Skip to content

Simple Storage Service (S3)

Stores files and objects, such as images, PDFs, exports, and other binary data. CloudFront uses an S3 bucket to serve front-end applications, and the Byks module creates that bucket for you. You provision buckets for any other file storage yourself with a BYM module.

Byks guides

GitHub actions

Terraform configuration

The only S3 bucket terraform-byks-module creates automatically is the static-site origin behind a CloudFront distribution.

Configure that bucket through the cloudfront_distributions block. See CloudFront Terraform configuration for the full options table, including the S3-specific fields default_s3_origin_type, override_s3_bucket_name, force_destroy_s3, and additional_s3_origins.

For any other bucket, provision it directly with the terraform-aws-s3-bucket module, outside the module "application" block. Each instance of the module creates one bucket.

s3.tf
module "example" {
  source = "git@github.com:BYM-IKT/terraform-aws-s3-bucket.git?ref=v4"
  name = "team-example-bucket-name"
  # options go here
}

Options

Option Type Default Description
name string required Name of the bucket. Must be globally unique, lowercase, between 3 and 63 characters, and follow S3's bucket naming rules.
force_destroy bool false Empty and delete the bucket without warning when it's deleted.
versioning_enabled bool true Keep previous versions of objects when they're overwritten or deleted.
expire_old_versions_days number 14 Days before expiring old (deleted) object versions. Set to 0 to disable.
expire_failed_multipart_upload_days number 3 Days before expiring failed multipart uploads. Set to 0 to disable.
create_cloudfront_oai bool false Create a CloudFront Origin Access Identity with read access to the bucket, and restrict the bucket policy to it.
encryption bool true Encrypt the bucket with AES256 using an S3-managed key. See use_kms_encryption to use a KMS key instead.
use_kms_encryption bool false Encrypt the bucket with a dedicated KMS key instead of the default AES256 encryption. Adds KMS permissions to the read and write policy outputs.
disable_public_access bool true Block all public access to the bucket. Set to false only when the bucket needs public permissions.
object_ownership_rule string "BucketOwnerEnforced" Either BucketOwnerEnforced, ObjectWriter, or BucketOwnerPreferred. With BucketOwnerEnforced, the bucket owner controls all object permissions and ACL grants no longer apply.
additional_tags map(string) {} Extra tags applied to the bucket.
extra_lifecycle_configuration_rules list(object) [] Extra lifecycle rules, beyond the built-in version and multipart-upload cleanup. See Lifecycle rule object.
backup_settings any {} AWS Backup schedule and retention settings for the bucket. See Backup settings object.
cors_rules map(object) {} Cross-origin resource sharing rules for the bucket. The map key becomes the rule's ID. See CORS rule object.

Lifecycle rule object

Used in extra_lifecycle_configuration_rules.

Option Type Default Description
id string required Unique identifier for the rule.
enabled bool required Turn the rule on or off.
abort_incomplete_multipart_upload_days number null Days after which an incomplete multipart upload for objects matching the rule is aborted.
filter_and any null Scope the rule to objects matching a prefix, tags, or object size, instead of the whole bucket.
expiration any null Expire objects matching the rule, by date, age in days, or delete-marker cleanup.
transition list(any) null Move objects matching the rule to another storage class after a date or number of days.
noncurrent_version_expiration any null Expire noncurrent versions of objects matching the rule.
noncurrent_version_transition list(any) null Move noncurrent versions of objects matching the rule to another storage class.

Backup settings object

Used in backup_settings.

Option Type Default Description
hourly bool false Take hourly backups.
hourly_retention_days number 7 Days to keep hourly backups. Must be 2 or 7.
twelve_hours bool false Take backups every twelve hours.
twelve_hours_retention_days number 14 Days to keep twelve-hour backups. Must be 14.
daily bool false Take daily backups.
daily_retention_days number 14 Days to keep daily backups. Must be 5, 10, 14, or 35.
biweekly bool false Take backups every two weeks.
biweekly_retention_days number 185 Days to keep biweekly backups. Must be 185.
monthly bool false Take monthly backups.
monthly_retention_days number 370 Days to keep monthly backups. Must be 95, 185, 370, or 1850.
monthly_annually bool false Take an extra yearly backup alongside the monthly one.
monthly_retention_years number 5 Years to keep the yearly backup. Must be 5.
biannual bool false Take backups every six months.
biannual_retention_days number 370 Days to keep biannual backups. Must be 370.
daily_no_copy bool false Take daily backups on the no-copy plan, instead of daily.
daily_no_copy_retention_days number 14 Days to keep no-copy daily backups. Must be 1, 14, or 35.
biweekly_no_copy bool false Take biweekly backups on the no-copy plan, instead of biweekly.
biweekly_no_copy_retention_days number 35 Days to keep no-copy biweekly backups. Must be 35.
monthly_no_copy bool false Take monthly backups on the no-copy plan, instead of monthly.
monthly_no_copy_retention_days number 370 Days to keep no-copy monthly backups. Must be 370.
biannual_no_copy bool false Take biannual backups on the no-copy plan, instead of biannual.
biannual_no_copy_retention_days number 740 Days to keep no-copy biannual backups. Must be 740.

CORS rule object

Used in cors_rules. The map key becomes the rule's ID.

Option Type Default Description
allowed_methods set(string) required HTTP methods allowed by the rule. Must be GET, PUT, HEAD, POST, or DELETE.
allowed_origins set(string) required Origins allowed to make cross-origin requests.
allowed_headers set(string) null Headers allowed in a preflight request.
expose_headers set(string) null Headers exposed to the browser in the response.
max_age_seconds number null Seconds browsers cache the preflight response.

Resources