Lesson 110 · AWS Learning Path

AWS 110: S3 storage classes

· Published · 14 min read

An EC2 instance connects to persistent EBS volumes on one side and fast temporary host-local instance-store disks on the other

The real problem

A team recognizes the name S3 storage classes but has not connected the feature to a real requirement, identity boundary, network or data path, failure mode, price dimension, and cleanup owner. A plausible configuration could still fail the workload.

Final outcome

The learner will produce a requirement-led artifact for S3 storage classes, inspect the matching AWS control plane in the Management Console, run a matching CloudShell or AWS CLI query, interpret the output, diagnose one failure, defend one architecture choice, and prove cleanup or approved retained state.

The practical outcome is not a command transcript. It must show what was expected, what happened, what the result proves, what it does not prove, and which evidence would change the decision.

Learning objectives

By the end of this lesson, the learner can:

  • explain s3 standard;
  • explain intelligent-tiering;
  • explain infrequent access;
  • explain archive classes;
  • explain s3 express one zone;
  • connect control-plane state to the real data, network, identity, or application behavior;
  • identify cost and cleanup ownership before any optional mutation;
  • troubleshoot from evidence without opening broad access or adding broad permissions.

Relationship model

Requirement
   |
   v
Identity and policy -> AWS configuration -> network or data path -> workload behavior
        |                    |                      |                    |
        +--------------------+----------------------+--------------------+
                                      |
                                      v
                         monitoring, cost, recovery, cleanup

Use this model to separate an AWS object that exists from a result that actually works. Every arrow is a verification boundary.

Prerequisites, permissions, Region, and safety

  • Learning baseline: This sequence assumes practical Linux knowledge but no prior cloud-computing or AWS knowledge. Cloud, networking, security, data, automation, and architecture concepts must come from completed earlier lessons. If a prerequisite checkpoint is incomplete, return to its linked lesson before continuing.
  • Confirm a non-root caller with aws sts get-caller-identity and keep the account number private.
  • Use ap-south-1 unless this lesson explicitly names a second Region.
  • Confirm the intended profile and Region with aws configure list before interpreting an empty result.
  • Use read-only List, Get, and Describe permissions for the named services. Design exercises run locally and require no resource-creation permission.
  • This is a no-create lesson. Console and CLI work is read-only, and every design artifact is created locally.
  • Never publish account IDs, public addresses, ARNs containing private account data, session IDs, presigned URLs, object data, credentials, or KMS material.
  • Do not use root, world-open SSH or RDP, disabled TLS verification, unowned resources, or irreversible retention controls in a training exercise.

Core model

ConceptWhat the learner must understand
S3 StandardS3 Standard is the general-purpose multi-AZ class for frequently accessed data with low-latency access and no retrieval fee.
Intelligent-TieringS3 Intelligent-Tiering monitors access and moves eligible objects among access tiers. Monitoring and automation charges, archive-tier options, object size, and retrieval behavior must be included in the decision.
Infrequent accessS3 Standard-IA is multi-AZ and S3 One Zone-IA stores data in one AZ. Both are designed for infrequent access and include retrieval and minimum-duration or minimum-size cost considerations.
Archive classesS3 Glacier Instant Retrieval offers millisecond retrieval. Flexible Retrieval and Deep Archive require restore workflows and have different retrieval times and minimum storage durations.
S3 Express One ZoneS3 Express One Zone uses directory buckets for single-AZ, very low-latency access and has a different feature and request model from general purpose buckets.
Lifecycle is not instant cost eliminationTransitions and expirations are asynchronous and subject to eligibility, minimum-size defaults, minimum-duration charges, request charges, and versioning behavior.

How it works

Select a class from access frequency, latency, AZ resilience, object size, retention duration, retrieval volume, restore workflow, request rate, predictability, and deletion timing. Storage price alone is an incomplete comparison.

Read the result in layers:

  1. Scope: account, Region, VPC, bucket, AZ, endpoint, principal, object version, or resource ARN.
  2. Control plane: the requested configuration exists and reached an expected state.
  3. Behavior: the request, connection, health check, replication, restore, or application result meets the requirement.
  4. Operations: monitoring, failure owner, cost, retention, rollback, and cleanup are known.

Control-plane success is necessary but not sufficient. A resource can be available while policy, routing, DNS, health, data, or application behavior remains wrong.

Architecture decision table

RequirementPreferred directionWhy
Unknown or changing access patternsIntelligent-TieringAutomatic tiering can reduce manual prediction when monitoring economics fit.
Re-creatable single-AZ secondary copyOne Zone-IA may fitThe workload explicitly accepts loss of one AZ and retrieval charges.
Archive needs immediate millisecond accessGlacier Instant RetrievalIt is an archive-priced class without a restore wait.
Long-term archive with rare planned recoveryGlacier Deep ArchiveLowest storage direction trades for long restore times and duration commitments.

