1---2name: storage3description: Choose and architect storage systems for applications with the right tradeoffs.4---5
6## Object vs Block vs File
7
8- Object storage (S3, R2, GCS) for immutable blobs: images, videos, backups, logs — cheap, scales infinitely, but no partial updates
9- Block storage (EBS, Persistent Disks) for databases and apps needing filesystem semantics — faster, but tied to single instance
10- Network file systems (NFS, EFS) when multiple instances need shared filesystem access — convenient but latency and cost add up
11- Default to object storage for user uploads — block storage for database files only
12
13## When SQL vs NoSQL
14
15- SQL when you need joins, transactions, or complex queries — fighting against NoSQL for relational data wastes months
16- Document stores (MongoDB, Firestore) for nested/variable schemas where you always fetch the whole document
17- Key-value (Redis, DynamoDB) for simple lookups by ID at massive scale — not for complex queries
18- Time-series databases (InfluxDB, TimescaleDB) for metrics with timestamp-based queries — regular SQL struggles with retention policies
19- Start with PostgreSQL unless you have a specific reason not to — it handles JSON, full-text search, and scales further than most assume
20
21## Local vs Cloud Storage
22
23- Local disk for ephemeral data: temp files, build artifacts, caches — assume it disappears on restart
24- Cloud storage for anything that must survive instance termination — never store user data only on local disk
25- Local SSD for databases in production — network-attached storage adds latency to every query
26- Hybrid: local cache in front of cloud storage for frequently accessed files
27
28## CDN Patterns
29
30- Put CDN in front of static assets always — origin requests are slower and more expensive
31- Set long cache TTLs with versioned URLs (`style.abc123.css`) — cache invalidation is slow and unreliable
32- CDN for dynamic content only if latency matters more than freshness — adds complexity for marginal gains
33- Edge caching for API responses works but cache keys get tricky — start simple, add only when needed
34
35## Upload Handling
36
37- Never accept uploads directly to app server disk in production — use presigned URLs to cloud storage
38- Set file size limits at load balancer level, not just application — prevents memory exhaustion attacks
39- Generate unique keys for uploads (UUIDs) — user-provided filenames cause collisions and path traversal risks
40- Validate file types by content (magic bytes), not extension — extensions are trivially spoofed
41
42## Data Locality
43
44- Keep compute and storage in same region — cross-region data transfer adds latency and cost
45- Replicate data to regions where users are, not where developers are
46- Multi-region storage adds complexity — single region with backups elsewhere usually sufficient
47- Database read replicas in user regions for read-heavy workloads
48
49## Retention and Lifecycle
50
51- Define retention policy before storing data — "keep everything" becomes expensive and legally risky
52- Automate deletion of temporary data — manual cleanup never happens consistently
53- Tiered storage for aging data: hot → warm → cold → archive — but check retrieval costs before archiving
54- Separate storage for logs vs business data — different retention, different compliance requirements
55
56## Cost Traps
57
58- Egress fees dominate cloud storage costs — calculate before choosing provider
59- Many small files cost more than few large files — batch small writes when possible
60- Minimum storage duration on cold tiers — early deletion still charges full period
61- API request costs matter at scale — millions of LIST operations add up
62
63## Backup Strategy
64
65- 3-2-1 rule: 3 copies, 2 different media types, 1 offsite — cloud counts as one location
66- Test restores regularly — untested backups are not backups
67- Point-in-time recovery for databases — daily snapshots lose a day of data
68- Version important files — deletion or corruption often discovered late