S3 bucket versioning needs review

S3 Versioning supports object recovery after overwrites and ordinary deletions.

Description

Without S3 Versioning, fewer recovery options are available after an object is overwritten or deleted. Versioning is useful for data that needs change history, although it does not replace a separate backup. Enabling it cannot restore content already lost beforehand.

Potential impact

  • Recovering an accidentally overwritten object may be difficult.
  • Deletion or automation errors can cause greater data loss and longer recovery.

Remediation

  • Set versioning: yes on buckets that need object history.
  • Limit permissions to delete old versions, and review lifecycle retention and separate backups.
  • Check storage costs and the recovery procedure. Once enabled, versioning can be suspended but the bucket cannot return to an unversioned state.

Examples

These excerpts compare versioning settings. Supply policy.json separately and adapt the bucket policy and Requester Pays setting to actual requirements.

Before

yaml
- name: S3 버킷 생성
  amazon.aws.s3_bucket:
    name: mys3bucket
    policy: "{{ lookup('file','policy.json') }}"
    requester_pays: yes
    versioning: no

New version retention is not enabled. On a previously versioned bucket, this suspends versioning without automatically deleting existing versions.

After

yaml
- name: S3 버킷 생성
  amazon.aws.s3_bucket:
    name: mys3bucket
    policy: "{{ lookup('file','policy.json') }}"
    requester_pays: yes
    versioning: yes

Versions are retained for subsequent changes. An ordinary deletion without a version ID creates a delete marker, but a principal with permission can permanently delete a specific version, so restrict that permission too.

References