{"enrichment":{"faq":[{"a":"aws-s3 guides you through bucket creation with security hardening: enable versioning and encryption (SSE-S3 or KMS), activate public access blocks to prevent accidental exposure, and configure bucket policies to enforce HTTPS-only access. The skill covers setting object-level permissions and implementing least-privilege access controls for production environments.","q":"How do you create and secure an S3 bucket with aws-s3?"},{"a":"aws-s3 helps you set up lifecycle rules to automatically transition objects between storage classes\u2014moving to GLACIER for archival or INTELLIGENT_TIERING for cost optimization. You can configure expiration policies to delete old versions or incomplete multipart uploads, reducing storage costs while maintaining compliance and data retention requirements.","q":"What lifecycle rules and storage class transitions does aws-s3 support?"},{"a":"aws-s3 walks you through configuring cross-region replication (CRR) to automatically copy objects to a secondary region, ensuring high availability and disaster recovery. The skill covers replication metrics, status monitoring, and failover strategies so your data remains accessible even if a region becomes unavailable.","q":"How can aws-s3 enable cross-region replication for disaster recovery?"},{"a":"aws-s3 explains presigned URLs\u2014time-limited, cryptographically signed URLs that grant temporary access to private S3 objects without exposing credentials. Use them for downloads, uploads, or sharing sensitive data with external users; the skill covers URL expiration, permission scoping, and security best practices.","q":"How do presigned URLs in aws-s3 provide temporary secure access?"},{"a":"aws-s3 provides diagnostics for common access issues: verify bucket policies and IAM roles, check public access block settings, confirm encryption key permissions (for KMS), and validate cross-account policies. The skill guides you through policy evaluation logic and logging configuration to identify permission mismatches quickly.","q":"How does aws-s3 help troubleshoot S3 access denied errors?"},{"a":"aws-s3 demonstrates bucket policies that deny non-HTTPS requests, restrict access by VPC endpoint, enforce specific IAM principals, and block public uploads. The skill shows policy syntax, condition operators, and validation techniques to ensure only authorized, encrypted traffic reaches your buckets.","q":"What S3 bucket policies enforce HTTPS and restrict access with aws-s3?"}],"shadow_tags":["object-storage-management","aws-infrastructure","data-retention-policies","encryption-and-security","disaster-recovery-setup","cost-optimization-storage","access-control-iam","compliance-and-governance"],"summary_rewrite":"AWS S3 equips you with production-grade bucket configuration, from hardening with encryption and public access blocks to enforcing policies and setting up cross-region replication. Handle lifecycle transitions, presigned URLs, and access control in one skill."},"files":[{"bytes":11877,"path":"infrastructure/cloud-aws/aws-s3/SKILL.md","sha256":"377f4dc615ec8bc6311bc6483965f8db63b03cb764e82191f95b0b9b5b64f1b9","url":"https://skillfed.io/files/BagelHole/DevOps-Security-Agent-Skills/aws-s3/090a66c6/SKILL.md"}],"id":"BagelHole/DevOps-Security-Agent-Skills/aws-s3","links":{"html":"https://skillfed.io/BagelHole/DevOps-Security-Agent-Skills/aws-s3","md":"https://skillfed.io/BagelHole/DevOps-Security-Agent-Skills/aws-s3.md","repo":"https://github.com/BagelHole/DevOps-Security-Agent-Skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":4,"language":"Shell","last_updated":"2026-05-22","license":"MIT","name":"aws-s3","publisher":"BagelHole","stars":44},"relations":{"similar":[{"id":"BagelHole/DevOps-Security-Agent-Skills/object-storage"},{"id":"itsmostafa/aws-agent-skills/s3"},{"id":"chaterm/terminal-skills/cloud-backup"},{"id":"BagelHole/DevOps-Security-Agent-Skills/aws-cost-optimization"},{"id":"personamanagmentlayer/pcl/aws-expert"},{"id":"manutej/luxor-claude-marketplace/aws-cloud-architecture"},{"id":"BagelHole/DevOps-Security-Agent-Skills/aws-cloudtrail"},{"id":"aj-geddes/useful-ai-prompts/aws-s3-management"},{"id":"giuseppe-trisciuoglio/developer-kit/aws-sdk-java-v2-s3"},{"id":"giuseppe-trisciuoglio/developer-kit/aws-cloudformation-s3"}]},"slug":{"owner":"BagelHole","repo":"DevOps-Security-Agent-Skills","skill":"aws-s3"},"version":"090a66c6"}
