AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium
A global media company uses a content management system (CMS) that stores large media files (up to several terabytes each) in an Amazon S3 bucket. Content creators frequently upload new files and update existing ones. The company wants to improve the efficiency of content ingestion by allowing content creators to upload directly to S3 without exposing AWS credentials to their client applications, while also ensuring that large files can be uploaded reliably even over unstable network connections. Which solution would meet these requirements effectively?
- AGenerate S3 pre-signed URLs for Multi-Part Uploads, which content creators can use to upload files directly.
- BUse Amazon CloudFront with signed URLs to allow uploads to an S3 bucket.
- CImplement a custom API Gateway endpoint that proxies uploads to S3, handling authentication and authorization.
- DProvide content creators with temporary IAM credentials configured with specific S3 put object permissions.
Show answer & explanationAnswer & explanation
Correct answer: A. Generate S3 pre-signed URLs for Multi-Part Uploads, which content creators can use to upload files directly.
S3 pre-signed URLs allow temporary, direct access to S3 objects without exposing AWS credentials. Combining this with Multi-Part Uploads enables uploading large files in smaller parts, which can be retried independently, improving reliability over unstable networks and allowing for parallel uploads.
Why the other options are wrong
- B. CloudFront is primarily a CDN for content delivery, not for direct uploads to S3 from clients. While signed URLs can be used with CloudFront, they are typically for restricting access to content, not for enabling robust uploads of large files.
- C. A custom API Gateway endpoint and proxying uploads to S3 would add significant latency, complexity, and cost, especially for large files, and wouldn't inherently provide the multi-part upload benefits for resilience.
- D. Providing temporary IAM credentials directly to client applications is less secure than pre-signed URLs, as it still involves managing and distributing credentials, even if temporary. It also doesn't inherently facilitate reliable large file uploads via multi-part functionality.
S3 Pre-signed URLs with Multi-Part Upload
S3 pre-signed URLs grant temporary, time-limited permission for a user to perform an action (e.g., upload, download) on a specific S3 object without needing AWS credentials. Multi-Part Upload is an S3 feature for uploading large objects by splitting them into smaller parts.
- Pre-signed URLs enable direct S3 access without exposing credentials.
- Multi-Part Upload improves reliability and speed for large file uploads.
- Parts can be uploaded in parallel and retried independently.
Memory trick: Pre-signed Parts Protect Uploads.