30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification
Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.4.2. Amazon S3 for Object Storage (Developer Interaction)

First Principle: Amazon S3 provides highly durable, scalable object storage for developers, enabling applications to efficiently store and retrieve vast amounts of unstructured data via simple API interactions.

S3 stores any amount of data as objects (files) in buckets, with 99.999999999% (11 nines) durability. For developers, S3 is the default answer for storing files, static assets, backups, and data lake content. For developers, S3 is an ideal choice for storing unstructured data like images, videos, documents, backups, and log files.

  • Buckets: Data is stored in "buckets," which are containers for objects. Developers create and manage these buckets.
  • Objects: Files (objects) are stored with a unique key within a bucket. Each object consists of data, metadata, and a key.
  • API Interactions: Developers interact with S3 using RESTful APIs via AWS SDKs (e.g., PutObject to upload, GetObject to download).
  • Serialization: application objects are serialized before PutObject and deserialized after GetObject. JSON is the language-neutral default for nested data (lists, maps); CSV can't represent nesting cleanly, XML is heavier, and Python pickle is Python-only and unsafe to load from untrusted sources.
  • Pre-signed URLs: (Allow temporary access to objects without requiring AWS credentials.) Developers can generate pre-signed URLs to allow users to upload or download objects directly to/from S3 for a limited time. Each URL is signed for one operation: in boto3, generate_presigned_url('get_object', Params={'Bucket': b, 'Key': k}, ExpiresIn=3600) for a download or 'put_object' for an upload. It carries only the signer's permissions.
  • S3 Event Notifications: (Configure notifications when certain events occur in a bucket.) Developers can trigger AWS Lambda functions or other services in response to S3 events (e.g., image resizing when a new image is uploaded).
  • Security: Control access using Bucket Policies and IAM Policies. To encrypt an upload with SSE-KMS, pass ServerSideEncryption='aws:kms' to PutObject, plus SSEKMSKeyId to choose a specific customer managed key; 'AES256' selects SSE-S3 instead (see 3.1.3).
  • Storage Classes: Standard (frequent access, no minimum duration or retrieval fee) → Standard-IA (infrequent, millisecond access, multi-AZ) → One Zone-IA (cheaper but a single AZ, so only for easily reproducible data) → Glacier Instant Retrieval (archive, milliseconds) → Glacier Flexible Retrieval (minutes to hours) → Glacier Deep Archive (cheapest; standard retrieval within 12 hours, bulk within 48). IA classes bill a 30-day minimum and Glacier classes 90–180 days, so short-lived objects are cheapest in Standard.
  • Lifecycle Rules: Transition actions move objects to cheaper classes as they age (for example, Standard-IA at 90 days and Deep Archive at 365). Expiration actions delete them, with no scanning code needed.
  • Versioning: Keeps every version of an object, so an overwrite or delete can be undone by restoring a previous version (a delete just adds a delete marker).
  • Multipart Upload: Required above 5 GB and recommended above about 100 MB. CreateMultipartUpload (returns an UploadId) → UploadPart for each part → CompleteMultipartUpload. AbortMultipartUpload only cleans up an upload you abandon.

Scenario: You're developing a photo-sharing application where users can upload images. These images need to be stored securely and scalably, and you want to trigger an automated process (e.g., resizing) as soon as an image is uploaded.

⚠️ Exam Trap: S3 is strongly consistent for all operations as of December 2020. Read-after-write is immediate. If a question presents "eventual consistency" as an S3 answer, it's a distractor — that behavior was eliminated.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications