AWS FSx
Amazon FSx provides fully managed, high-performance file systems. Choose from NetApp ONTAP, OpenZFS, Windows File Server, or Lustre for HPC workloads.
What is FSx? (Simple Explanation)
FSx is an AWS service in the Storage category. Amazon FSx provides fully managed, high-performance file systems.
When Would You Use FSx?
- Windows application migrations
- High-performance computing and ML
- Enterprise data management
- DevOps and CI/CD pipelines
Who Uses FSx?
From startups to enterprises, FSx powers:
What Makes FSx Powerful
FSx Pricing & Free Tier
Free Tier: 5GB Standard storage, 20,000 GET requests, 2,000 PUT requests (12 months). After that, ~$0.023/GB/month.
FSx Best Practices
- 1Block all public access by default (never grant s3:* to *)
- 2Enable versioning and MFA delete on critical buckets
- 3Use lifecycle policies to automatically tier to Glacier after 90 days
- 4Encrypt at rest with SSE-KMS (not SSE-S3)
- 5Enable S3 Access Logs or CloudTrail data events for audit trail
Getting Started with FSx in 5 Minutes
- 1Open the AWS Console and navigate to FSx
- 2Click "Create bucket" or "Create file system"
- 3Name your resource (globally unique for S3) and choose a region
- 4Configure public access settings (block all public access by default) and click "Create"
FSx CLI Quick Reference
2 production-ready commands. Full CLI Library (225+ services) →
aws fsx helpView all FSx CLI v2 commands and subcommandsaws fsx describe-fsx --helpView options for describing FSx resourcesPros & Cons of FSx
Pros
- FSx for Lustre — sub-ms latency, hundreds of GB/s throughput
- FSx for Windows — SMB protocol, AD integration
- FSx for NetApp ONTAP — multi-protocol, SnapMirror
- FSx for OpenZFS — ZFS snapshots and replication
Cons
- ✕Storage costs compound over time — data tends to grow, not shrink
- ✕Cross-region replication adds latency and egress costs
- ✕Inexperienced users can accidentally expose data publicly (misconfigured bucket policies)
FSx vs Alternatives
FSx vs EC2
Choose FSx for Windows application migrations and High-performance computing and ML. It excels at fsx for lustre — sub-ms latency, hundreds of gb/s throughput.
Choose EC2 as an alternative when your requirements differ. Each service in the Storage category serves different architectural patterns.
Services That Work with FSx
FSx is rarely used alone. It is typically combined with:
Compliance & Security
How AWS FSx fits into major compliance standards. Browse all 41 frameworks →
FSx configuration is audited by CIS Benchmarks v1.5–v3.0 for secure cloud defaults.
NIST 800-53FSx access controls, encryption, and audit logging map to NIST 800-53 AC, SC, and AU control families.
PCI DSS 4.0FSx encryption, access control, and logging support PCI DSS for cardholder data environments.
SOC 2FSx security, availability, and confidentiality controls evaluated under SOC 2 Trust Services Criteria.
ISO 27001FSx configuration and monitoring controls map to ISO 27001 Annex A information security management.
Frequently Asked Questions About FSx
What is AWS FSx?
Amazon FSx provides fully managed, high-performance file systems. Choose from NetApp ONTAP, OpenZFS, Windows File Server, or Lustre for HPC workloads.
What is FSx used for?
FSx is commonly used for: Windows application migrations; High-performance computing and ML; Enterprise data management; DevOps and CI/CD pipelines. It's a core service in the storage category of AWS.
Is FSx free?
Free Tier: 5GB Standard storage, 20,000 GET requests, 2,000 PUT requests (12 months). After that, ~$0.023/GB/month.
What are the key features of FSx?
FSx's most important capabilities include: FSx for Lustre — sub-ms latency, hundreds of GB/s throughput. FSx for Windows — SMB protocol, AD integration. FSx for NetApp ONTAP — multi-protocol, SnapMirror. FSx for OpenZFS — ZFS snapshots and replication. Each of these is designed to help teams windows application migrations.
How does FSx compare to alternatives?
FSx competes with both AWS-native alternatives (EC2, EKS, S3) and third-party equivalents. The right choice depends on your specific requirements for scalability, cost, and operational overhead. See the comparisons section below for detailed guidance.
Which compliance frameworks apply to FSx?
CIS AWS v3.0: FSx configuration is audited by CIS Benchmarks v1.5–v3.0 for secure cloud defaults. NIST 800-53: FSx access controls, encryption, and audit logging map to NIST 800-53 AC, SC, and AU control families. PCI DSS 4.0: FSx encryption, access control, and logging support PCI DSS for cardholder data environments. SOC 2: FSx security, availability, and confidentiality controls evaluated under SOC 2 Trust Services Criteria. ISO 27001: FSx configuration and monitoring controls map to ISO 27001 Annex A information security management.
People also search for
Was this page helpful?
Ready to secure your FSx configuration?
Pavora continuously monitors your AWS FSx for misconfigurations, compliance violations, and security risks.