cases:
- CRR — compliance, lower latency access, replication across accounts
- SRR — log aggregation, live replication between production and test accounts
Replication notes:
- After enabling Replication, only new objects are replicated
- Optionally, replicate existing objects using S3 Batch Replication (replicates existing objects and objects that failed replication)
- For DELETE operations:
- Can replicate delete markers from source to target (optional)
- Deletions with a version ID are NOT replicated (to avoid malicious deletes)
- There is no "chaining" of replication: if bucket 1 replicates into bucket 2, which replicates into bucket 3, objects created in bucket 1 are NOT replicated to bucket 3
9. S3 Storage Classes — Tổng quan (Overview)
- Amazon S3 Standard – General Purpose
- Amazon S3 Standard-Infrequent Access (IA)
- Amazon S3 One Zone-Infrequent Access
- Amazon S3 Glacier Instant Retrieval
- Amazon S3 Glacier Flexible Retrieval
- Amazon S3 Glacier Deep Archive
- Amazon S3 Intelligent-Tiering
- Amazon S3 Express One Zone
- Có thể chuyển giữa các class thủ công hoặc dùng S3 Lifecycle configuration
- Amazon S3 Standard – General Purpose
- Amazon S3 Standard-Infrequent Access (IA)
- Amazon S3 One Zone-Infrequent Access
- Amazon S3 Glacier Instant Retrieval
- Amazon S3 Glacier Flexible Retrieval
- Amazon S3 Glacier Deep Archive
- Amazon S3 Intelligent-Tiering
- Amazon S3 Express One Zone
- Can move between classes manually or using S3 Lifecycle configurations
10. S3 Durability & Availability
Durability (độ bền dữ liệu):
- 99.999999999% (11 số 9) độ bền của object, trải trên nhiều AZ
- Nếu lưu 10,000,000 object, trung bình chỉ mất 1 object mỗi 10,000 năm
- Giống nhau cho MỌI storage class
Availability (tính sẵn sàng):
- Đo mức độ service luôn sẵn sàng phục vụ
- Khác nhau tuỳ storage class
- Ví dụ: S3 Standard có 99.99% availability = không khả dụng khoảng 53 phút/năm
Durability:
- High durability (99.999999999%, 11 9's) of objects across multiple AZ
- If you store 10,000,000 objects, you can expect on average to lose a single object every 10,000 years
- Same for all storage classes
Availability:
- Measures how readily available a service is
- Varies depending on storage class
- Example: S3 Standard has 99.99% availability = not available 53 minutes a year
11. S3 Standard — General Purpose
- 99.99% Availability
- Dùng cho dữ liệu truy cập thường xuyên
- Độ trễ thấp, throughput cao
- Chịu được 2 sự cố facility đồng thời
- Use cases: Big Data analytics, ứng dụng mobile & gaming, phân phối nội dung…
- 99.99% Availability
- Used for frequently accessed data
- Low latency and high throughput
- Sustains 2 concurrent facility failures
- Use cases: Big Data analytics, mobile & gaming applications, content distribution…
12. S3 Storage Classes — Infrequent Access
Dùng cho dữ liệu ít truy cập nhưng cần lấy nhanh khi cần; chi phí thấp hơn Standard.
- S3 Standard-IA
- 99.9% Availability
- Use cases: Disaster Recovery, backups
- S3 One Zone-IA
- Độ bền cao (99.999999999%) nhưng chỉ trong MỘT AZ — mất dữ liệu nếu AZ bị phá huỷ
- 99.5% Availability
- Use cases: lưu bản sao backup phụ (secondary) của dữ liệu on-premises, hoặc dữ liệu có thể tạo lại được
For data that is less frequently accessed, but requires rapid access when needed; lower cost than S3 Standard.
