That doesn't work, the standard endpoint always remains available.
I assume random names are the only way forward. Unfortunately a bucket name can’t be longer than 63 characters.
You can stuff >256 bits into 56 BASE32 digits. The 63 character limit seems like it would only be constraining if humans want meaningful bucket names.
Surprising people are not already doing this. Something that has been beat into me for at least a decade.
> Other than deleting the bucket, there’s nothing you can do to prevent it. You can’t protect your bucket with services like CloudFront or WAF when it’s being accessed directly through the S3 API.
You can't protect your bucket with CloudFront if it's being access using S3 api.