S3 bucket has incomplete multipart uploads consuming storage
- Severity
- Medium
- Service
- S3
- Check ID
- S3_INCOMPLETE_MULTIPART
What this check finds
Incomplete multipart uploads accumulate storage charges (at the bucket's storage class rate) indefinitely until explicitly aborted. They are never visible as objects but do appear on the bill. Common causes are interrupted uploads or application bugs that initiate but never complete multipart uploads.
Passing looks like: No incomplete S3 multipart uploads.
How to fix it
Abort incomplete multipart uploads.
AWS CLI
aws s3api list-multipart-uploads --bucket BUCKET_NAMEThen abort each one:
aws s3api abort-multipart-upload --bucket BUCKET_NAME --key KEY --upload-id UPLOAD_IDPrevent recurrence by adding a bucket lifecycle rule with AbortIncompleteMultipartUpload and DaysAfterInitiation: 7.
Names in capitals are placeholders for your own resource. Review a command before you run it.
AWS console
S3 → bucket → Management → Lifecycle rules → Create rule.
Compliance
This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs
More S3 checks
- HighInternet accessible S3 bucket via policy
- HighPublic grant to S3 bucket via ACL
- MediumS3 bucket does not require SSL/HTTPS for all requests
- LowS3 Block Public Access does not block all access types
- LowS3 Block Public Access is not enabled for the account
- LowS3 bucket does not have server-access logging enabled
- LowS3 bucket with versioning enabled does not have MFA delete configured
- LowVPC with private subnets has no S3 endpoint