S3 bucket default encryption for object uploads


Since the launch of default encryption feature earlier this year for S3 buckets and objects uploaded to S3, I've been adding objects to an existing bucket and I am not seeing the default encryption being shown in the Console for these objects. Does anyone have any insight?

asked 2 years ago855 views
1 Answer
Accepted Answer

Starting January 5, 2023, the automatic encryption status for S3 bucket default encryption configuration and all new object uploads is visible in AWS CloudTrail logs across all AWS Regions, including the AWS GovCloud (US) Regions and the AWS China Regions. Over the next few weeks, we will roll out this automatic encryption status to the Amazon S3 console, S3 Inventory, S3 Storage Lens, and Amazon S3 API responses in the AWS CLI and AWS SDKs in all Regions. During the next few weeks, the automatic encryption status will also be rolled out to the Amazon S3 console, S3 Inventory, S3 Storage Lens, and as an additional Amazon S3 API response header in the AWS Command Line Interface and AWS SDKs. When this update is complete in all AWS Regions, we will update the documentation.

Will Amazon S3 encrypt my existing objects that are unencrypted? No. Beginning on January 5, 2023, Amazon S3 only automatically encrypts new object uploads. To encrypt existing objects, you can use S3 Batch Operations to create encrypted copies of your objects. These encrypted copies will retain the existing object data and name and will be encrypted by using the encryption keys that you specify.

Above answers referenced from: https://docs.aws.amazon.com/AmazonS3/latest/userguide/default-encryption-faq.html

answered 2 years ago
profile picture
reviewed 4 months ago
profile pictureAWS
reviewed 2 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions