从EC2迁移文件至AWS S3后,如何禁用删除选项并保障至少6个月留存?
Hey there! Let's walk through exactly how to secure your S3 bucket for your EC2-to-S3 migration—you want to disable that pesky "Delete" option in the console, prevent accidental deletions, and make sure every file sticks around for at least 6 months. Here's the step-by-step breakdown:
The simplest way to remove the delete button from the S3 console is to deny the s3:DeleteObject and s3:DeleteObjectVersion permissions for any user/role accessing the bucket. This doesn't just hide the button—it blocks deletion attempts entirely, even via CLI/SDK.
Here's a sample IAM policy you can attach to your EC2 instance's role or any user who manages the bucket:
{ "Version": "2012-10-17", "Statement": [ // Allow necessary actions for migration and access { "Effect": "Allow", "Action": [ "s3:PutObject", "s3:GetObject", "s3:ListBucket", "s3:ListBucketVersions" ], "Resource": [ "arn:aws:s3:::your-bucket-name", "arn:aws:s3:::your-bucket-name/*" ] }, // Block all deletion actions { "Effect": "Deny", "Action": [ "s3:DeleteObject", "s3:DeleteObjectVersion" ], "Resource": "arn:aws:s3:::your-bucket-name/*" } ] }
Once this policy is active, the "Delete" option in the S3 console will be grayed out for any user/role using this policy—no more accidental clicks!
To guarantee files can't be deleted or modified for at least 6 months, you'll need to use S3's Versioning and Object Lock features together. These create a WORM (Write Once, Read Many) environment that locks objects down.
Step 2.1: Enable Versioning on Your Bucket
First, turn on versioning for your bucket. This ensures that even if someone tries to overwrite an object, the original version is preserved. You can do this in the S3 console under the "Properties" tab of your bucket, or via CLI:
aws s3api put-bucket-versioning --bucket your-bucket-name --versioning-configuration Status=Enabled
Step 2.2: Set Up Object Lock with 6-Month Retention
Object Lock is what enforces the mandatory retention period. You have two modes to choose from:
- Compliance Mode: Strictest option—no one (not even the AWS root account) can delete or modify the object before the retention period ends. Ideal for your "at least 6 months" requirement.
- Governance Mode: Regular users can't delete objects, but admins with specific permissions can override the lock if needed.
Note: You can only enable Object Lock when creating a bucket, or by replicating your existing bucket to a new one with Object Lock enabled. Once enabled, you can set:
- A default retention policy for the bucket (so every new object gets locked automatically)
- Or specify the retention period when uploading objects from EC2.
Example: Upload from EC2 with Compliance Lock
If you're using the AWS CLI on your EC2 instance to copy files, add these parameters to enforce a 6-month compliance lock:
# Calculate the retention date (6 months from now) RETENTION_DATE=$(date -d "+6 months" +%Y-%m-%d) # Copy file to S3 with Object Lock aws s3 cp /path/to/your/ec2/file.txt s3://your-bucket-name/file.txt \ --object-lock-mode COMPLIANCE \ --object-lock-retain-until-date $RETENTION_DATE
Optional: Set a Bucket-Wide Default Retention
If you want every object uploaded to the bucket to automatically get a 6-month lock, set a default retention policy in the S3 console under "Object Lock" → "Default Retention", or via CLI:
aws s3api put-object-lock-configuration --bucket your-bucket-name \ --object-lock-configuration '{ "ObjectLockEnabled": "Enabled", "Rule": { "DefaultRetention": { "Mode": "COMPLIANCE", "Days": 180 } } }'
- Combining IAM permission restrictions with Object Lock gives you layered security: no one can click "Delete" in the console, and even if someone tried to bypass that (via a loophole), Object Lock would block deletion until the 6-month period is up.
- After the retention period ends, you can add a lifecycle rule to transition objects to cheaper storage classes (like S3 Standard-Infrequent Access) if needed, to save costs.
内容的提问来源于stack exchange,提问作者Mohit Agrawal

