Quick reference for storage types, storage classes, CLI commands, lifecycle rules, and encryption across the big three clouds.
Object StorageBlock StorageS3Lifecycle
Storage Types
| Type | Access | Use for |
| Object | HTTP by key | Media, backups, data lakes |
| Block | Attach to 1 VM | Boot disks, databases |
| File | NFS / SMB mount | Shared filesystems |
Service Name Map
| Concept | AWS | Azure | GCP |
| Object | S3 | Blob | GCS |
| Block | EBS | Managed Disks | Persistent Disk |
| File | EFS | Azure Files | Filestore |
| Archive | Glacier | Archive tier | Archive class |
CLI Commands
AWS S3
aws s3 mb s3://bucket # make bucket
aws s3 cp file s3://bucket/key # upload
aws s3 sync ./dir s3://bucket/pfx --delete # mirror
aws s3 ls s3://bucket --recursive # list
aws s3 presign s3://bucket/key --expires-in 3600
aws s3 rm s3://bucket/key # delete
Azure Blob
az storage container create -n c --account-name acct
az storage blob upload --account-name acct -c c -n key -f file
az storage blob list --account-name acct -c c -o table
az storage blob download --account-name acct -c c -n key -f out
Google Cloud Storage
gcloud storage buckets create gs://bucket --location=US
gcloud storage cp file gs://bucket/key
gcloud storage rsync ./dir gs://bucket/pfx --recursive
gcloud storage ls gs://bucket/**
gcloud storage sign-url gs://bucket/key --duration=1h
S3 Storage Classes
| Class | Min days | Retrieval |
| Standard | 0 | Instant |
| Intelligent-Tiering | 0 | Instant, auto |
| Standard-IA | 30 | Instant |
| Glacier Flexible | 90 | Minutes–hours |
| Deep Archive | 180 | Up to 12h |
Lifecycle & Versioning
# Lifecycle rule (S3 JSON)
{ "Rules": [{ "ID": "tier", "Status": "Enabled",
"Filter": { "Prefix": "logs/" },
"Transitions": [{ "Days": 30, "StorageClass": "GLACIER" }],
"Expiration": { "Days": 365 } }] }
aws s3api put-bucket-lifecycle-configuration \
--bucket b --lifecycle-configuration file://lc.json
# Versioning
aws s3api put-bucket-versioning --bucket b \
--versioning-configuration Status=Enabled
Encryption & Gotchas
# Upload with KMS key
aws s3 cp f s3://b/k --sse aws:kms --sse-kms-key-id alias/key
# Deny non-TLS access (bucket policy condition)
"Condition": { "Bool": { "aws:SecureTransport": "false" } }
- Buckets are private by default — never enable public access casually.
- Durability is ~11 nines; that does not protect against accidental deletes — use versioning.
- Egress (internet / cross-region) is billed per GB; keep compute near data.
- Cheap tiers have minimum-duration fees; early deletion adds charges.