AWS Data Storage Flashcards
(103 cards)
Data Storage Services
S3 + Glacier
DynamoDB
ElastiCache
Amazon S3 Use cases
Backup and storage * Disaster Recovery * Archive * Hybrid Cloud storage * Application hosting * Media hosting * Data lakes & big data analytics * Software delivery * Static website
S3 Max. Object Size is
5 TB (5000GB)
Amazon S3 – Security
User-Based, Resource-Based, Encryption
S3 - Policy in User-Based
IAM Policies
S3 - Resource-Based
- Bucket Policies – bucket wide rules from the S3 console - allows cross
account - Object Access Control List (ACL) – finer grain (can be disabled)
- Bucket Access Control List (ACL) – less common (can be disabled)
S3 Storage Classes
- Amazon S3 Standard - General Purpose
- Amazon S3 Standard-Infrequent Access (IA)
- Amazon S3 One Zone-Infrequent Access
- Amazon S3 Glacier Instant Retrieval
- Amazon S3 Glacier Flexible Retrieval
- Amazon S3 Glacier Deep Archive
- Amazon S3 Intelligent Tiering
Describe S3 User-Based
- IAM Policies – which API calls should be allowed for a specific user from IAM
Describe S3 Resource-Based
- Bucket Policies – bucket wide rules from the S3 console - allows cross
account - Object Access Control List (ACL) – finer grain (can be disabled)
- Bucket Access Control List (ACL) – less common (can be disabled)
How to use objects in S3 type encryption
encrypt objects in Amazon S3 using encryption keys
S3 - JSON-based policies
- Resources: buckets and objects
- Effect: Allow / Deny
- Actions: Set of APIs to Allow or Deny
- Principal: The account or user to apply
the policy to
Use S3 bucket for policy to:
- Grant public access to the bucket
- Force objects to be encrypted at upload
- Grant access to another account (Cross
Account)
S3 - Replication CRR is:
Cross-Region Replication
Same-Region Replication is:
SRR
S3 use cases CRR
compliance, lower latency access, replication across accounts
S3 use cases SRR
log aggregation, live replication between production and test accounts
S3 Storage Classes – Infrequent Access
- For data that is less frequently accessed, but requires rapid access when needed
- Lower cost than S3 Standard
- para dados acessados com menos frequência mas requerem acesso rápido quando necessário, custo mais baixo do que classe Standard
Amazon S3 Standard-Infrequent Access (S3 Standard-IA) - availability and use cases
- 99.9% Availability
- Use cases: Disaster Recovery, backups
Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) - availabilty percent
99.5%
Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA) - Use cases:
Storing secondary backup copies of on-premises data, or data you can recreate
Amazon S3 Glacier Storage Classes:
- Amazon S3 Glacier Instant Retrieval
- Amazon S3 Glacier Flexible Retrieval
- Amazon S3 Glacier Deep Archive – for long term storage:
Resources Amazon S3 Glacier Instant Retrieval
- Millisecond retrieval, great for data accessed once a quarter
- Minimum storage duration of 90 days
Resources Amazon S3 Glacier Flexible Retrieval (formerly Amazon S3 Glacier):
- Expedited (1 to 5 minutes), Standard (3 to 5 hours), Bulk (5 to 12 hours) – free
- Minimum storage duration of 90 days
Resources Amazon S3 Glacier Deep Archive – for long term storage:
- Standard (12 hours), Bulk (48 hours)
- Minimum storage duration of 180 days