AWS BucketBuddy
Browse, upload, download, and manage Amazon S3 objects directly from VS Code — without ever leaving your editor.
AWS BucketBuddy gives developers a visual S3 browser in the VS Code sidebar. Connect using any AWS CLI profile — standard credentials, SSO, assumed roles, or process credentials — and navigate your S3 buckets like a file explorer. Connect multiple profiles simultaneously to browse buckets across accounts side-by-side and copy objects between environments.
Publisher: Krish Kanchinadam · kkmohan
Website: getbucketbuddy.com
What it looks like
S3 Explorer
│
├── 🔵 work-profile | us-east-1 | 123456789012 (➡️ Go to bucket… is an inline icon on this row)
│ ├── 📁 prod-data us-east-1 (3)
│ │ ├── 📍 Path: s3://prod-data/
│ │ ├── 📂 configs/ (1)
│ │ │ ├── 📍 Path: s3://prod-data/configs/
│ │ │ ├── ⬆️ Back to bucket root
│ │ │ └── 📄 app.json 12.4 KB
│ │ ├── 📂 logs/
│ │ └── 📄 README.md 1.1 KB
│ └── 📁 staging-bucket us-east-1
│ └── 📄 deploy.zip 4.2 MB · GLACIER
│
├── 🟢 dev-profile | eu-west-1 | 987654321098
│ └── 📁 dev-assets eu-west-1
│ ├── 📂 builds/
│ └── (empty)
│
└── ➕ Connect another profile…
Version History (auto-updates on object selection)
└── README.md s3://prod-data/README.md
├── 2026-03-14 10:00 • LATEST 1.1 KB
└── 2026-03-10 09:00 0.9 KB
Features
| Feature |
Description |
| 🪣 Browse Buckets |
Lists all owned S3 buckets per profile. Cross-account buckets accessible directly by URL. |
| 📁 Navigate Folders |
Drill into S3 prefixes as folders — lazy-loaded with pagination. Breadcrumb + Up navigation shown inside each folder. |
| 👁️ Open in Editor |
Preview text, JSON, YAML, CSV, Markdown, and images inline in VS Code. File size warning before opening large files. Non-text content type banner shown when applicable. |
| ⬇️ Download |
Download any object or entire folder to a local path. Multi-select to download several objects at once. |
| ⬆️ Upload |
Upload local files into any bucket or prefix via file picker, or drag files from the OS file explorer. |
| 🗑️ Delete |
Delete objects or folders with an optional confirmation prompt. Multi-select for bulk delete. |
| ✏️ Rename / Move |
Copy to a new key then delete the original — single step. |
| 📁 Rename Folder |
Rename an entire folder — every object under its prefix is copied to the new prefix and the originals deleted, with a modal confirmation naming the object count first. |
| 📂 Create Folder |
Create a new folder (zero-byte prefix) directly from the tree. |
| 📄 Create File |
Create a new (empty) object directly from the tree, with overwrite confirmation. |
| 🪣 Create Bucket |
Create a new S3 bucket from within the extension. |
| 🔗 Copy S3 URI |
Copies s3://bucket/key to the clipboard. |
| 🌐 Pre-signed URL |
Generates a time-limited shareable HTTPS URL (5 min, 1 hr, or 24 hr). |
| 🖥️ Copy as AWS CLI |
Copies a ready-to-run aws s3 cp command for any object. |
| 🌀 Copy as curl |
Copies a pre-signed curl command for any object. |
| 🔗 Open in AWS Console |
Opens the object, folder, or bucket directly in the AWS Management Console. |
| 🔍 Search |
Search objects by prefix within any bucket or folder. |
| 🔃 Sort Objects |
Sort by name (asc/desc), last modified, or size. |
| 🔢 Object Counts |
Buckets and folders show item counts after expansion. |
| 📦 Storage Class |
Non-STANDARD storage class (GLACIER, DEEP_ARCHIVE, etc.) shown inline on objects. |
| 🕐 Version History |
Browse S3 object versions in a dedicated side panel — open, download, or restore any prior version. |
| 🖱️ Drag & Drop |
Drag S3 objects/folders between buckets, or drag local files from the OS file explorer into a bucket. |
| 👥 Multi-Profile |
Connect multiple AWS profiles simultaneously — browse side-by-side with colour-coded badges. |
| 🔄 Cross-Account Copy |
Copy objects between AWS accounts and environments — streams through client, no server-side copy required. |
| 🔁 Refresh Node |
Right-click any bucket or folder to refresh just that node without refreshing the full tree. |
| 💾 Persistent Sessions |
Connected profiles and pinned buckets are remembered across VS Code restarts. |
| ⚡ Eager Bucket Listing |
Buckets are fetched and the tree auto-expanded as soon as a profile connects — no manual click needed. |
| 🔒 Read-Only Lock |
Profiles and buckets default to locked (read-only) to prevent accidental changes — configurable via bucketbuddy.lockByDefault. Buckets show a green pencil (writable) or red padlock (locked) icon — the same colored icon appears both as the bucket's main icon and as the hover-revealed click target; profile rows are color-coded (red/green/amber) for their aggregate status. Click the lock icon to toggle. Locking a profile locks all its buckets unless a bucket is individually unlocked. |
