All you need to know about encrypting AWS S3 buckets

  Рет қаралды 13,064

cloudonaut

cloudonaut

Күн бұрын

Dance like nobody's watching, encrypt like everyone is. Learn how to enable S3 default encryption. But that's not enough. A bucket policy ensures all uploaded objects comply with your encryption standard. On top of that, you will learn how to avoid insane costs by enabling bucket keys.
Interested in more? Check out the blog post: cloudonaut.io/all-you-need-to...
Support us:
Have you learned something new by reading, listening, or watching our content? If so, we kindly ask you to support us in producing high-quality & independent AWS content. We look forward to sharing our AWS knowledge with you. cloudonaut.io/support-us/
Chapters:
00:00 - Intro
00:45 - What to expect
01:40 - Demo: S3 Default Encryption
03:42 - S3 Encryption
06:41 - Demo: S3 Bucket Policy
11:55 - Costs for S3 Encryption
12:47 - Demo: S3 Bucket Keys
13:36 - Wrap Up
#aws #amazonwebservice #cloudcomputing #cloudonaut #s3bucket #s3 #encrypting

Пікірлер: 23
@andriys5772
@andriys5772 2 жыл бұрын
Thank you!
@malikshamim7034
@malikshamim7034 2 жыл бұрын
Thanks alot ,please create a video on these gateways like virtual private gateway ,transit gateway , border gateway ,customer gateway , interface endpoint ,gateway endpoint , vpc endpoints ,these concepts are really confusing
@cloudonaut
@cloudonaut 2 жыл бұрын
Thanks a lot for your feedback. Will add your content wishes into our backlog.
@oleksandrlytvyn532
@oleksandrlytvyn532 Жыл бұрын
Thanks
@cloudonaut
@cloudonaut Жыл бұрын
You are welcome!
@putinaspiliponis6428
@putinaspiliponis6428 2 жыл бұрын
What are security considerations for SSE-KMS bucket keys versus object keys? I kinda got the impression that in the case of "bucket key" the original requestor entity doesn't have to be granted specifically to use a specific KMS key.
@cloudonaut
@cloudonaut 2 жыл бұрын
bucket keys are much cheaper in terms of KMS API calls. The only change is that all objects are encrypted with the same key. Which makes sense anyways.
@sarulatha7374
@sarulatha7374 2 жыл бұрын
Hi Thanks a lot for this video. Could you please make a video how to encrypt and decrypt the files using AWS KMS
@cloudonaut
@cloudonaut 2 жыл бұрын
Good point, will add that to our TODO list. :)
@brunocardoso8277
@brunocardoso8277 2 жыл бұрын
Hi, thanks for the content. if I may ask a question, how can i write the policies for SSE-S3 encryptions? I tried some, but when I set nothing in the header its was rejecting all my requests from a Java Client. Thanks
@cloudonaut
@cloudonaut 2 жыл бұрын
I'd say, replacing s3:x-amz-server-side-encryption-aws-kms-key-id: !GetAtt 'Key.Arn' from our example with "s3:x-amz-server-side-encryption": "AES256" should do the trick.
@Niko-kf1gt
@Niko-kf1gt Жыл бұрын
I have couple of s3 buckets where the default encryption is turned on by default (SS3-S3) but for some reason some objects are showing as unencrypted. I wonder if we can encrypt after an object has been uploaded , if I go to the object and try to edit the server-side encryption it says I don't have permission.
@cloudonaut
@cloudonaut Жыл бұрын
The default encryption does only apply when creating or updating/replacing an object. The setting does not affect objects, that have been created before.
@raze5
@raze5 2 жыл бұрын
What you think would be reasons to NOT to enable bucket key? But choosing more expensive key instead?
@cloudonaut
@cloudonaut 2 жыл бұрын
I don't see a good reason. All other services use similar optimizations to reduce kms requests.
@thatguynick7992
@thatguynick7992 10 ай бұрын
Is there an updated version of this content. Currently there isn’t an option to enable and disable encryption. SSE-S3 is default
@cloudonaut
@cloudonaut 10 ай бұрын
Correct, S3 buckets are encrypted by default those days. Up until know, we haven't recorded an updated video yet.
@RahulAhire
@RahulAhire 2 жыл бұрын
How can I verify that the objects are actually encrypted.
@cloudonaut
@cloudonaut 2 жыл бұрын
What do you mean by "verify that the objects are actually encrypted"? As the de/encryption happens on-the-fly you have to trust AWS and their security/quality certifications, that the encryption is working. All you can do is the check the details of an object to check which encryption was applied.
@RahulAhire
@RahulAhire 2 жыл бұрын
@@cloudonaut whenever I access the encrypted files in console or preview it, I get it in its original form. Let's says there's a hack (or there's a raid by police) that my system faced and by mistakenly I allow read access. How can I see if the encryption is working. When I encryption a text file locally it automatically turns into something random.
@salathielojage6805
@salathielojage6805 Жыл бұрын
Sir, your face is obscuring some of your code!
@cloudonaut
@cloudonaut Жыл бұрын
Thanks for your feedback!
@Northstar2000
@Northstar2000 16 күн бұрын
Security by obfuscation
How I use AWS Security Hub
27:12
cloudonaut
Рет қаралды 17 М.
I'm Excited To see If Kelly Can Meet This Challenge!
00:16
Mini Katana
Рет қаралды 31 МЛН
Smart Sigma Kid #funny #sigma #comedy
00:40
CRAZY GREAPA
Рет қаралды 34 МЛН
World’s Largest Jello Pool
01:00
Mark Rober
Рет қаралды 114 МЛН
AWS S3 Encryption |  Server Side Encryption(SSE) and Client Side Encryption(CSE) [S3 p3]
11:36
The Most Important AWS Core Services That You NEED To Know About!
18:09
Be A Better Dev
Рет қаралды 410 М.
Amazon Web Service - Replace IAM Users with AWS SSO
18:06
cloudonaut
Рет қаралды 27 М.
A Deep Dive into AWS CloudTrail
26:04
cloudonaut
Рет қаралды 8 М.
AWS S3 Bucket Policy vs IAM - What's the Difference?
12:11
Be A Better Dev
Рет қаралды 30 М.
AWS Client VPN: Connected with the Cloud
19:23
cloudonaut
Рет қаралды 10 М.
Kerberos Authentication Explained | A deep dive
16:52
Destination Certification
Рет қаралды 336 М.
Amazon S3 Access Control - IAM Policies, Bucket Policies and ACLs
19:44
Digital Cloud Training
Рет қаралды 80 М.
Как бесплатно замутить iphone 15 pro max
0:59
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 8 МЛН
КРАХ WINDOWS 19 ИЮЛЯ 2024 | ОБЪЯСНЯЕМ
10:04
تجربة أغرب توصيلة شحن ضد القطع تماما
0:56
صدام العزي
Рет қаралды 64 МЛН
Klavye İle Trafik Işığını Yönetmek #shorts
0:18
Osman Kabadayı
Рет қаралды 9 МЛН
Опасность фирменной зарядки Apple
0:57
SuperCrastan
Рет қаралды 12 МЛН