AWS EFS
Amazon Elastic File System (EFS) provides a simple, scalable, shared file system for Linux workloads. It grows and shrinks automatically as files are added and removed, and thousands of clients can mount it at the same time over the NFS v4 protocol.
Key concepts #
- File system with mount targets: one network interface per subnet (one per Availability Zone), with its own security group that must allow NFS (TCP 2049) from the clients.
- Regional file systems store data redundantly in several Availability Zones; One Zone file systems cost less and keep it in a single zone.
- Performance modes (General Purpose, Max I/O) and throughput modes (Elastic, Provisioned, Bursting).
- Storage classes and lifecycle management move files not accessed for a while to cheaper classes (Infrequent Access, Archive).
- Access points enforce a user and a root directory per application, and IAM policies can control mounting. Data is encrypted at rest with KMS and in transit with TLS.
- Used by EC2, ECS, Fargate, EKS and Lambda.
EBS, EFS or S3? #
| Access | Use | |
|---|---|---|
| EBS | One instance (block device) | Boot volumes and databases |
| EFS | Many Linux clients (file system) | Shared files, content management, home directories |
| S3 | HTTP API (objects) | Backups, static files, data lakes |
Pricing #
Per GB stored per month (depending on the storage class) plus throughput charges in some modes. See the EFS pricing.
With Terraform #
The resources are aws_efs_file_system, aws_efs_mount_target, aws_efs_access_point and aws_efs_file_system_policy.
See tutorials: