AWS Snowball
AWS Snowball is a petabyte-scale data transport solution using physical ruggedized devices for offline data transfer into and out of AWS.
What is Snowball? (Simple Explanation)
Snowball is an AWS service in the Storage category. AWS Snowball is a petabyte-scale data transport solution using physical ruggedized devices for offline data transfer into and out of AWS.
When Would You Use Snowball?
- Large-scale data migration
- Data center decommissioning
- Disaster recovery seeding
- Remote site data collection
Who Uses Snowball?
From startups to enterprises, Snowball powers:
What Makes Snowball Powerful
Snowball Pricing & Free Tier
Free Tier: 5GB Standard storage, 20,000 GET requests, 2,000 PUT requests (12 months). After that, ~$0.023/GB/month.
Snowball Best Practices
- 1Block all public access by default (never grant s3:* to *)
- 2Enable versioning and MFA delete on critical buckets
- 3Use lifecycle policies to automatically tier to Glacier after 90 days
- 4Encrypt at rest with SSE-KMS (not SSE-S3)
- 5Enable S3 Access Logs or CloudTrail data events for audit trail
Getting Started with Snowball in 5 Minutes
- 1Open the AWS Console and navigate to Snowball
- 2Click "Create bucket" or "Create file system"
- 3Name your resource (globally unique for S3) and choose a region
- 4Configure public access settings (block all public access by default) and click "Create"
Snowball CLI Quick Reference
2 production-ready commands. Full CLI Library (225+ services) →
aws snowball helpView all Snowball CLI v2 commands and subcommandsaws snowball describe-snowball --helpView options for describing Snowball resourcesPros & Cons of Snowball
Pros
- 80 TB Snowball Edge Storage Optimized
- 100 TB Snowball Edge Compute Optimized with GPU
- Built-in 256-bit KMS encryption
- Tamper-resistant enclosure with TPM
- E Ink shipping label
Cons
- ✕Storage costs compound over time — data tends to grow, not shrink
- ✕Cross-region replication adds latency and egress costs
- ✕Inexperienced users can accidentally expose data publicly (misconfigured bucket policies)
Snowball vs Alternatives
Snowball vs S3
Choose Snowball for Large-scale data migration and Data center decommissioning. It excels at 80 tb snowball edge storage optimized.
Choose S3 as an alternative when your requirements differ. Each service in the Storage category serves different architectural patterns.
Services That Work with Snowball
Snowball is rarely used alone. It is typically combined with:
Compliance & Security
How AWS Snowball fits into major compliance standards. Browse all 41 frameworks →
Snowball configuration is audited by CIS Benchmarks v1.5–v3.0 for secure cloud defaults.
NIST 800-53Snowball access controls, encryption, and audit logging map to NIST 800-53 AC, SC, and AU control families.
PCI DSS 4.0Snowball encryption, access control, and logging support PCI DSS for cardholder data environments.
SOC 2Snowball security, availability, and confidentiality controls evaluated under SOC 2 Trust Services Criteria.
ISO 27001Snowball configuration and monitoring controls map to ISO 27001 Annex A information security management.
Frequently Asked Questions About Snowball
What is AWS Snowball?
AWS Snowball is a petabyte-scale data transport solution using physical ruggedized devices for offline data transfer into and out of AWS.
What is Snowball used for?
Snowball is commonly used for: Large-scale data migration; Data center decommissioning; Disaster recovery seeding; Remote site data collection. It's a core service in the storage category of AWS.
Is Snowball free?
Free Tier: 5GB Standard storage, 20,000 GET requests, 2,000 PUT requests (12 months). After that, ~$0.023/GB/month.
What are the key features of Snowball?
Snowball's most important capabilities include: 80 TB Snowball Edge Storage Optimized. 100 TB Snowball Edge Compute Optimized with GPU. Built-in 256-bit KMS encryption. Tamper-resistant enclosure with TPM. E Ink shipping label. Each of these is designed to help teams large-scale data migration.
How does Snowball compare to alternatives?
Snowball competes with both AWS-native alternatives (S3, Glacier, KMS) and third-party equivalents. The right choice depends on your specific requirements for scalability, cost, and operational overhead. See the comparisons section below for detailed guidance.
Which compliance frameworks apply to Snowball?
CIS AWS v3.0: Snowball configuration is audited by CIS Benchmarks v1.5–v3.0 for secure cloud defaults. NIST 800-53: Snowball access controls, encryption, and audit logging map to NIST 800-53 AC, SC, and AU control families. PCI DSS 4.0: Snowball encryption, access control, and logging support PCI DSS for cardholder data environments. SOC 2: Snowball security, availability, and confidentiality controls evaluated under SOC 2 Trust Services Criteria. ISO 27001: Snowball configuration and monitoring controls map to ISO 27001 Annex A information security management.
People also search for
Was this page helpful?
Ready to secure your Snowball configuration?
Pavora continuously monitors your AWS Snowball for misconfigurations, compliance violations, and security risks.