QuestionQ3

Reliability and Business Continuity

A company is implementing Cross-Region Replication (CRR) for its Amazon S3 buckets. The S3 buckets are in the us-east-1 Region. The company uses server-side encryption with Amazon S3 managed keys (SSE-S3) to protect the data in the buckets.

A CloudOps engineer creates a new AWS account to store backups in S3 buckets. All backup buckets are in the us-west-2 Region. The CloudOps engineer enables versioning on both the source buckets and destination buckets. The CloudOps engineer creates an IAM role in the source account for s3.amazonaws.com. The CloudOps engineer grants the IAM role permissions to perform read actions in the source buckets, replicate actions in the destination buckets, and encrypt actions using the destination bucket's key. The destination bucket policy allows the IAM role to perform replicate and read actions.

After completing the replication configuration, the CloudOps engineer notices that objects are not replicating.

What is the likely reason that the objects are not replicating?

Explanation

When cross-account replication is configured to transfer replica ownership to the destination bucket owner, the S3 replication role and the destination bucket policy must allow s3:ObjectOwnerOverrideToBucketOwner. SSE-S3 supports replication and does not require multi-Region KMS keys or SSE-KMS at the destination, and S3 replication does not require gateway VPC endpoints.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!