Writer
Puts and reads objects. Never deletes.
On Storage › Storage targets, open the target’s menu › Prepare bucket
Enter an administrative key for the storage
It is used for this preparation only and never stored. No platform key should have these rights.
Tick Make a missing bucket with Object Lock if you want locking
Object Lock can only be switched on when the bucket is created.
Click Prepare the bucket
The bucket is created if missing, versioning is switched on, and a rule removes unfinished uploads after 7 days. Each step shows the call it made and the result, verified with the target’s own keys.
| Mode | Who can delete a locked backup early | Use it when |
|---|---|---|
| None | Anyone with a delete key. | The storage has no Object Lock - then keep a second copy elsewhere. |
| Governance (recommended) | Only a key with a special bypass right - which no platform key should have. | Almost always. |
| Compliance | Nobody, not even the storage’s root account, until the date passes. | Legal or regulatory retention. You type the bucket name to confirm. |
Set the mode in the target’s Object Lock panel and click Apply. New artifacts, file indexes and manifests are then locked for the retention policy’s Object-lock days; keeping a backup longer for GFS extends its lock. Turning locking off leaves existing locks in place.
Writer
Puts and reads objects. Never deletes.
Pruner
Deletes exact versions when retention allows, and sets legal holds.
Reader
Reads for restores.
The panel’s Show the policies gives the three policies to attach to these keys. None of them may bypass governance retention or change the bucket’s configuration.