S3 buckets over 1 TiB with public access where Requester Pays could shift download costs
What does ZopNight detect here?
ZopNight checks S3 buckets holding at least 1 TiB that have public access enabled and Requester Pays off. Enabling Requester Pays moves request and download charges to authenticated requesters, but no per-bucket measure separates outside downloads from your own, so ZopNight raises no dollar finding until that split can be measured.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-175 |
| Category | rightsizing |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | >= 1 TiB stored, public access enabled, Requester Pays off |
| Source | ZopNight |
| Permissions used | s3:ListAllMyBuckets · s3:GetBucketRequestPayment · s3:GetBucketPolicyStatus |
Where it applies
By default the bucket owner pays for every download
AWS explains that bucket owners normally pay all storage and data transfer costs for their bucket. With Requester Pays turned on, the requester pays for requests and data downloads instead, while the owner still pays for storage. AWS suggests it for sharing large datasets, such as reference data, geospatial files or crawl data, without paying for everyone else’s use.
The numbers can be large. The AWS data transfer price list charges $0.09 per GB for the first 10 TB a month out to the internet from US East (N. Virginia), after the 100 GB a month that is free across all services. Outside users pulling 5 TB of a public dataset each month cost the owner about $450.
Checking a bucket’s size and payer setting
aws s3api get-bucket-request-payment --bucket my-dataset-bucket
aws s3api get-bucket-policy-status --bucket my-dataset-bucket
aws cloudwatch get-metric-statistics --namespace AWS/S3 --metric-name BucketSizeBytes \ --dimensions Name=BucketName,Value=my-dataset-bucket Name=StorageType,Value=StandardStorage \ --statistics Average --period 86400 \ --start-time 2026-09-20T00:00:00Z --end-time 2026-09-25T00:00:00ZPayer reads BucketOwner or Requester.
Pre-filters the rule applies
- Requester Pays is not already on.
- Public access is enabled on the bucket, which ZopNight uses as the sign that outside parties can read it. If that setting could not be read, the bucket is skipped.
- Storage across all classes adds up to at least 1 TiB.
The measurement that is missing
The saving is only the traffic that outside requesters generate, because your own reads would cost you the same either way. Nothing lightweight reports that per bucket. S3 request metrics count all requests with no split by who made them; Cost Explorer reports transfer for the whole account; and only server access logs or CloudTrail data events name the requester, which needs logging you enable and a separate analysis job. So the rule raises no finding for any bucket today rather than bill your own traffic as a saving. Public access itself is reviewed by S3 Bucket With Public Access Enabled.
How it will be priced once external traffic is measured
saving = external download GB x data transfer rate + external GET requests x request rateUntil then, estimate it from access logs by filtering out requests from your own accounts.
Turning on Requester Pays
- Confirm every consumer can sign requests with AWS credentials. AWS does not allow anonymous access to a Requester Pays bucket.
- Tell consumers to send
x-amz-request-payer(or--request-payer requesterin the CLI); requests without it are refused. - Enable it:
aws s3api put-bucket-request-payment --bucket my-dataset-bucket --request-payment-configuration Payer=Requester - Watch for 403 errors from consumers that have not updated.