Skip to main content
rightsizing · aws

S3 buckets over 1 TiB with public access where Requester Pays could shift download costs

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight checks S3 buckets holding at least 1 TiB that have public access enabled and Requester Pays off. Enabling Requester Pays moves request and download charges to authenticated requesters, but no per-bucket measure separates outside downloads from your own, so ZopNight raises no dollar finding until that split can be measured.

Signal and threshold

How ZopNight evaluates S3 buckets over 1 TiB with public access where Requester Pays could shift download costs.
Field Value
Rule IDsRC-175
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
Threshold>= 1 TiB stored, public access enabled, Requester Pays off
SourceZopNight
Permissions useds3:ListAllMyBuckets · s3:GetBucketRequestPayment · s3:GetBucketPolicyStatus

By default the bucket owner pays for every download

AWS explains that bucket owners normally pay all storage and data transfer costs for their bucket. With Requester Pays turned on, the requester pays for requests and data downloads instead, while the owner still pays for storage. AWS suggests it for sharing large datasets, such as reference data, geospatial files or crawl data, without paying for everyone else’s use.

The numbers can be large. The AWS data transfer price list charges $0.09 per GB for the first 10 TB a month out to the internet from US East (N. Virginia), after the 100 GB a month that is free across all services. Outside users pulling 5 TB of a public dataset each month cost the owner about $450.

Checking a bucket’s size and payer setting

Terminal window
aws s3api get-bucket-request-payment --bucket my-dataset-bucket
aws s3api get-bucket-policy-status --bucket my-dataset-bucket
aws cloudwatch get-metric-statistics --namespace AWS/S3 --metric-name BucketSizeBytes \
--dimensions Name=BucketName,Value=my-dataset-bucket Name=StorageType,Value=StandardStorage \
--statistics Average --period 86400 \
--start-time 2026-09-20T00:00:00Z --end-time 2026-09-25T00:00:00Z

Payer reads BucketOwner or Requester.

Pre-filters the rule applies

  1. Requester Pays is not already on.
  2. Public access is enabled on the bucket, which ZopNight uses as the sign that outside parties can read it. If that setting could not be read, the bucket is skipped.
  3. Storage across all classes adds up to at least 1 TiB.

The measurement that is missing

The saving is only the traffic that outside requesters generate, because your own reads would cost you the same either way. Nothing lightweight reports that per bucket. S3 request metrics count all requests with no split by who made them; Cost Explorer reports transfer for the whole account; and only server access logs or CloudTrail data events name the requester, which needs logging you enable and a separate analysis job. So the rule raises no finding for any bucket today rather than bill your own traffic as a saving. Public access itself is reviewed by S3 Bucket With Public Access Enabled.

How it will be priced once external traffic is measured

Terminal window
saving = external download GB x data transfer rate + external GET requests x request rate

Until then, estimate it from access logs by filtering out requests from your own accounts.

Turning on Requester Pays

  1. Confirm every consumer can sign requests with AWS credentials. AWS does not allow anonymous access to a Requester Pays bucket.
  2. Tell consumers to send x-amz-request-payer (or --request-payer requester in the CLI); requests without it are refused.
  3. Enable it: aws s3api put-bucket-request-payment --bucket my-dataset-bucket --request-payment-configuration Payer=Requester
  4. Watch for 403 errors from consumers that have not updated.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·