Simple Storage Service (S3)
Stores files and objects, such as images, PDFs, exports, and other binary data. CloudFront uses an S3 bucket to serve front-end applications, and the Byks module creates that bucket for you. You provision buckets for any other file storage yourself with a BYM module.
Byks guides
-
S3-triggered Lambda Function
A Lambda function that is triggered when new files arrive in an S3 bucket.
-
Secure Access to S3 Buckets
Serve content from a private S3 bucket through CloudFront
GitHub actions
Terraform configuration
The only S3 bucket terraform-byks-module creates automatically is the static-site origin behind a CloudFront distribution.
Configure that bucket through the cloudfront_distributions block. See CloudFront Terraform configuration for the full options table, including the S3-specific fields default_s3_origin_type, override_s3_bucket_name, force_destroy_s3, and additional_s3_origins.
For any other bucket, provision it directly with the terraform-aws-s3-bucket module, outside the module "application" block. Each instance of the module creates one bucket.
module "example" {
source = "git@github.com:BYM-IKT/terraform-aws-s3-bucket.git?ref=v4"
name = "team-example-bucket-name"
# options go here
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
name |
string |
required | Name of the bucket. Must be globally unique, lowercase, between 3 and 63 characters, and follow S3's bucket naming rules. |
force_destroy |
bool |
false |
Empty and delete the bucket without warning when it's deleted. |
versioning_enabled |
bool |
true |
Keep previous versions of objects when they're overwritten or deleted. |
expire_old_versions_days |
number |
14 |
Days before expiring old (deleted) object versions. Set to 0 to disable. |
expire_failed_multipart_upload_days |
number |
3 |
Days before expiring failed multipart uploads. Set to 0 to disable. |
create_cloudfront_oai |
bool |
false |
Create a CloudFront Origin Access Identity with read access to the bucket, and restrict the bucket policy to it. |
encryption |
bool |
true |
Encrypt the bucket with AES256 using an S3-managed key. See use_kms_encryption to use a KMS key instead. |
use_kms_encryption |
bool |
false |
Encrypt the bucket with a dedicated KMS key instead of the default AES256 encryption. Adds KMS permissions to the read and write policy outputs. |
disable_public_access |
bool |
true |
Block all public access to the bucket. Set to false only when the bucket needs public permissions. |
object_ownership_rule |
string |
"BucketOwnerEnforced" |
Either BucketOwnerEnforced, ObjectWriter, or BucketOwnerPreferred. With BucketOwnerEnforced, the bucket owner controls all object permissions and ACL grants no longer apply. |
additional_tags |
map(string) |
{} |
Extra tags applied to the bucket. |
extra_lifecycle_configuration_rules |
list(object) |
[] |
Extra lifecycle rules, beyond the built-in version and multipart-upload cleanup. See Lifecycle rule object. |
backup_settings |
any |
{} |
AWS Backup schedule and retention settings for the bucket. See Backup settings object. |
cors_rules |
map(object) |
{} |
Cross-origin resource sharing rules for the bucket. The map key becomes the rule's ID. See CORS rule object. |
Lifecycle rule object
Used in extra_lifecycle_configuration_rules.
| Option | Type | Default | Description |
|---|---|---|---|
id |
string |
required | Unique identifier for the rule. |
enabled |
bool |
required | Turn the rule on or off. |
abort_incomplete_multipart_upload_days |
number |
null |
Days after which an incomplete multipart upload for objects matching the rule is aborted. |
filter_and |
any |
null |
Scope the rule to objects matching a prefix, tags, or object size, instead of the whole bucket. |
expiration |
any |
null |
Expire objects matching the rule, by date, age in days, or delete-marker cleanup. |
transition |
list(any) |
null |
Move objects matching the rule to another storage class after a date or number of days. |
noncurrent_version_expiration |
any |
null |
Expire noncurrent versions of objects matching the rule. |
noncurrent_version_transition |
list(any) |
null |
Move noncurrent versions of objects matching the rule to another storage class. |
Backup settings object
Used in backup_settings.
| Option | Type | Default | Description |
|---|---|---|---|
hourly |
bool |
false |
Take hourly backups. |
hourly_retention_days |
number |
7 |
Days to keep hourly backups. Must be 2 or 7. |
twelve_hours |
bool |
false |
Take backups every twelve hours. |
twelve_hours_retention_days |
number |
14 |
Days to keep twelve-hour backups. Must be 14. |
daily |
bool |
false |
Take daily backups. |
daily_retention_days |
number |
14 |
Days to keep daily backups. Must be 5, 10, 14, or 35. |
biweekly |
bool |
false |
Take backups every two weeks. |
biweekly_retention_days |
number |
185 |
Days to keep biweekly backups. Must be 185. |
monthly |
bool |
false |
Take monthly backups. |
monthly_retention_days |
number |
370 |
Days to keep monthly backups. Must be 95, 185, 370, or 1850. |
monthly_annually |
bool |
false |
Take an extra yearly backup alongside the monthly one. |
monthly_retention_years |
number |
5 |
Years to keep the yearly backup. Must be 5. |
biannual |
bool |
false |
Take backups every six months. |
biannual_retention_days |
number |
370 |
Days to keep biannual backups. Must be 370. |
daily_no_copy |
bool |
false |
Take daily backups on the no-copy plan, instead of daily. |
daily_no_copy_retention_days |
number |
14 |
Days to keep no-copy daily backups. Must be 1, 14, or 35. |
biweekly_no_copy |
bool |
false |
Take biweekly backups on the no-copy plan, instead of biweekly. |
biweekly_no_copy_retention_days |
number |
35 |
Days to keep no-copy biweekly backups. Must be 35. |
monthly_no_copy |
bool |
false |
Take monthly backups on the no-copy plan, instead of monthly. |
monthly_no_copy_retention_days |
number |
370 |
Days to keep no-copy monthly backups. Must be 370. |
biannual_no_copy |
bool |
false |
Take biannual backups on the no-copy plan, instead of biannual. |
biannual_no_copy_retention_days |
number |
740 |
Days to keep no-copy biannual backups. Must be 740. |
CORS rule object
Used in cors_rules. The map key becomes the rule's ID.
| Option | Type | Default | Description |
|---|---|---|---|
allowed_methods |
set(string) |
required | HTTP methods allowed by the rule. Must be GET, PUT, HEAD, POST, or DELETE. |
allowed_origins |
set(string) |
required | Origins allowed to make cross-origin requests. |
allowed_headers |
set(string) |
null |
Headers allowed in a preflight request. |
expose_headers |
set(string) |
null |
Headers exposed to the browser in the response. |
max_age_seconds |
number |
null |
Seconds browsers cache the preflight response. |
Resources
-
AWS documentation
Official AWS documentation for S3