Description
Without S3 Versioning, fewer recovery options are available after an object is overwritten or deleted. Versioning is useful for data that needs change history, although it does not replace a separate backup. Enabling it cannot restore content already lost beforehand.
Potential impact
- Recovering an accidentally overwritten object may be difficult.
- Deletion or automation errors can cause greater data loss and longer recovery.
Remediation
- Set
versioning: yeson buckets that need object history. - Limit permissions to delete old versions, and review lifecycle retention and separate backups.
- Check storage costs and the recovery procedure. Once enabled, versioning can be suspended but the bucket cannot return to an unversioned state.
Examples
These excerpts compare versioning settings. Supply policy.json separately and adapt the bucket policy and Requester Pays setting to actual requirements.
Before
- name: S3 버킷 생성
amazon.aws.s3_bucket:
name: mys3bucket
policy: "{{ lookup('file','policy.json') }}"
requester_pays: yes
versioning: no
New version retention is not enabled. On a previously versioned bucket, this suspends versioning without automatically deleting existing versions.
After
- name: S3 버킷 생성
amazon.aws.s3_bucket:
name: mys3bucket
policy: "{{ lookup('file','policy.json') }}"
requester_pays: yes
versioning: yes
Versions are retained for subsequent changes. An ordinary deletion without a version ID creates a delete marker, but a principal with permission can permanently delete a specific version, so restrict that permission too.