Professional questions normally contain several valid services. State the requirement that selects one option, why the nearest alternative fails it, and what changed requirement would reverse the choice.

Complete storage-class comparison

Prices vary by Region and date, so this table teaches behavior rather than embedding a price. Confirm current rates and exact feature support before a production decision.

Storage class/tierResilience and accessEconomic/operational boundaryTypical fit
S3 StandardGeneral purpose, multi-AZ, millisecond accessHighest normal storage direction; no minimum storage-duration charge and no retrieval feeFrequently or unpredictably read active objects, websites/origins, data processing
S3 Intelligent-Tiering Frequent AccessMulti-AZ, millisecond accessStarting/default tier; eligible objects are monitored for access and automatically movedLong-lived data with unknown or changing access
Intelligent-Tiering Infrequent AccessMulti-AZ, millisecond accessAutomatic after the current no-access period; no retrieval charge, but eligible objects incur monitoring/automation chargeObjects that cool without predictable dates
Intelligent-Tiering Archive Instant AccessMulti-AZ, millisecond accessAutomatic deeper instant tier after the documented no-access periodRarely read data that still needs immediate access
Intelligent-Tiering Archive AccessMulti-AZ archive, asynchronous accessOptional tier; object must be restored/promoted before normal accessVery rare data where minutes-to-hours retrieval is acceptable
Intelligent-Tiering Deep Archive AccessMulti-AZ deep archive, asynchronous accessOptional deepest tier and longest retrieval directionVery rare long-lived data with hours-level recovery
S3 Standard-IAMulti-AZ, millisecond accessRetrieval charge, 30-day minimum-duration charge, and 128-KB minimum billable object sizePredictably infrequent but immediately needed primary/secondary data
S3 One Zone-IASingle AZ, millisecond accessLower storage direction, retrieval charge, 30-day minimum, 128-KB minimum; data can be lost with AZ destructionRe-creatable secondary copies or data with an accepted single-AZ risk
S3 Glacier Instant RetrievalMulti-AZ archive, millisecond accessRetrieval charge, 90-day minimum, 128-KB minimumArchive accessed about quarterly where immediate retrieval is mandatory
S3 Glacier Flexible RetrievalMulti-AZ archive, asynchronous restore90-day minimum; retrieval tier/time and archive per-object overhead matterArchives where minutes-to-hours retrieval and a restore workflow fit
S3 Glacier Deep ArchiveMulti-AZ deep archive, asynchronous restore180-day minimum; longest restore direction and archive per-object overheadCompliance and long-term preservation with rare planned recovery
S3 Express One ZoneSingle-AZ class in a directory bucket, single-digit-millisecond designDifferent bucket/API/request and pricing model; not a lifecycle destination for normal general purpose objectsLatency-sensitive, request-intensive workloads with explicit zonal design

Intelligent-Tiering archive tier names are easy to confuse with the standalone Glacier storage classes. Moving automatically inside Intelligent-Tiering is tiering within that storage class; transitioning an object to GLACIER_IR, GLACIER, or DEEP_ARCHIVE changes its storage class. Inspect StorageClass, tiering/archive status, and restore status rather than inferring from age.

How Intelligent-Tiering actually decides

An object starts in Frequent Access. S3 monitors access and can move eligible objects to lower tiers after defined periods without access; current AWS documentation controls the exact day thresholds and optional archive configuration. Objects smaller than 128 KB remain in Frequent Access and are not monitored for automatic tiering, so millions of tiny objects do not receive the expected tier movements. There is no minimum billable object size for Intelligent-Tiering itself, but object count, requests, and the per-object monitoring charge can dominate.

The class is attractive when future access is uncertain, but it does not remove design work:

  • Define whether archive tiers are enabled and whether their asynchronous retrieval meets RTO.
  • Understand which access operations promote an object and which metadata/list operations do not.
  • Model monitoring charges versus possible savings, especially for many small objects.
  • Keep lifecycle for final expiration, noncurrent-version handling, incomplete multipart cleanup, or deliberate transitions where required.
  • Monitor actual tiers and storage bytes; “Intelligent” does not mean cost is automatically globally optimal.

Lifecycle transition rules and hidden constraints

For lifecycle configurations created or modified under the current default behavior, objects smaller than 128 KB do not transition to any storage class unless the configuration deliberately changes the size behavior with supported filters/header behavior. Older configurations created before the September 2024 change can retain previous defaults until edited. This is a migration trap: two visually similar buckets can treat small objects differently because of configuration history.

Lifecycle transitions and expiration are asynchronous. Eligibility date and physical movement date can differ. Billing generally changes according to documented eligibility behavior, so a delayed console display is not proof that the old class rate still applies.