- S3 Standard-IA
- 99.9% Availability
- Use cases: Disaster Recovery, backups
- S3 One Zone-IA
- High durability (99.999999999%) in a single AZ — data lost when AZ is destroyed
- 99.5% Availability
- Use cases: storing secondary backup copies of on-premises data, or data you can recreate
13. Amazon S3 Glacier Storage Classes
- Storage object chi phí thấp dành cho archiving/backup
- Giá = chi phí lưu trữ + chi phí truy xuất (retrieval)
| Class | Tốc độ truy xuất | Min. storage duration |
|---|---|---|
| S3 Glacier Instant Retrieval | Mili-giây — phù hợp dữ liệu truy cập 1 lần/quý | 90 ngày |
| S3 Glacier Flexible Retrieval (trước là "S3 Glacier") | Expedited (1–5 phút), Standard (3–5 giờ), Bulk (5–12 giờ — miễn phí) | 90 ngày |
| S3 Glacier Deep Archive (lưu trữ dài hạn) | Standard (12 giờ), Bulk (48 giờ) | 180 ngày |
- Low-cost object storage meant for archiving/backup
- Pricing = storage cost + retrieval cost
| Class | Retrieval speed | Min. storage duration |
|---|---|---|
| S3 Glacier Instant Retrieval | Millisecond — great for data accessed once a quarter | 90 days |
| S3 Glacier Flexible Retrieval (formerly "S3 Glacier") | Expedited (1–5 min), Standard (3–5 hrs), Bulk (5–12 hrs — free) | 90 days |
| S3 Glacier Deep Archive (long-term storage) | Standard (12 hrs), Bulk (48 hrs) | 180 days |
14. S3 Intelligent-Tiering
- Chỉ tính phí giám sát & auto-tiering hằng tháng nhỏ
- Tự động chuyển object giữa các Access Tier dựa trên usage pattern
- Không tính phí retrieval
- Các tier:
- Frequent Access tier (tự động) — mặc định
- Infrequent Access tier (tự động) — object không truy cập trong 30 ngày
- Archive Instant Access tier (tự động) — object không truy cập trong 90 ngày
- Archive Access tier (tuỳ chọn) — cấu hình từ 90 tới 700+ ngày
- Deep Archive Access tier (tuỳ chọn) — cấu hình từ 180 tới 700+ ngày
- Small monthly monitoring and auto-tiering fee
- Moves objects automatically between Access Tiers based on usage
- No retrieval charges
- Tiers:
- Frequent Access tier (automatic) — default tier
- Infrequent Access tier (automatic) — objects not accessed for 30 days
- Archive Instant Access tier (automatic) — objects not accessed for 90 days
- Archive Access tier (optional) — configurable from 90 to 700+ days
- Deep Archive Access tier (optional) — configurable from 180 to 700+ days
15. S3 Storage Classes — So sánh (Comparison)
| Standard | Intelligent-Tiering | Standard-IA | One Zone-IA | Glacier Instant | Glacier Flexible | Glacier Deep Archive | |
|---|---|---|---|---|---|---|---|
| Durability | 99.999999999% (11 9's) cho tất cả class | ||||||
| Availability | 99.99% | 99.9% | 99.9% | 99.5% | 99.9% | 99.99% | 99.99% |
| Availability SLA | 99.9% | 99% | 99% | 99% | 99% | 99.9% | 99.9% |
| Số AZ | ≥ 3 | ≥ 3 | ≥ 3 | 1 | ≥ 3 | ≥ 3 | ≥ 3 |
| Min. storage duration | Không | Không | 30 ngày | 30 ngày | 90 ngày | 90 ngày | 180 ngày |
| Min. billable object size | Không | Không | 128 KB | 128 KB | 128 KB | 40 KB | 40 KB |
| Phí retrieval | Không | Không | Theo GB | Theo GB | Theo GB | Theo GB | Theo GB |
| Standard | Intelligent-Tiering | Standard-IA | One Zone-IA | Glacier Instant | Glacier Flexible | Glacier Deep Archive | |
|---|---|---|---|---|---|---|---|
| Durability | 99.999999999% (11 9's) for all classes | ||||||
| Availability | 99.99% | 99.9% | 99.9% | 99.5% | 99.9% | 99.99% | 99.99% |
| Availability SLA | 99.9% | 99% | 99% | 99% | 99% | 99.9% | 99.9% |
| Availability Zones | ≥ 3 | ≥ 3 | ≥ 3 | 1 | ≥ 3 | ≥ 3 | ≥ 3 |
| Min. storage duration | None | None | 30 days | 30 days | 90 days | 90 days | 180 days |
| Min. billable object size | None | None | 128 KB | 128 KB | 128 KB | 40 KB | 40 KB |
| Retrieval fee | None | None | Per GB | Per GB | Per GB | Per GB | Per GB |
16. S3 Storage Classes — So sánh giá (Price Comparison, minh hoạ / illustrative — us-east-1)
⚠️ Bảng dưới mang tính minh hoạ (giá AWS thay đổi theo thời gian) — chỉ để nắm thứ tự chi phí tương đối giữa các storage class.
