能否直接上传文件至Amazon S3 Infrequent Access(S3IA)及启用KMS加密?
Great questions! Let’s break them down one by one to get you sorted for your archive migration to AWS:
1. Direct Upload to S3 IA Without S3 Standard
Absolutely! You don’t need to route files through S3 Standard first—you can upload directly to S3 Infrequent Access (S3 IA) right from the start. This is perfect for your use case (low-access files that need immediate availability) because it cuts out unnecessary steps and avoids any temporary storage costs in the Standard tier. AWS designed S3 IA to support direct uploads specifically for scenarios like long-term archiving with on-demand access.
2. KMS Encryption Support for Direct Uploads via Node.js/Python
Yep, this is fully supported. Both the AWS SDK for Node.js (v3 recommended) and Boto3 (AWS SDK for Python) let you specify KMS encryption alongside the S3 IA storage class during upload. Here’s how you can implement it in each language:
Node.js Example (AWS SDK v3)
import { S3Client, PutObjectCommand } from "@aws-sdk/client-s3"; const s3Client = new S3Client({ region: "your-region" }); const uploadParams = { Bucket: "your-bucket-name", Key: "path/to/your/archive-file.zip", Body: "your-file-content", // Or a readable stream for large files StorageClass: "INFREQUENT_ACCESS", ServerSideEncryption: "aws:kms", SSEKMSKeyId: "arn:aws:kms:your-region:your-account-id:key/your-kms-key-id" }; const run = async () => { try { const response = await s3Client.send(new PutObjectCommand(uploadParams)); console.log("Upload successful:", response); } catch (err) { console.error("Error uploading file:", err); } }; run();
Python Example (Boto3)
import boto3 s3 = boto3.client('s3', region_name='your-region') with open('local-archive-file.zip', 'rb') as file: s3.put_object( Bucket='your-bucket-name', Key='path/to/your/archive-file.zip', Body=file, StorageClass='INFREQUENT_ACCESS', ServerSideEncryption='aws:kms', SSEKMSKeyId='arn:aws:kms:your-region:your-account-id:key/your-kms-key-id' ) print("File uploaded successfully to S3 IA with KMS encryption!")
Just make sure your IAM role/user has the necessary permissions: s3:PutObject on the target bucket, and kms:GenerateDataKey (plus any other required KMS permissions) for the specified KMS key.
内容的提问来源于stack exchange,提问作者Xmus Jackson Flaxon Waxon

