S3 bucket versioning is not enabled

Keep S3 object versions so earlier content can be recovered after overwrites or deletions.

Description

Without S3 versioning, recovering an object’s previous state after an overwrite or deletion is harder. Operational mistakes, deployment errors, and malicious changes leave fewer recovery options.

VersioningConfiguration.Status: Enabled keeps versions for subsequent object changes. It cannot recover data already lost before activation. Suspending versioning leaves existing versions in place.

Potential impact

  • Earlier content may be unavailable after an object is overwritten or deleted.
  • Recovery from operational mistakes or automation errors can take longer.

Remediation

  • Set VersioningConfiguration with Status: Enabled on buckets that need recoverable history.
  • Configure lifecycle rules with retention needs and storage costs in mind, and restrict permissions to permanently delete versions.
  • Test version creation and restoration. Consider additional protection such as Object Lock when immutable retention is required.

Examples

These excerpts enable versioning on the same bucket. Replication configuration is not included.

Before

yaml
Resources:
  RecordServiceS3Bucket:
    Type: AWS::S3::Bucket

Versioning is not enabled on the new bucket. Previous content may not remain after an overwrite or deletion.

After

yaml
Resources:
  RecordServiceS3Bucket:
    Type: AWS::S3::Bucket
    Properties:
      VersioningConfiguration:
        Status: Enabled

Versions are kept for subsequent changes. Lifecycle expiration or permanent version deletion can still remove them, so versioning alone does not provide an immutable backup.

References