Skip to main content
orphan · aws

S3 buckets holding incomplete multipart uploads with no abort lifecycle rule

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight targets S3 buckets that hold incomplete multipart uploads and have no lifecycle rule using `AbortIncompleteMultipartUpload`. S3 bills the orphaned parts as storage until the upload is completed or aborted. A finding needs the bytes those parts occupy, which ZopNight cannot yet measure per bucket, so it currently reports nothing.

Signal and threshold

How ZopNight evaluates S3 buckets holding incomplete multipart uploads with no abort lifecycle rule.
Field Value
Rule IDsRC-074
Categoryorphan
Severitylow
Metricnone — pure configuration read
Thresholdat least 1 incomplete upload and no abort rule
SourceZopNight
Permissions useds3:ListBucketMultipartUploads · s3:GetLifecycleConfiguration

Parts of an unfinished upload are billed like any object

Multipart upload sends a large object in pieces and assembles it at the end. The multipart upload overview explains that S3 keeps every uploaded part until you complete or stop the upload, and that you are billed for all storage, bandwidth and requests for the upload and its parts in the meantime. A client that crashes halfway through a 50 GB upload leaves those parts behind, invisible in a normal object listing.

AWS recommends a lifecycle rule with the AbortIncompleteMultipartUpload action for exactly this reason.

Seeing what is left over

Terminal window
aws s3api list-multipart-uploads --bucket my-bucket \
--query 'Uploads[].[Key,UploadId,Initiated]' --output table
aws s3api get-bucket-lifecycle-configuration --bucket my-bucket

Uploads initiated weeks ago are almost certainly abandoned. S3 Storage Lens reports IncompleteMultipartUploadStorageBytes, which its metrics glossary lists among the free cost-optimization metrics, if you want the byte total without walking every upload.

The gates ZopNight applies

  • The bucket’s lifecycle configuration was read and contains no abort rule for incomplete multipart uploads. If the configuration could not be read, the bucket is skipped.
  • At least one incomplete upload was actually found. A missing rule on its own is not evidence of waste.
  • The bucket has a price, used only to confirm pricing is available and never as the saving.
  • ZopNight knows how many bytes the incomplete parts hold and has the S3 Standard storage rate for the Region.

Why no finding appears today

The last gate is not met yet. Counting the bytes held by incomplete parts for every bucket would mean listing the parts of every upload, which is the expensive fan-out ZopNight deliberately avoids, so that measure is not collected. Without it there is no honest dollar figure, and pricing the whole bucket instead would overstate the waste by orders of magnitude. The check therefore raises nothing on any bucket until a per-bucket byte measure is available.

How the saving will be priced

Terminal window
saving = incomplete part GiB x S3 Standard price per GiB-hour x 730
cost after fix = 0 for those parts

Adding an abort rule now

  1. In the S3 console, open the bucket’s Management tab and create a lifecycle rule.
  2. Choose to delete incomplete multipart uploads and set the number of days, such as 7.
  3. Or apply it from the CLI with aws s3api put-bucket-lifecycle-configuration and a rule containing AbortIncompleteMultipartUpload with DaysAfterInitiation, as in the lifecycle example.
  4. Abort a specific upload immediately with aws s3api abort-multipart-upload.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·