SimAWSby ShahriarLabs
Search

Object storage · Chapter 2 of 3

How S3 achieves extreme durability

Replicating data across multiple data centres guarantees that it will survive hardware failures, but protecting against user error requires understanding S3 versioning and lifecycle mechanics.

14 min2 sectionsBack to Object storage

FoundationsBuilds the idea from nothing. No prior AWS assumed.

Protecting data from accidental deletion

What happens to an object when it is deleted in a versioned bucket?

App ClientS3 APIVersioning Onphoto.jpg (v1)ID: 111111photo.jpg (v2)ID: 222222Delete MarkerID: 333333S3 versioning retains old object versions upon overwrite and creates delete markers rather than deleting physical bytes when a delete request is received.

The bucket contains an initial version of an object named photo.jpg, designated with version ID 111111.

1/6
  1. 01

    The permanency of versioning

    Once bucket versioning is enabled, it can never be disabled; it can only be suspended. When versioning is suspended, existing versions remain intact, but new writes overwrite the current version without creating new historic versions.

  2. 02

    The role of a delete marker

    When a user deletes an object in a versioned bucket, S3 does not erase the data. Instead, it writes a zero-byte placeholder called a delete marker as the new current version. A standard read request returns a `404 Not Found` error, but the historic versions are still retrievable.

  3. 03

    Lifecycle rules clean the past

    Because old versions are never deleted automatically, versioned buckets grow indefinitely. S3 Lifecycle rules are used to manage this cost by transitioning non-current versions to cheaper storage classes, or deleting them permanently after a set number of days.

Check yourself

You run a delete command on an object in a versioned bucket. How does S3 handle this request?

Under the hoodThe same thing from underneath: limits, failure modes, numbers.

Under the hood of eleven nines durability

What is the physical reality behind the S3 durability SLA?

App ClientS3 APIVersioning Onphoto.jpg (v1)ID: 111111photo.jpg (v2)ID: 222222Delete MarkerID: 333333S3 versioning retains old object versions upon overwrite and creates delete markers rather than deleting physical bytes when a delete request is received.

The bucket contains an initial version of an object named photo.jpg, designated with version ID 111111.

1/6
  1. 01

    Durability versus availability

    S3 promises `99.999999999%` durability, meaning the probability of losing a single object is one in one hundred billion. This is achieved by replicating each object across at least three separate facilities within a Region. In contrast, the availability SLA is lower, allowing for occasional brief outages.

  2. 02

    Handling large files

    For files larger than 100 megabytes, AWS requires or strongly recommends using multipart uploads. This process splits the file into independent parts, uploads them concurrently, and reassembles them. If a single part fails to upload, only that part must be retried.

  3. 03

    The mechanics of object sizes

    An S3 bucket can store an unlimited number of objects, but an individual object cannot exceed 5 terabytes. To upload an object of this size, the caller must use the multipart upload API, as a single-operation PUT is limited to a smaller payload.

The numbers

Designed durability
99.999999999%Eleven nines means losing one object out of 100 billion per year.
Availability SLA (Standard)
99.9%Guarantees access availability, which is different from data durability.
Maximum object size
50 TBCurrent maximum object size; increased in December 2025. A single PUT remains limited to 5 GB; large objects use multipart upload.
Single PUT size limit
5 GBObjects larger than 5 GB must be uploaded via the multipart API.
Multipart threshold
100 MBAWS recommends multipart uploads for any file larger than this threshold.

Check yourself

Which of the following is true regarding S3 bucket versioning once it has been enabled?

Official references & further reading

These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.

Report an error or suggest a clearer explanation →