Hands-On Mini Lab

S3 Versioning and Lifecycle Lab

Negligible for tiny test objects if cleaned up. Lifecycle transitions and retained versions can create charges if left behind.

Goal

Reinforce Buckets and objects, Versioning, Lifecycle rules, Encryption, Cleanup discipline through a small, inspectable activity. This is a learning exercise, not a production design: use a dedicated sandbox or test account, record what you observe, and do not copy the permissions or data-handling choices into production without review.

What you should be able to explain afterward: what AWS managed for you, what you configured, what evidence proves the result, and what could continue to cost money or expose data if you leave it behind.

Concepts Reinforced

  • Buckets and objects
  • Versioning
  • Lifecycle rules
  • Encryption
  • Cleanup discipline

Prerequisites

  • AWS CLI configured
  • Permission to create a test S3 bucket

Before you start

  1. Choose one AWS Region and write it down; many resources and console views are Region-specific.
  2. Confirm that you are operating only in an authorized non-production account and that you can identify the account ID before creating anything.
  3. Open the AWS service documentation linked below if a console label or command option is unfamiliar. The lab is successful when you understand the observation, not when you click through it quickly.

Estimated Cost

Exact Steps

Read the entire sequence before beginning. Substitute your own test names for every placeholder, keep the Region consistent, and pause after each step to inspect the result. If a command returns an error, do not repeatedly retry it without reading the error: check Region, account, permissions, resource identifiers, and whether the preceding step actually completed.

  1. Create a uniquely named bucket in one Region.
  2. Enable versioning on the bucket.
  3. Upload a small text object twice with different content.
  4. List object versions and observe that S3 retained both versions.
  5. Apply a lifecycle rule that expires noncurrent versions after a short test interval where allowed by your account policy.
Runnable example after replacing bucket name and Region
aws s3api create-bucket --bucket djames-study-example-111122223333 --region us-east-1
aws s3api put-bucket-versioning --bucket djames-study-example-111122223333 --versioning-configuration Status=Enabled
aws s3 cp ./note.txt s3://djames-study-example-111122223333/note.txt
aws s3api list-object-versions --bucket djames-study-example-111122223333 --prefix note.txt

Verification

Verification is the evidence that the concept worked. Capture the relevant ARN, status, identity, log entry, policy result, object version, or query output before cleanup. A successful command alone is not proof that the intended control behaved correctly.

  • aws s3api list-object-versions returns more than one version for the same key.
  • The lifecycle configuration is visible with get-bucket-lifecycle-configuration.

If the result is different

  • Confirm the selected Region and AWS account.
  • Check the exact resource identifier and current status.
  • Review the service event history, CloudTrail event, CloudWatch log, or command output when available.
  • Re-read the relevant IAM policy, trust policy, security rule, or service setting instead of assuming the service is at fault.

Cleanup Steps

Cleanup is part of the lab. Remove test resources in dependency order, delete temporary credentials or local files, and check the billing or resource console for anything that remains. Some services retain versions, snapshots, logs, or recovery artifacts even after the visible parent resource is deleted.

  • Delete all object versions and delete markers.
  • Delete the bucket.

Sources and Review Metadata