Objects older than 90 days are failing to transition to Glacier cold tier

Siti Omar 20 Reputation points
2026-09-17T06:31:37.8266667+00:00

We have S3 buckets configured for long-term storage and objects older than 90 days are failing to transition to the Glacier cold tier. This started happening recently when I noticed our standard storage costs weren't dropping. I checked the lifecycle configurations thoroughly and see no indication of anything out of the ordinary. I also look at the specific bucket properties and see that my lifecycle rule is still enabled. I checked the bucket policies and no change.

I don't know how to debug lifecycle policy execution as the only thing that changed was a minor update to our bucket versioning settings a few weeks ago. I have tried reviewing CloudTrail and Server Access Logs to find out why the transition isn't triggering, but I see no clear errors. What should I do now? Any suggestions?

Windows for business | Windows 365 Enterprise
0 comments No comments

Answer accepted by question author
Jason Nguyen Tran 26,970 Reputation points Independent Advisor
2026-09-17T07:25:30.4933333+00:00

Hello Siti Omar,

When objects fail to transition to Glacier after 90 days, even though the lifecycle rule appears enabled, it usually points to either versioning changes or hidden conditions in the policy evaluation. Since you mentioned recently enabling bucket versioning, note that lifecycle rules apply differently to current and noncurrent object versions, so you may need to explicitly configure transitions for both.

The first step is to double-check the lifecycle configuration XML/JSON and confirm that the rule scope includes current versions. If versioning was turned on after the rule was created, the policy may only be applying to noncurrent versions. You can use the AWS CLI command aws s3api get-bucket-lifecycle-configuration to verify the exact rules being applied. Next, review CloudTrail for PutLifecycleConfiguration events to ensure no silent changes occurred.

To debug execution, enable S3 Lifecycle logging by checking the object’s status with aws s3api head-object and confirm whether the transition date is being calculated. If the transition is scheduled but not executed, check whether Glacier is blocked by bucket policies or KMS encryption settings. Sometimes, restrictive bucket policies prevent transition actions even if the lifecycle rule is valid.

As a best practice, test with a small bucket and a simplified lifecycle rule to confirm transitions work, then replicate the configuration to production. This helps isolate whether the issue is rule syntax, versioning, or policy conflicts.

I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.

Jason

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.