Description
Without S3 versioning, recovering an object’s previous state after an overwrite or deletion is harder. Operational mistakes, deployment errors, and malicious changes leave fewer recovery options.
VersioningConfiguration.Status: Enabled keeps versions for subsequent object changes. It cannot recover data already lost before activation. Suspending versioning leaves existing versions in place.
Potential impact
- Earlier content may be unavailable after an object is overwritten or deleted.
- Recovery from operational mistakes or automation errors can take longer.
Remediation
- Set
VersioningConfigurationwithStatus: Enabledon buckets that need recoverable history. - Configure lifecycle rules with retention needs and storage costs in mind, and restrict permissions to permanently delete versions.
- Test version creation and restoration. Consider additional protection such as Object Lock when immutable retention is required.
Examples
These excerpts enable versioning on the same bucket. Replication configuration is not included.
Before
Resources:
RecordServiceS3Bucket:
Type: AWS::S3::Bucket
Versioning is not enabled on the new bucket. Previous content may not remain after an overwrite or deletion.
After
Resources:
RecordServiceS3Bucket:
Type: AWS::S3::Bucket
Properties:
VersioningConfiguration:
Status: Enabled
Versions are kept for subsequent changes. Lifecycle expiration or permanent version deletion can still remove them, so versioning alone does not provide an immutable backup.