Skip to content
Article

What Is Object Storage? How It Differs from Block and File Storage

Object storage keeps data with its ID and metadata in a flat namespace. How it differs from block and file storage, S3 compatibility and its role in backup.

Oğuzhan Gerçek··7 min read
What Is Object Storage? How It Differs from Block and File Storage

Short answer: Object storage is a storage model that keeps data as "objects" rather than in a folder hierarchy or in disk blocks. Each object consists of the data itself, metadata describing it and a unique ID, and it sits in a flat namespace. Objects are accessed over HTTP through an API, most commonly the Amazon S3 API. It scales almost without limit and is cheap per unit of capacity. It suits backups, archives, media and large volumes of unstructured data, and not for latency-sensitive work such as databases.

What is object storage?

SNIA (the Storage Networking Industry Association) defines object storage as a model in which data is stored as uniquely identifiable, indivisible objects. Each object carries its ID and its metadata. There are no nested folders as in a file system; all objects sit in a flat structure and are found by their IDs. Access goes not through a file system but through simple APIs that work over HTTP.

Three concepts come up in everyday use:

  • Bucket: The logical container objects live in. Access permissions, retention rules and versioning are usually defined at bucket level.
  • Key: The object's name within the bucket. A key such as backups/2026/10/server01.vbk looks like a folder path, but it is actually a flat name.
  • Metadata: System information such as size and date, plus tags the user adds. Search, classification and retention rules work off these tags.

Block vs file vs object storage

  • Block storage: Attaches to a server like a raw disk (SAN, iSCSI, Fibre Channel). The operating system formats that disk with its own file system. It is the lowest-latency model; databases and virtual machine disks run on it.
  • File storage: Keeps data in a folder hierarchy and shares it over the network (NAS, NFS, SMB). Suited to common file shares where several users or servers access the same files.
  • Object storage: Accessed over an HTTP API, with a flat namespace and rich metadata. It scales best in both capacity and object count; on the other hand, changing an object usually means rewriting all of it.

That last point matters in practice: because objects are indivisible units, updating a few bytes in the middle of a large file cannot be done in place as it can on block storage. Object storage therefore suits data that is written once and read many times, or never changes, rather than data that changes frequently.

How does object storage work?

Object storage systems spread data across many servers. There are two ways to make it durable:

  • Replication: Several full copies of each object are kept on different servers. Simple, but expensive in capacity.
  • Erasure coding: Data is split into K chunks and M coding chunks are added; even if any M chunks are lost, the data can be rebuilt. According to the Ceph documentation, at scale erasure coding saves capacity compared with replication.

Amazon S3 shows best how far the scale goes. Launched on March 14, 2006, S3 stores more than 500 trillion objects in its 20th year and serves more than 200 million requests per second. Over the same period its price per GB fell from 15 cents to just over 2 cents, a drop of about 85%. AWS expresses S3's annual durability design target as "eleven nines"; except for the One Zone classes, which keep data in a single Availability Zone, objects are stored across at least three Availability Zones.

What does S3-compatible storage mean?

S3 started as Amazon's own service; over time its API became the common language of object storage. An "S3-compatible" system is storage that speaks the same API, so software written for S3 can connect to it. That lets backup software, data lakes and applications work through the same interface whether the data sits in AWS or in your own data center.

One common way to build S3-compatible storage on your own infrastructure is open-source Ceph. Ceph delivers block, file and object storage in one system; its object layer, the Ceph Object Gateway, is compatible with a large subset of the S3 and OpenStack Swift APIs. That wording holds an important detail: compatibility is not always complete. Test that the API calls your software needs are supported before going live.

Immutable backups against ransomware

The most valuable object storage feature for backup is Object Lock. In Amazon S3, Object Lock applies a WORM (write once, read many) model that prevents an object from being deleted or overwritten for a set period. In compliance mode, nobody, including the root account, can remove the lock. According to AWS documentation, the feature has been assessed by Cohasset Associates for use in environments subject to SEC 17a-4, CFTC and FINRA rules.

Many S3-compatible systems offer the same capability: Red Hat Ceph Storage supports S3 Object Lock in its object layer. On the backup side, Veeam can keep backups written to a bucket with Object Lock enabled immutable for a chosen period of 1 to 999 days. Even if ransomware takes over an administrator account, it cannot delete the backups before that period ends. We cover the recovery side in our ransomware recovery playbook and the basics of backup in our backup article.

When is object storage the wrong choice?

  • Latency-sensitive work: Databases and virtual machine disks expect sub-millisecond latency; they belong on block storage.
  • Small files that change often: In workloads where a file is constantly updated in small pieces, every change means rewriting the object.
  • Legacy applications that expect a file system: Applications that rely on file system behavior such as folder structure, file locking and permissions cannot move to object storage directly.

Object storage in Türkiye: where does the data live?

When you use public cloud object storage, the first question is the region. Personal data written to a bucket in a region abroad counts as a cross-border transfer under the KVKK (Türkiye's personal data protection law), and that includes backups and logs. See our KVKK article for details. For organizations with a data residency requirement, the option is S3-compatible object storage built in a data center inside the country: the software uses the same API, and the data never leaves Türkiye.

Frequently asked questions

What does object storage mean? A storage model that keeps data as objects, each with its ID and metadata, in a flat namespace, accessed over an HTTP API.

Is object storage the same as cloud storage? Not exactly. Cloud storage is a service model: renting storage over the internet. Object storage is a technical model. Most cloud storage services are object storage, but object storage can also be built in your own data center.

What is S3? The object storage service Amazon launched in 2006: Simple Storage Service. Its API became the common interface of object storage over time; S3-compatible systems support the same API.

Is object storage suitable for backup? Yes; most backup software supports object storage as a target. It scales cheaply and can hold immutable backups with Object Lock, which makes it a good fit for a second copy protected against ransomware.

What is erasure coding? A method that splits data into chunks and adds coding chunks, so the data can be rebuilt even if some chunks are lost. It uses less capacity than full replication.

Sources