| 🏷️ Environment Grouping |
Add env=DEV/Staging/Prod (or any custom value) to a profile in your AWS config, or right-click a profile → "Set Environment/Group…" to assign one without touching your config file. Each banner has its own Connect All / Disconnect All, scoped to just that group. |
| 🔐 Protected Profiles |
Mark profiles/buckets (by env or profile name pattern) as protected — they're skipped by "Unlock All," though still unlockable one at a time. |
| 📜 Activity Log |
Every write (upload, delete, rename, restore, copy, tag edit) is recorded with a timestamp in a dedicated output channel. |
| 🆚 Overwrite Diff Preview |
Overwrite confirmations show existing vs. incoming size/modified-date before you confirm. |
| 🏷️ Object Tags |
View, add, edit, or remove S3 object tags directly from the tree. |
| 🌐 Search All Buckets |
Search across every already-listed bucket for every connected profile in one command. |
| 🆚 Compare Versions |
Diff any two object versions side-by-side in VS Code's native diff editor. |
| ⏹️ Cancellable Transfers |
Multi-file downloads, uploads, folder downloads, folder deletes, and folder copies can be cancelled mid-operation. |
| 📋 Bucket Details |
Read-only view of a bucket's policy, encryption, lifecycle rules, and versioning status. |
| 🕘 Recent Objects |
Quickly reopen recently viewed objects from any connected profile. |
| ✍️ S3 Draft Editing |
Open a text object as an editable draft, then explicitly upload it with Save Active S3 Draft. Content type and user metadata are retained. |
| ℹ️ Object Properties |
Inspect object size, ETag, content type, cache-control, encryption, storage class, and custom metadata. |
| 🛡️ Permission Diagnostics |
Safely test read/list access for a bucket without creating, changing, or deleting any data. |
| 📊 Storage Insights |
Summarize object count and bytes by storage class for a bucket or prefix (up to 5,000 objects). |
| 📋 List All Files |
Right-click a bucket or folder → "List All Files…" for a plain-text listing (up to 5,000 objects) — choose recursive (every object under every subfolder) or this-folder-only. |
| 🔐 S3 Object Lock |
Display an object's retention and legal-hold state when the profile is authorized to read it. |
| 🔄 Configured Folder Sync |
Opt-in local-folder-to-S3 sync with include/exclude filters, preview-first workflow, cancellation, and optional remote deletion. |
| 🔖 Saved Searches & Paths |
Save reusable cross-bucket search queries and pin a bucket/folder path for one-click navigation. |
| 🚚 Transfer Queue |
View the active and recent BucketBuddy upload transfers in the current VS Code session. |
| 💵 Cost Estimate |
Estimate monthly storage cost by storage class for a bucket or prefix (up to 5,000 current objects). Clearly labelled as an advisory US Standard-region storage-only estimate. |
| 🧹 Multipart Cleanup |
Preview incomplete multipart uploads, then explicitly abort them to release uploaded parts. |
| 🧭 IAM Action Guidance |
Permission diagnostics identify denied read/list checks and point to the smallest common IAM action to review, without testing writes. |
| 🌐 CloudFront Invalidations |
Create an explicit, confirmed CloudFront invalidation for an object, prefix, or bucket path using the connected AWS profile. |
| ✅ Checksum Verification |
Download an object with S3 checksum mode and verify its SHA-256 checksum when the bucket exposes one. |
| 🛠️ Bulk Object Properties |
Apply a Cache-Control or Content-Type value to selected objects with a final confirmation; existing custom metadata is retained. |
| 📣 Event Notifications |
Read a bucket’s Lambda, SQS, SNS, and EventBridge notification configuration without leaving VS Code. |
| ⭐ Rate on Marketplace |
An occasional, unobtrusive prompt after real usage (10+ activations, 7+ days) asks if you'd rate BucketBuddy — snoozeable or dismissible for good, and always available manually via "Rate AWS BucketBuddy on the Marketplace" in the Command Palette. |
| 📧 Send Feedback |
"Send Feedback / Report a Bug" in the Command Palette opens a pre-filled email draft (version/OS included) — nothing is sent until you do. |
Configured Folder Sync
Folder sync is deliberately opt-in. Add named mappings in VS Code Settings, then run
BucketBuddy: Sync Configured Folder…. Every run opens a preview and requires an
explicit Apply Sync confirmation. Remote deletion is disabled by default.