Minimum duration is a billing commitment, not a technical lock. You can often delete or overwrite earlier, but pay a prorated charge for the unused minimum period. Normal minimum-duration directions are:

  • 30 days: Standard-IA and One Zone-IA;
  • 90 days: Glacier Instant Retrieval and Glacier Flexible Retrieval;
  • 180 days: Glacier Deep Archive.

Do not create a transition chain whose timing contradicts class constraints. Do not archive each tiny log line individually when aggregation into immutable larger objects can reduce per-object overhead and request cost.

Archive restore mental model

Glacier Instant Retrieval is directly readable with millisecond access. Glacier Flexible Retrieval and Deep Archive require an asynchronous restore request before normal GET access.

archived object version
      |
      | RestoreObject(days, retrieval tier)
      v
restore in progress ----> temporary accessible restored copy
      |                         |
      | status/metrics          | expires after requested days
      v                         v
original object remains in the same archive storage class

A restore does not permanently change the archive object's storage class. To keep a permanent active copy, copy the restored object into an appropriate class/key and then manage both versions deliberately. Restore the exact version ID required, select an available retrieval tier whose time/cost meets the incident RTO, poll with a bound, and test application permissions after restoration. KMS, Object Lock, versioning, and policy controls still apply.

Worked decisions and calculations

Example 1: 10 million 20-KiB thumbnails

The raw data is about 190.7 GiB, but every thumbnail is below 128 KB. Standard-IA and Glacier Instant Retrieval apply a 128-KB minimum billable size; Intelligent-Tiering keeps sub-128-KB objects in Frequent Access without auto-tiering. Lifecycle transition requests also occur per object. The lowest advertised per-GB rate can therefore be the wrong answer. Consider keeping active thumbnails in Standard, packaging true archive data into larger immutable objects when retrieval semantics permit, and model requests separately.

Example 2: 5-TiB monthly backup retained 400 days

Access is extremely rare and recovery may take hours. Deep Archive may fit after comparing transition request, 180-day commitment, retrieval tier, restore request, temporary restored-copy storage, data transfer, and the organization's tested RTO. If the backup may be deleted after 60 days, Deep Archive's low storage rate does not erase the early-deletion charge.

Example 3: machine-learning feature data with unpredictable rereads

The objects are large, long-lived, and access changes by experiment. Intelligent-Tiering may fit because prediction is poor and millisecond access tiers are useful. If a training job cannot wait for archive restore, do not enable optional asynchronous archive tiers or set their timing beyond the active research period. Measure KMS and request behavior too.

Example 4: transcoding scratch output

The data is re-creatable, belongs to one AZ's compute workflow, and is deleted within hours. One Zone-IA's 30-day minimum makes it a poor “cheap temporary” selection. Standard or S3 Express One Zone may be evaluated according to API/latency and cost, while ephemeral block/local storage may fit intermediate data even better. The word “temporary” is a retention requirement, not a storage-class name.

Required failure tests

  1. Request a normal GET for a Flexible Retrieval or Deep Archive object that has not been restored; identify the archive-state error and do not broaden IAM.
  2. Model an object deleted before its minimum duration and show the remaining-duration charge term.
  3. Apply a lifecycle rule to a below-128-KB object in a supplied timeline and correctly predict whether the current default transitions it.
  4. Distinguish an access denial from an archive-not-restored failure using API code, version ID, storage class, restore header/status, caller, and KMS evidence.

AWS Management Console guided practice

Before opening a service page, write the expected account, Region, starting state, and evidence. Do not choose Create, Save, Purchase, Lock, or Delete unless the lesson explicitly authorizes the live track.

  1. Open S3 Storage Lens or an instructor-supplied inventory and group objects by storage class, object size, age, current/noncurrent status, and access requirement.
  2. Open current S3 pricing for ap-south-1 and record storage, retrieval, request, monitoring, minimum-duration, and data-transfer dimensions for the supplied scenario.
  3. Use the class decision table to reject at least two lower-storage-price options that fail the latency, AZ, or retention requirement.

For each step, capture the field name and value in text. A screenshot may support the record but does not replace the explanation. Console labels can evolve, so use the service search and current documentation if a navigation label differs.

CloudShell and AWS CLI practice

CloudShell is the default browser-based command environment taught in AWS 028. AWS 029 and AWS 030 cover local CLI installation and authentication. This lesson therefore does not assume that an unconfigured local shell is ready.

Start every session with:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account portion of the ARN before sharing. Then perform the topic query:

Inventory storage-class distribution for a supplied prefix and attach current pricing dimensions without moving data.

