13 ms·
Not be that guy, but we never send an object to S3 without compressing it on our end first.
by funstuff007 4y ago
Not be that guy, but we never send an object to S3 without compressing it on our end first.
- flatiron 4y agoWe never send anything unencrypted to S3. I have no clue why someone would not want to encrypt their data before putting it in the cloud…
- cmeacham98 4y agoFor people also using other AWS services (in particular compute ones like EC2) this doesn't do anything meaningful.
- flatiron 4y agoWe use other aws services. We decrypt the files on those services.
- thecleaner 4y agoBecause there is already server side encryption. Which I guess means data on disk is always encrypted not sure about in-memory.
- barkingcat 4y agoWould you encrypt files that are supposed to be publicly readable and accessible? I get hashing it and providing hashes, but encrypting public files seems excessive.
- 101011 4y agoThere's a very common data/ETL pattern wherein raw (unencrypted) data is stored into S3 at the very beginning of any pipeline. Adding encryption adds a layer for failure, which can grind your pipeline to a halt. I've seen a pattern of: drop raw data into an S3 bucket that has a very restrictive policy with a long retention policy. Then, process that data asynchronously (encrypt, transform, filter, etc) and drop it into a different bucket/area that is accessed by other consumers. Then, if any part of your ETL fails (encryption included), you can fix your bug and reprocess from your raw data without writers seeing any impact.