"bucketbuddy.folderSyncMappings": [
{
"name": "Website assets → staging",
"localPath": "${workspaceFolder}/public",
"profile": "staging",
"bucket": "my-staging-assets",
"prefix": "web/",
"include": ["*"],
"exclude": ["*.map", ".DS_Store"],
"deleteRemote": false
}
]
The target bucket must be unlocked. Sync only transfers files selected by the filters;
it does not watch folders or run automatically.
Getting Started
1. Install
Install from the VS Code Marketplace — search for AWS BucketBuddy in the Extensions panel, or visit getbucketbuddy.com.
BucketBuddy uses your existing AWS CLI profiles. If you haven't set one up:
aws configure
# or for SSO:
aws configure sso
Click the BucketBuddy icon in the Activity Bar. On first launch, the extension
automatically connects every AWS profile found in your ~/.aws/credentials and
~/.aws/config files — no manual setup needed. Each profile appears as its own
colour-coded root node with its configured buckets already pinned.
On subsequent launches, BucketBuddy restores the exact set of profiles that were
active when VS Code last closed (respecting any profiles you manually disconnected).
4. Browse or go to a bucket
- Owned buckets are listed and the tree auto-expanded as soon as a profile connects, if your
credentials have
s3:ListAllMyBuckets — no manual click needed
- Pre-configured buckets from
buckets= in your AWS config are pinned immediately
- Direct access — click the "Go to bucket…" icon on a profile row (or right-click → Go to Bucket…) and enter a bucket name or
s3:// URL
- Every bucket starts locked (read-only) — see Read-Only Lock below
5. Connect an additional profile
Click the + icon in the panel header and select a profile. It appears as a new
root node — each session has a distinct colour badge for easy identification.
Auto-Connect Buckets
Add a buckets= field to your AWS config and BucketBuddy will automatically pin those buckets
when you connect the profile — no manual "Go to bucket…" needed each time:
[MyProfile]
aws_access_key_id = ...
aws_secret_access_key = ...
region = us-east-1
account_id = 123456789012
buckets = prod-data, staging-bucket, my-logs
env = DEV
The account_id field is also shown in the profile header for easy identification. env groups
this profile under a "DEV" banner alongside every other profile that also sets env=DEV — see
Environment Grouping below.
Environment Grouping
Add an env= field to any profile in your AWS config to group similar profiles under a banner —
DEV, Staging, Prod, or any name you choose:
[dev-a]
env = DEV
[dev-b]
env = DEV
[prod-main]
env = Prod
Profiles sharing the same env value are grouped under one banner at the root of the tree.
Recognized names (dev, staging, prod) are sorted first; other custom values sort
alphabetically; profiles with no env set are grouped last under "Other". If you never set env
on any profile, the tree renders flat exactly as before — this is fully opt-in.
Prefer not to edit your AWS config? Right-click any profile → "Set Environment/Group…" to
assign it a group directly from the tree. This is stored locally by BucketBuddy only — it never
reads or writes your ~/.aws/config file — and always wins over that file's env= value if both
are set. Pick "Clear override" to fall back to whatever the config file says (or ungrouped, if
nothing is set there either).
