AWS

S3

Browse buckets and objects, download files, upload, and pin what you use often.

S3 is Amazon's file storage. Files are objects, and they live in buckets. This screen is a file browser for them.

Buckets

Every bucket in the account, with its region. Pin the ones you use often and they stay at the top.

You can switch between a list and a grid view, and open any bucket in the AWS console with one click when you need something we do not do.

Browsing

Inside a bucket, folders and objects are listed with size and last-modified date. Click a file for its details.

  • Download — pulls the file down through a short-lived, signed link.
  • Upload — up to 50 MB per file here. Larger files should go through the AWS console or the CLI.
  • New folder — creates a prefix.
  • Delete — permanent unless the bucket has versioning enabled.

The two settings worth checking on every bucket

We show them because they are the two that cause incidents:

  1. Public access. A bucket open to the world is the classic data leak. If a bucket is public and you did not mean it, fix it now — and check Account-level Block Public Access on the Dashboard, which prevents it happening again.

  2. Versioning. With versioning on, deleting an object keeps the old version and you can recover it. With it off, delete means gone. Worth turning on for anything you would miss.

Encryption at rest is also shown.

Costs

S3 charges for storage, for requests and for data leaving AWS. The usual surprises:

  • Old versions. With versioning on, every version is still stored and still billed. A lifecycle rule to expire old versions is often a large saving.
  • Incomplete multipart uploads. Failed uploads leave fragments that are billed forever until a lifecycle rule removes them.
  • Wrong storage class. Archives sitting on Standard.

FinOps picks up the big ones.

Permissions

Browsing needs s3:ListAllMyBuckets, s3:GetBucketLocation, s3:ListBucket and s3:GetObject. Upload, new folder, new bucket and delete need the matching write permissions — leave them off if you want a strictly read-only key. See AWS permissions.

Operators can upload and create; only Owners and Admins can delete. See Roles.