contentintech

Cloud Storage Cheatsheet

Quick reference for storage types, storage classes, CLI commands, lifecycle rules, and encryption across the big three clouds.

Object StorageBlock StorageS3Lifecycle
NotesCheatsheet

Storage Types

TypeAccessUse for
ObjectHTTP by keyMedia, backups, data lakes
BlockAttach to 1 VMBoot disks, databases
FileNFS / SMB mountShared filesystems

Service Name Map

ConceptAWSAzureGCP
ObjectS3BlobGCS
BlockEBSManaged DisksPersistent Disk
FileEFSAzure FilesFilestore
ArchiveGlacierArchive tierArchive class

CLI Commands

AWS S3

aws s3 mb s3://bucket                       # make bucket
aws s3 cp file s3://bucket/key              # upload
aws s3 sync ./dir s3://bucket/pfx --delete  # mirror
aws s3 ls s3://bucket --recursive           # list
aws s3 presign s3://bucket/key --expires-in 3600
aws s3 rm s3://bucket/key                    # delete

Azure Blob

az storage container create -n c --account-name acct
az storage blob upload --account-name acct -c c -n key -f file
az storage blob list --account-name acct -c c -o table
az storage blob download --account-name acct -c c -n key -f out

Google Cloud Storage

gcloud storage buckets create gs://bucket --location=US
gcloud storage cp file gs://bucket/key
gcloud storage rsync ./dir gs://bucket/pfx --recursive
gcloud storage ls gs://bucket/**
gcloud storage sign-url gs://bucket/key --duration=1h

S3 Storage Classes

ClassMin daysRetrieval
Standard0Instant
Intelligent-Tiering0Instant, auto
Standard-IA30Instant
Glacier Flexible90Minutes–hours
Deep Archive180Up to 12h

Lifecycle & Versioning

# Lifecycle rule (S3 JSON)
{ "Rules": [{ "ID": "tier", "Status": "Enabled",
  "Filter": { "Prefix": "logs/" },
  "Transitions": [{ "Days": 30, "StorageClass": "GLACIER" }],
  "Expiration": { "Days": 365 } }] }

aws s3api put-bucket-lifecycle-configuration \
  --bucket b --lifecycle-configuration file://lc.json

# Versioning
aws s3api put-bucket-versioning --bucket b \
  --versioning-configuration Status=Enabled

Encryption & Gotchas

# Upload with KMS key
aws s3 cp f s3://b/k --sse aws:kms --sse-kms-key-id alias/key

# Deny non-TLS access (bucket policy condition)
"Condition": { "Bool": { "aws:SecureTransport": "false" } }
  • Buckets are private by default — never enable public access casually.
  • Durability is ~11 nines; that does not protect against accidental deletes — use versioning.
  • Egress (internet / cross-region) is billed per GB; keep compute near data.
  • Cheap tiers have minimum-duration fees; early deletion adds charges.

Section navigation