Read-Only Lock
Every profile and bucket starts locked (read-only) to prevent accidental changes —
especially useful for production accounts. Right-click a profile or bucket and choose
Unlock (Allow Edits) to make it writable, or hover the row and click its lock icon (red closed
padlock while locked, green icon while unlocked — a pencil for buckets, an open padlock for
profiles); choose Lock (Read-Only) to re-lock it.
Buckets show that same red-padlock/green-pencil icon as their permanent main icon too, so
status is visible without even hovering. Profile rows are color-coded instead (red = locked,
green = unlocked, amber = mixed) since a profile's status is really an aggregate over all of its
known buckets, not just its own setting — amber means some of its buckets are unlocked and some
aren't, so you're never guessing whether "locked" on the profile means every bucket underneath it
is locked too.
- Locking a profile locks every bucket under it, unless a bucket has been individually unlocked.
- Unlocking a single bucket overrides its profile's lock for that bucket only.
- Attempting a write (upload, delete, rename, create folder/file, restore version, copy-in) on a
locked target shows a warning with an "Unlock Now" button — it only unlocks; you'll need to
retry the action afterward, so a single click can never both unlock and delete/overwrite.
- Lock state is remembered across VS Code restarts and across every workspace.
- The default for anything you haven't explicitly locked/unlocked yet is controlled by
bucketbuddy.lockByDefault (default true). Set it to false if you'd rather new profiles and
buckets start unlocked — existing explicit choices per profile/bucket are never affected either way.
Bulk actions: the toolbar has Lock All Profiles and Unlock All Profiles. Unlock All
requires confirmation and skips any protected profile (see below) — you'll be told which ones
were skipped and can still unlock them individually.
Protected profiles: add glob patterns to bucketbuddy.protectedEnvPatterns (default
["prod*", "production*"], matched against a profile's env= value) or
bucketbuddy.protectedProfilePatterns (matched against the profile name) to mark certain
profiles/buckets as protected. Protection only changes what Unlock All does — a protected
item is excluded from that bulk action (hover its tooltip to see why), but the individual
lock/unlock toggle always still works on it, one at a time.
Activity log: every successful write is recorded — action, profile, bucket, and detail — in a
dedicated BucketBuddy Activity output channel. Open it from the toolbar's Show Activity Log
button.
Direct Bucket Access
No s3:ListAllMyBuckets permission? No problem. Use Go to bucket… to navigate directly
to any bucket by name or s3:// URL — even cross-account buckets your credentials have been
explicitly granted access to. BucketBuddy validates the bucket is accessible before confirming.
Version History Panel
Click any S3 object — a dedicated Version History panel updates automatically showing all
versions and delete markers. From the panel you can:
- Open any prior version in the VS Code editor
- Download a specific version
- Restore a prior version (promotes it to LATEST via a copy)
Requires the bucket to have versioning enabled.
Cross-Account Object Copy
Right-click any object → Copy to Another Profile…
- Select the target profile (e.g. staging, prod)
- Enter the target bucket name
- Confirm (or edit) the target key
The object streams from the source account through VS Code to the target account — no server-side
copy required, so it works seamlessly across AWS accounts, environments, and regions.
Panel Header Buttons
| Icon |
Action |
| ℹ️ |
Open About page |
| 🔄 |
Refresh the tree |
| ➕ |
Connect a new profile session |
| 🪣+ |
Go to bucket by name or URL |
| 🔍 |
Search objects |
| 🔌 |
Connect all profiles (reconnects any disconnected profiles) |
| ⏏️ |
Disconnect all profile sessions |
| 🌐 |
Search all already-listed buckets across every connected profile |
| 🕘 |
Recent Objects — reopen a recently viewed object |
| 🔒 |
Lock All Profiles |
| 🔓 |
Unlock All Profiles (skips protected profiles, with confirmation) |
| 📜 |
Show Activity Log |
| 🔄 |
Sync Configured Folder — runs an opt-in mapping from bucketbuddy.folderSyncMappings |
| 🔖 |
Saved Searches — replay a saved cross-bucket search |
| 📑 |
Saved Bucket Paths — jump to a bookmarked profile/bucket/prefix |
Context Menu Actions
On a profile session node:
- Go to Bucket…