NW_BUCKET="replace-with-owned-bucket-name"
aws s3api list-objects-v2 --bucket "$NW_BUCKET" --prefix documents/ --query 'Contents[].{Key:Key,Bytes:Size,Class:StorageClass,Modified:LastModified}' --output table

Expected interpretation:

Objects that omit StorageClass in some API views normally use S3 Standard. This listing does not show noncurrent versions, archive restore state, minimum-duration exposure, or full request cost.

Replace every replace-with-... sample value before running its command, and use only an explicitly owned resource. Explain each option first. These queries are read-only; a successful response does not authorize a later create or delete operation.

Practical work

Create p06-storage-class-plan.md. Map active documents, 30-day noncurrent versions, 90-day archives, legal evidence, temporary restores, and re-creatable analytics data to candidate classes. Calculate one 12-month scenario using current ap-south-1 prices and state every request, retrieval, size, duration, and transfer assumption. No class is changed.

The evidence package must contain:

  • the problem and final requirement in the learner's own words;
  • caller type and Region with private identifiers redacted;
  • exact planned values, ownership, and cost class;
  • one Console observation and matching CLI or API evidence;
  • one behavior result or supplied data-plane record;
  • one denied, failed, or counterexample result and evidence-led diagnosis;
  • one architecture choice plus the rejected alternative;
  • cleanup proof or explicit retained-state owner, expiry, and next lesson.

Verification standard

Use expected state before observed state. Record timestamps in UTC and preserve the original failure before changing anything. A passing submission answers all four questions:

  1. What exact requirement was tested?
  2. Which evidence proves the AWS configuration?
  3. Which evidence proves the workload behavior?
  4. What remains unproven or requires later monitoring?

If AWS returns no rows, verify account, Region, permission, filters, pagination, resource type, and deletion state before concluding that nothing exists.

Common failures and troubleshooting

SymptomEvidence firstLikely boundarySmallest safe response
object appears missingcaller, Region, filters, pagination, tagsscope or read permissionalign scope before creating a duplicate
state remains pending or unavailableservice state, events, dependencies, quotasdependency or capacitycorrect the named dependency and wait with a bound
AccessDeniedprincipal, action, resource, explicit-deny contextidentity, resource, endpoint, organization, or KMS policychange only the proven policy layer
configuration exists but behavior failsroute, DNS, security, listener, health, logs, object versiondata path or applicationtest the next boundary and change one control
bill is higher than expectedhours, bytes, requests, AZs, addresses, retentioncost model or retained resourcestop optional work and reconcile the ledger
cleanup is blockeddependency inventory and owning servicedeletion order or immutable stateremove owned dependants in reviewed reverse order

Do not troubleshoot by attaching administrator access, opening administration ports to the internet, disabling encryption, retrying uncontrolled creation, deleting unknown resources, or weakening retention.

Cost, cleanup, and retained state

No AWS resource is created. Close CloudShell and remove or redact downloaded evidence.

Cleanup evidence requires terminal state and an after-inventory. Search related ENIs, public IPv4 addresses, EBS volumes and snapshots, load balancers, target groups, Auto Scaling instances, endpoints, logs, S3 versions and delete markers, backup recovery points, and global IAM roles when they apply. Billing data can lag, so schedule a later review.

Architecture and certification decisions

  • Certification coverage: SAA-C03; SOA-C03; SAP-C02; DOP-C02.
  • Exam mapping: SAA D1-D4.
  • Explain service scope, failure boundary, consistency, recovery, security, operations, and price rather than matching a keyword.
  • Treat availability and durability, encryption and authorization, routing and filtering, health and lifecycle, backup and replication, and discount and capacity as separate concepts.
  • Do not reproduce protected certification questions.

Knowledge check

  1. Which archive class provides millisecond access?

Expected direction: S3 Glacier Instant Retrieval.

  1. Which IA class stores data in one AZ?

Expected direction: S3 One Zone-IA.

  1. Does lifecycle transition happen exactly at the configured second?

Expected direction: No. Eligibility and processing are asynchronous.

  1. Why can a cheaper per-GB class cost more?

Expected direction: Retrieval, requests, monitoring, minimum duration, object size, and transfer can dominate.

Completion gate and assessment

AreaPointsPassing evidence
Requirement and model15Correct scope, terminology, and final outcome
Console evidence15Current path and interpreted fields
CLI or API evidence15Scoped command, expected result, and limitations
Behavior or decision exercise20Reproducible result or defensible architecture reasoning
Troubleshooting15Original symptom, hypothesis, one change, retest, rollback
Security and cost10Least privilege, data protection, current price dimensions
Cleanup and handoff10Terminal-state proof or approved retained-state record

Pass at 80 out of 100 with no critical safety failure. A missing practical artifact, unexplained output, unsafe access, destructive action outside the owned scope, unplanned billed resource, or false cleanup claim requires remediation and a changed retest.

Official sources

Advertisement