Skip to main content
rightsizing · aws

S3 buckets with no lifecycle configuration, so cold objects stay in S3 Standard indefinitely

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags S3 buckets that have no lifecycle configuration at all, meaning nothing moves ageing objects out of S3 Standard. The saving would be the cold Standard data multiplied by the Standard to Standard-IA rate gap, $0.023 versus $0.0125 per GB-month in us-east-1, and ZopNight waits for a per-bucket cold-data measure before showing one.

Signal and threshold

How ZopNight evaluates S3 buckets with no lifecycle configuration, so cold objects stay in S3 Standard indefinitely.
Field Value
Rule IDsRC-072
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
Thresholdno lifecycle configuration and measured cold Standard data
SourceZopNight
Permissions useds3:ListAllMyBuckets · s3:GetLifecycleConfiguration · cloudwatch:GetMetricStatistics

Without a lifecycle rule, S3 never moves or deletes anything

S3 does not tier objects on its own. An S3 Lifecycle configuration is the set of rules that transitions objects to cheaper storage classes or expires them after a number of days. A bucket without one keeps every object in the class it was written to, usually S3 Standard, until someone deletes it by hand.

The rate gap is large. AWS’s price list for US East (N. Virginia) shows S3 Standard at $0.023 per GB for the first 50 TB each month and S3 Standard-IA at $0.0125, with S3 Glacier Flexible Retrieval at $0.0036 and S3 Glacier Deep Archive at $0.00099.

Finding buckets with no lifecycle configuration

get-bucket-lifecycle-configuration returns an error for a bucket that has none, so a loop can list them:

Terminal window
for b in $(aws s3api list-buckets --query 'Buckets[].Name' --output text); do
aws s3api get-bucket-lifecycle-configuration --bucket "$b" >/dev/null 2>&1 || echo "$b"
done

For each result, check how much sits in Standard with the free daily storage metric:

Terminal window
aws cloudwatch get-metric-statistics --namespace AWS/S3 --metric-name BucketSizeBytes \
--dimensions Name=BucketName,Value=my-bucket Name=StorageType,Value=StandardStorage \
--start-time 2026-09-22T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Average

Signals ZopNight needs for this bucket

  1. ZopNight has confirmed the bucket has no lifecycle policy. If it cannot tell, it assumes nothing.
  2. The bucket has a known monthly cost.
  3. ZopNight has current Standard and Standard-IA storage rates.
  4. It has a measured amount of cold data in Standard, meaning data that is old and rarely read.

What keeps the finding hidden today

Total bucket size is not enough: it cannot tell you how much of the data is cold. ZopNight does not yet collect that per-bucket cold-data figure, so the rule raises nothing on any bucket until it does. The older approach of claiming a fixed share of the bucket bill has been removed, because a lifecycle rule only saves money on data that actually qualifies to move.

The transition saving

Terminal window
saving = cold Standard GB x (Standard rate - Standard-IA rate)

ZopNight prices only the Standard-IA step. Moving further, to a Glacier class, would save more per GB but adds retrieval fees and minimum storage durations.

Adding a lifecycle configuration

  1. Decide the ages per prefix: for example Standard-IA after 30 days, a Glacier class after 90, and expiry after 365 where data may be deleted.
  2. Write the rules and apply them:
Terminal window
aws s3api put-bucket-lifecycle-configuration --bucket my-bucket \
--lifecycle-configuration file://lifecycle.json
  1. Keep small objects in mind. By default S3 does not transition objects under 128 KB, per the transition considerations, and Standard-IA bills smaller objects as 128 KB, per the storage class guide.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·