- Disconnect Profile
- Create Bucket
- Set Environment/Group…
- Lock (Read-Only) / Unlock (Allow Edits)
On an environment/group banner:
- Connect All in Group
- Disconnect All in Group
On a bucket:
- Upload File
- Create Folder
- Create File…
- Refresh Node
- Search Objects
- Copy S3 URI
- Open in AWS Console
- Download Folder
- Delete Folder
- Copy Folder…
- View Bucket Details
- Storage Insights
- List All Files…
- Run Permission Diagnostics
- Save Bucket Path…
- Lock (Read-Only) / Unlock (Allow Edits)
On a folder:
- Upload File
- Create Folder
- Create File…
- Refresh Node
- Search Objects
- Copy S3 URI
- Open in AWS Console
- Download Folder
- Delete Folder
- Copy Folder…
- Rename Folder…
- Storage Insights
- List All Files…
- Save Bucket Path…
On an object:
- Open in Editor
- Edit Object…
- Download
- Copy S3 URI
- Copy Pre-signed URL
- Copy as AWS CLI Command
- Copy as curl Command
- Open in AWS Console
- Rename / Move
- Copy to Another Profile…
- View/Edit Tags…
- View Object Properties
- View Object Lock
- Version History
- Delete
On a version (Version History panel):
- Open Version
- Download Version
- Compare with…
- Restore Version
Settings
| Setting |
Default |
Description |
bucketbuddy.defaultProfile |
"default" |
Declared in extension settings, but not currently used by startup logic |
bucketbuddy.credentialsFilePath |
"" |
Override path to ~/.aws/credentials |
bucketbuddy.configFilePath |
"" |
Override path to ~/.aws/config |
bucketbuddy.maxItems |
500 |
Max items loaded per list operation |
bucketbuddy.confirmBeforeDelete |
true |
Show confirmation dialog before deleting objects |
bucketbuddy.defaultBucket |
"" |
Declared in extension settings, but not currently used for automatic navigation |
bucketbuddy.sortMode |
"nameAsc" |
Object sort order: nameAsc, nameDesc, lastModifiedDesc, sizeDesc |
bucketbuddy.lockByDefault |
true |
Whether a profile/bucket with no explicit choice yet starts locked (true) or unlocked (false) |
bucketbuddy.protectedEnvPatterns |
["prod*", "production*"] |
Glob patterns matched against a profile's env= value; matches are excluded from Unlock All |
bucketbuddy.protectedProfilePatterns |
[] |
Glob patterns matched against the profile name itself; same effect as above |
bucketbuddy.folderSyncMappings |
[] |
Opt-in local-folder → S3 sync mappings; see Configured Folder Sync above |
Multiple Profiles Simultaneously
Connect as many AWS profiles as you need — each appears as a collapsible root node with a
distinct color badge (🔵 🟢 🟡 🟣 🟠 🔴) and shows the region and account ID from your config.
Useful when:
- You have buckets spread across dev, staging, and production accounts
- You need to compare or migrate objects between AWS accounts
- Your IAM role grants direct bucket access but not
ListAllMyBuckets
Add a session: click + in the panel header, or ➕ Connect another profile… at the bottom
Connect all: click the plug icon in the panel header to reconnect every profile at once
Remove a session: right-click the profile node → Disconnect Profile
Disconnect all: click the disconnect button in the panel header
First launch: all profiles in ~/.aws/credentials + ~/.aws/config are connected automatically.
Subsequent launches: restores the profiles that were active when VS Code last closed.
Sessions and pinned buckets are persisted — they reconnect automatically when you reopen VS Code.
Security
- No credentials stored. BucketBuddy never persists access keys anywhere. Only profile names (plain strings) are saved across sessions.
- No network calls from WebViews. All AWS API calls run in the VS Code extension host.
- Credential chain per session:
fromIni() → fromSSO() → fromProcess() — restricted to the selected AWS profile so ambient environment credentials cannot silently override it.
Requirements
- VS Code 1.85.0 or later
- AWS CLI configured with at least one profile (
aws configure)
- Node.js is not required — the extension bundles all dependencies
⚠️ Data Loss Warning
This extension performs live operations directly against Amazon S3. Object deletions are
permanent and irreversible unless versioning is enabled on the bucket. Sarvatix Solutions accepts
no responsibility for any accidental, inadvertent, or unintended deletion, modification, or
loss of data. Use at your own risk. Always ensure critical buckets have versioning enabled
and maintain independent backups.
License
Proprietary. Copyright © 2026 Sarvatix Solutions. All rights reserved.
See LICENSE file for full terms.
| |