Memory hook: Choose the application's storage protocol first, then decide whether you need persistent access, hybrid access or data movement.
Must remember
Separate block, file and object needs
- EBS supplies block volumes with AZ placement constraints. An application normally creates a filesystem on the volume; it is not automatically a shared network filesystem.
- EFS supplies shared NFS access for Linux/POSIX workloads. Choose its availability and throughput configuration deliberately; “shared” does not mean every file-storage protocol is supported.
- S3 supplies an object API. Object keys are not ordinary disk blocks or a full POSIX filesystem. An application needing native file locking or SMB semantics usually needs another access layer.
- FSx is a family of managed specialized filesystems. Choose the correct family rather than treating every FSx option as interchangeable. AWS storage overview
Recognize the FSx families by their strongest clue
- FSx for Windows File Server: Windows SMB shares, NTFS permissions and Active Directory integration. This fits Windows home directories and applications that depend on Windows file-server behavior; EFS is not a drop-in replacement.
- FSx for Lustre: parallel high-throughput file access for HPC, analytics and machine learning. Link S3 datasets to a fast computation tier; understand scratch versus persistent deployment requirements rather than assuming every filesystem copy is your durable source.
- FSx for NetApp ONTAP: NetApp features and multiprotocol access, including NFS, SMB and iSCSI. Familiar snapshots, cloning, efficiency and migration capabilities matter when preserving an existing NetApp environment.
- FSx for OpenZFS: managed ZFS-oriented file workloads over NFS, with snapshots and cloning. The cue is ZFS compatibility and NFS behavior, not Windows SMB integration. Windows file-server features
- Across all four, check performance capacity, network placement, backup/restore and availability options separately. A fast scratch filesystem and a highly available production file store answer different questions.
Match a gateway to the on-premises interface
AWS Storage Gateway connects local applications to cloud storage while preserving a file, block or tape interface.
- S3 File Gateway exposes NFS/SMB file shares backed by S3 objects, with local caching. It is useful when an existing file-based workflow must use object storage without rewriting every client.
- Volume Gateway exposes iSCSI block volumes. Cached volumes keep primary data in AWS and cache frequently accessed data locally; stored volumes keep the full dataset locally and back it up to AWS.
- Tape Gateway presents a virtual tape library to existing backup software. It preserves the tape workflow while moving storage/archival responsibilities into AWS.
- A gateway provides an ongoing hybrid interface. It is not simply a one-time copying tool, and caching does not make network outages irrelevant.
- FSx File Gateway is no longer available to new customers. Do not confuse that restricted product with S3 File Gateway or FSx for Windows, which are separate services. Availability record
Distinguish transfer clients from migration jobs
- Transfer Family provides managed file-transfer capabilities such as SFTP, FTPS, FTP and AS2, with storage integration appropriate to the endpoint type. Use it when partners already speak a transfer protocol; it does not require them to adopt the S3 API.
- DataSync automates supported storage transfers, with task configuration, verification, scheduling and bandwidth controls. It is a strong fit for migrations and recurring synchronization rather than a general partner-facing SFTP login service. Agent requirements depend on the source/destination design. Transfer Family, DataSync
- Snow Family is the historical physical/offline transfer and edge-compute pattern: compare dataset size and available bandwidth before assuming a network transfer is feasible. Snowball Edge is closed to new customers; existing customers have separate availability and support timelines. This pack creates no physical jobs. Learn the architectural clue without assuming a new account can order devices. Product-specific availability notice
- Compare total cost: idle server/filesystem capacity, gateway infrastructure, transfer volume, requests and cross-AZ/Region traffic. “Managed” removes some operations work, not every charge.
Choose under exam pressure
| Requirement in the question | Best direction |
|---|---|
| Windows application requires SMB and AD | FSx for Windows |
| Parallel HPC processing of S3 datasets | FSx for Lustre |
| Preserve NetApp features and protocols | FSx for ONTAP |
| ZFS-oriented NFS migration | FSx for OpenZFS |
| Existing file shares need S3-backed hybrid access | S3 File Gateway |
| Existing backup software expects tape | Tape Gateway |
| Partners upload using SFTP | Transfer Family |
| Verified recurring bulk synchronization | DataSync |
Traps
- A protocol-compatible service can still have different availability, performance and feature limits.
- File Gateway, Volume Gateway and Tape Gateway preserve different client interfaces.
- A transfer endpoint moves or exposes data; it does not decide the authoritative storage and recovery strategy.
- EFS is not a universal Windows file share, and S3 is not a disk volume.
Active recall
1. A Windows application depends on AD-integrated SMB shares and NTFS permissions. Why not select EFS?
FSx for Windows directly matches those interfaces and semantics. EFS serves NFS/POSIX-style workloads; shared capacity alone does not establish compatibility.
2. A research cluster repeatedly processes a large S3 dataset with parallel file access. Which FSx family fits?
Lustre fits the high-throughput parallel filesystem requirement and S3 integration. Keep the durable dataset and computation tier's lifecycle distinct.
3. Backup software must continue writing to a virtual tape library. Would an iSCSI Volume Gateway be equivalent?
No. Tape Gateway presents the expected tape interface. Volume Gateway presents block volumes, which changes what the backup software sees.
4. Partners have SFTP clients, while an internal migration needs verified scheduled copies. Must one service solve both?
No. Transfer Family fits the partner protocol endpoint; DataSync fits managed transfer tasks. They address different interfaces and operating workflows.
5. An on-premises system must retain its whole primary dataset locally while backing up to AWS. Which Volume Gateway mode matches?
Stored volumes. Cached volumes instead prioritize AWS-resident primary data with a local cache of frequently used blocks; that changes the dependency on connectivity.
Terraform anchor: Separate storage resources from transfer identities, and scope bucket-level and object-level IAM actions to the correct ARN types.