Build S3 cross-region replication rule configurations with filters, KMS encryption, RTC, and metrics.
Build S3 cross-region replication rule configurations with filters, KMS encryption, RTC, and metrics.
Required Fields
RoleRulesOutput will appear here...Build an S3 replication rule with combined prefix-and-tag filtering (Filter.And requires both to match), cross-account replication to a bucket owned by a different account, and S3 Replication Time Control (ReplicationTime with a 15-minute SLA) for predictable replication latency instead of S3's default best-effort timing (typically minutes, but with no formal guarantee). Enabling ExistingObjectReplication is what makes replication apply retroactively to objects that existed in the bucket before the rule was created, without it, a new replication rule only replicates objects uploaded after the rule takes effect, a very common source of 'why didn't my old objects replicate' confusion.
Always check whether a bucket already has objects before assuming a new replication rule covers everything, ExistingObjectReplication (or a one-time S3 Batch Replication job) is required for retroactive coverage, this is the single most common replication gap.
If the source bucket uses SSE-KMS, explicitly enable SseKmsEncryptedObjects in SourceSelectionCriteria and verify the replication IAM role has kms:Decrypt on the source key and kms:Encrypt on the destination key, a silently-skipped subset of objects due to this gap can go unnoticed for a long time since there's no obvious error.
Combining Prefix and Tags in Filter.And means both conditions must be true, an object matching the prefix but missing the required tag (or vice versa) simply doesn't replicate, verify your tagging pipeline actually applies the expected tag before assuming prefix-based coverage alone is sufficient.
The builder validates that Role and Rules resolve before accepting the JSON as a valid PutBucketReplication request, the fields S3 needs to know which IAM role performs replication and what rules govern it; it can't verify the replication role actually has the necessary permissions on both source and destination buckets/keys, that's only surfaced as replication failures once objects start (or fail to) replicate.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.