What it is
S3 is object storage. You put files (objects) into buckets. Documents, images, backups, that pricing spreadsheet with 200 formulas and one broken VLOOKUP. Any size. Basically unlimited quantity.
It is not a hard drive you mount. It is a place you put things and ask for them back by name. Versioning, lifecycle rules, and encryption are optional until the day they are not.
Azure Blob Storage is the twin. Same job. Different portal. Same consequences when the bucket (or container) is public and nobody noticed.
Why it matters in the meeting
When Selena says "it is just in S3," Bart hears "who can read it?" JJ hears "is this on the invoice?" Both questions are fair. Storage without an access story is a filing cabinet in the lobby.
S3 is cheap to fill and expensive to ignore. Public access blocks, bucket policies, and lifecycle rules are the meeting topics. The service itself is the easy part.
Real world
The classic story is a supplier portal deployed with defaults, public access not blocked, pricing matrix open to anyone with a URL. Bart finds it on Monday. The bucket becomes private. Nobody mentions it to the client.
Less dramatic version: years of logs in Standard with no lifecycle. The shelf was wrong. The bill was honest.
S3 is a very large drawer. The cloud will store whatever you put in it. You still decide who has the key, and whether yesterday's junk deserves today's price.
What to ask
- Is Block Public Access on for every production bucket?
- Who can list and read objects, and is that still the right list?
- Do we have lifecycle rules, or is everything living in Standard forever?
- If this bucket URL leaked tonight, what would a stranger see?
You just knew a little more Jack than you did five minutes ago.
All concepts