Skip to content

Prepare a bucket and use Object Lock

10 min · Screen: /storage · Needs: Permissions.Storage.Manage

  1. On Storage › Storage targets, open the target’s menu › Prepare bucket

  2. Enter an administrative key for the storage

    It is used for this preparation only and never stored. No platform key should have these rights.

  3. Tick Make a missing bucket with Object Lock if you want locking

    Object Lock can only be switched on when the bucket is created.

  4. Click Prepare the bucket

    The bucket is created if missing, versioning is switched on, and a rule removes unfinished uploads after 7 days. Each step shows the call it made and the result, verified with the target’s own keys.

Mode Who can delete a locked backup early Use it when
None Anyone with a delete key. The storage has no Object Lock - then keep a second copy elsewhere.
Governance (recommended) Only a key with a special bypass right - which no platform key should have. Almost always.
Compliance Nobody, not even the storage’s root account, until the date passes. Legal or regulatory retention. You type the bucket name to confirm.

Set the mode in the target’s Object Lock panel and click Apply. New artifacts, file indexes and manifests are then locked for the retention policy’s Object-lock days; keeping a backup longer for GFS extends its lock. Turning locking off leaves existing locks in place.

Writer

Puts and reads objects. Never deletes.

Pruner

Deletes exact versions when retention allows, and sets legal holds.

Reader

Reads for restores.

The panel’s Show the policies gives the three policies to attach to these keys. None of them may bypass governance retention or change the bucket’s configuration.