4 ms·
Why all that stuff with namespaces when they could just not allow name reuse?
by Aardwolf 7mo ago
Why all that stuff with namespaces when they could just not allow name reuse?
- deleted 7mo ago[deleted]
- CodesInChaos 7mo agoI'd allow re-use, but only by the original account. Not being able to re-create a bucket after deleting it would be annoying. I think that's an important defense that AWS should implement for existing buckets, to complement account scoped bucket.
- wiether 7mo agoThen they should allow bucket ownership transfer...
- iknownothow 7mo agoPotential reasons I can think of for why they don't disallow name reuse: a) AWS will need to maintain a database of all historical bucket names to know what to disallow. This is hard per region and even harder globally. Its easier to know what is currently in use rather know what has been used historically. b) Even if they maintained a database of all historically used bucket names, then the latency to query if something exists in it may be large enough to be annoying during bucket creation process. Knowing AWS, they'll charge you for every 1000 requests for "checking if bucket name exists" :p c) AWS builds many of its own services on S3 (as indicated in the article) and I can imagine there may be many of their internal services that just rely on existing behaviour i.e. allowing for re-creating the same bucket name.
- dwedge 7mo agoI can't accept a) or b). They already need to keep a database of all existing bucket names globally, and they already need to check this on bucket creation. Adding a flag on deleted doesn't seem like a big loss. As for c), I assume it's not just AWS relying on this behaviour. https://xkcd.com/1172/ https://xkcd.com/1172/
- orf 7mo agoThat would be a huge breaking change. Any workload that relies on re-using a bucket name would be broken, and at the scale of S3 that would have a non-trivial customer impact. Not to mention the ergonomics would suck - suddenly your terraform destroy/apply loop breaks if there’s a bucket involved
- afandian 7mo agoAny workload that relies on re-using a bucket name is broken by design. If someone else can get it, then it's Undefined Behaviour. So it's in keeping with the contract for AWS to prevent re-use. Surely?
- orf 7mo agoThink terraform tests, temporary environments, etc. Or anything else: it’s Hyrum's Law.
- hrmtst93837 7mo ago[flagged]
- JoBrad 7mo agoI think a better policy would be to disallow bucket names that follow the account regional namespace convention, but don’t match the account id indicated in the name.
- NetMageSCW 7mo agoSo no bucket sharing across accounts?
- JoBrad 7mo agoLimiting the creation of buckets that use the account namespace conventions doesn't affect whether other accounts can access it.