Object storage · Chapter 2 of 3
How S3 achieves extreme durability
Replicating data across multiple data centres guarantees that it will survive hardware failures, but protecting against user error requires understanding S3 versioning and lifecycle mechanics.
FoundationsBuilds the idea from nothing. No prior AWS assumed.
Protecting data from accidental deletion
What happens to an object when it is deleted in a versioned bucket?
The bucket contains an initial version of an object named photo.jpg, designated with version ID 111111.
- 01
The permanency of versioning
Once bucket versioning is enabled, it can never be disabled; it can only be suspended. When versioning is suspended, existing versions remain intact, but new writes overwrite the current version without creating new historic versions.
- 02
The role of a delete marker
When a user deletes an object in a versioned bucket, S3 does not erase the data. Instead, it writes a zero-byte placeholder called a delete marker as the new current version. A standard read request returns a `404 Not Found` error, but the historic versions are still retrievable.
- 03
Lifecycle rules clean the past
Because old versions are never deleted automatically, versioned buckets grow indefinitely. S3 Lifecycle rules are used to manage this cost by transitioning non-current versions to cheaper storage classes, or deleting them permanently after a set number of days.
Check yourself
You run a delete command on an object in a versioned bucket. How does S3 handle this request?
Under the hoodThe same thing from underneath: limits, failure modes, numbers.
Under the hood of eleven nines durability
What is the physical reality behind the S3 durability SLA?
The bucket contains an initial version of an object named photo.jpg, designated with version ID 111111.
- 01
Durability versus availability
S3 promises `99.999999999%` durability, meaning the probability of losing a single object is one in one hundred billion. This is achieved by replicating each object across at least three separate facilities within a Region. In contrast, the availability SLA is lower, allowing for occasional brief outages.
- 02
Handling large files
For files larger than 100 megabytes, AWS requires or strongly recommends using multipart uploads. This process splits the file into independent parts, uploads them concurrently, and reassembles them. If a single part fails to upload, only that part must be retried.
- 03
The mechanics of object sizes
An S3 bucket can store an unlimited number of objects, but an individual object cannot exceed 5 terabytes. To upload an object of this size, the caller must use the multipart upload API, as a single-operation PUT is limited to a smaller payload.
The numbers
- Designed durability
- 99.999999999%Eleven nines means losing one object out of 100 billion per year.
- Availability SLA (Standard)
- 99.9%Guarantees access availability, which is different from data durability.
- Maximum object size
- 50 TBCurrent maximum object size; increased in December 2025. A single PUT remains limited to 5 GB; large objects use multipart upload.
- Single PUT size limit
- 5 GBObjects larger than 5 GB must be uploaded via the multipart API.
- Multipart threshold
- 100 MBAWS recommends multipart uploads for any file larger than this threshold.
Check yourself
Which of the following is true regarding S3 bucket versioning once it has been enabled?
Official references & further reading
These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.
Report an error or suggest a clearer explanation →