| Standard | Intelligent-Tiering | Standard-IA | One Zone-IA | Glacier Instant | Glacier Flexible | Glacier Deep Archive | |
|---|---|---|---|---|---|---|---|
| Storage (per GB/tháng) | Cao nhất | Thấp – Cao (tự động tối ưu) | Trung bình | Thấp hơn Standard-IA | Thấp | Rất thấp | Thấp nhất |
| Retrieval | Miễn phí | Miễn phí | Theo GB | Theo GB | Theo GB (đắt hơn IA) | Theo GB + tốc độ (Expedited đắt nhất) | Theo GB + tốc độ (Standard/Bulk) |
| Retrieval time | Ngay lập tức | Ngay lập tức | Ngay lập tức | Ngay lập tức | Mili-giây | Phút → giờ | 12–48 giờ |
| Monitoring cost | Không | Có (nhỏ, theo 1000 object) | Không | Không | Không | Không | Không |
⚠️ The table below is illustrative (AWS pricing changes over time) — just to grasp the relative cost ordering across storage classes.
| Standard | Intelligent-Tiering | Standard-IA | One Zone-IA | Glacier Instant | Glacier Flexible | Glacier Deep Archive | |
|---|---|---|---|---|---|---|---|
| Storage (per GB/month) | Highest | Low – High (auto-optimized) | Medium | Lower than Standard-IA | Low | Very low | Lowest |
| Retrieval | Free | Free | Per GB | Per GB | Per GB (pricier than IA) | Per GB + speed (Expedited priciest) | Per GB + speed (Standard/Bulk) |
| Retrieval time | Instant | Instant | Instant | Instant | Milliseconds | Minutes → hours | 12–48 hours |
| Monitoring cost | None | Yes (small, per 1000 objects) | None | None | None | None | None |
17. S3 Express One Zone
- Storage class hiệu năng cao, single AZ
- Object lưu trong Directory Bucket (bucket nằm trong một AZ duy nhất)
- Xử lý hàng trăm nghìn request/giây với độ trễ mili-giây một chữ số
- Hiệu năng tới 10x tốt hơn S3 Standard (và giảm 50% chi phí)
- Độ bền cao (99.999999999%) và availability 99.95%
- Có thể đặt storage cùng AZ với compute để giảm latency
- Use cases: ứng dụng nhạy cảm độ trễ, ứng dụng nặng dữ liệu, huấn luyện AI/ML, mô hình tài chính, xử lý media, HPC…
- Tích hợp tốt nhất với: SageMaker Model Training, Athena, EMR, Glue…
- High performance, single Availability Zone storage class
- Objects stored in a Directory Bucket (bucket in a single AZ)
- Handles 100,000s requests per second with single-digit millisecond latency
- Up to 10x better performance than S3 Standard (50% lower costs)
- High Durability (99.999999999%) and Availability (99.95%)
- Can co-locate storage and compute in the same AZ (reduces latency)
- Use cases: latency-sensitive apps, data-intensive apps, AI & ML training, financial modeling, media processing, HPC…
- Best integrated with: SageMaker Model Training, Athena, EMR, Glue…