Object Lock
Object Lock uses the WORM (Write Once Read Many) principle and allows you to lock objects to prevent them from being overwritten or deleted.
To use Object Lock, the bucket must have versioning enabled. Object lock applies only to object versions.
Locking can be of different types and modes. Depending on the lock type, it can be set on individual objects or on a bucket by default — the lock will apply to new objects.
The ability to manage locks also depends on the user role and bucket policy rules; for details, see the Manage access to S3 manual. You can work with Object Lock in the control panel (capabilities are limited), via the S3 API, and via tools that use it, such as the AWS CLI.
To manage object locking after configuring Object Lock, use the Manage object locking manual.
If you delete a project that contains locked objects, they will not be deleted while the lock is active. However, they will not be displayed in the control panel and via the API. To restore locked objects after deleting a project, submit a ticket.
Types and retention modes
Locking can be temporary or indefinite. Temporary locking has two modes: Governance and Compliance.
If both a temporary and an indefinite lock are enabled for an object, the indefinite lock takes precedence.
* Available only to users:
- with the
memberrole; - with other roles with access to S3 if the bucket has a bucket policy that allows the action
s3:BypassGovernance.
Enable Object Lock in a bucket
Object Lock can be enabled by:
- Account Owner;
- users with the roles
member,s3.admin, andobject_storage:admin; - users with the roles
s3.bucket.user,s3.user, andobject_storage_userif the bucket policy allows them the actions3:PutBucketObjectLockConfiguration.
Once you enable Object Lock, you cannot disable it or suspend versioning.
Enabling Object Lock does not lock objects automatically. After configuring Object Lock in a bucket, you will be able to:
- manage object locking;
- upload objects with active locking right away (only via the S3 API and tools that use it);
- manage default retention in a bucket.
Control panel
AWS CLI
If versioning is disabled or suspended in a bucket, it will be enabled automatically when Object Lock is enabled.
-
In the Control panel, in the top menu, click Products and select S3.
-
Go to Buckets.
-
Open the bucket page → Configuration tab.
-
In the Data protection block, in the Object Lock line, click Edit.
-
Select the Enable Object Lock checkbox.
-
Optional: enable default retention in the bucket:
6.1.Select the Enable default retention checkbox.
6.2.Select a lock mode.
6.3.Specify the lock duration. The maximum lock duration is:
- for Compliance mode — one year. To set a Compliance lock for more than one year, use the API or tools, such as AWS CLI;
- for Governance mode — 100 years.
You can manage default retention even after enabling Object Lock.
-
Click Save.
Managing default retention in a bucket
Default retention can be managed by:
- Account Owner;
- users with the roles
member,s3.admin, andobject_storage:admin; - users with the roles
s3.bucket.user,s3.user, andobject_storage_userif the bucket policy allows them the corresponding actions.
Enable default retention
The temporary lock will be applied to all new objects in the bucket.
Control panel
AWS CLI
-
In the Control panel, in the top menu, click Products and select S3.
-
Go to Buckets.
-
Open the bucket page → Configuration tab.
-
In the Data protection block, in the Object Lock line, click Edit.
-
Make sure that the Enable Object Lock checkbox is selected.
-
Select the Enable default retention checkbox.
-
Select a lock mode.
-
Specify the lock duration. The maximum lock duration is:
- for Compliance mode — one year. To set a Compliance lock for more than one year, use the API or tools, such as AWS CLI;
- for Governance mode — 100 years.
-
Click Save.
Change default retention duration
If the lock mode is:
- Governance — the lock duration can be shortened or extended;
- Compliance — the lock duration can only be extended.
Control panel
AWS CLI
-
In the Control panel, in the top menu, click Products and select S3.
-
Go to Buckets.
-
Open the bucket page → Configuration tab.
-
In the Data protection block, in the Object Lock line, click Edit.
-
Specify a new lock duration. The maximum lock duration is:
- for Compliance mode — one year. To set a Compliance lock for more than one year, use the API or tools, such as AWS CLI;
- for Governance mode — 100 years.
-
Click Save.
Change default retention mode
You can only change the lock mode from Governance to Compliance.
Control panel
AWS CLI
- In the Control panel, in the top menu, click Products and select S3.
- Go to Buckets.
- Open the bucket page → Configuration tab.
- In the Data protection block, in the Object Lock line, click Edit.
- Select the Compliance lock mode.
- Specify the lock duration. The maximum Compliance lock duration is one year. To set a Compliance lock for more than one year, use the API or tools, such as AWS CLI.
- Click Save.
Disable default retention
You can only disable default retention in Governance mode.
When default retention is disabled, new objects will not be locked. Objects that were uploaded and automatically locked before default retention was disabled will remain locked according to the lock mode. Object Lock itself will not be disabled in the bucket.
Control panel
AWS CLI
Only the Account Owner or a user with the member role can disable default retention in the control panel.
- In the Control panel, in the top menu, click Products and select S3.
- Go to Buckets.
- Open the bucket page → Configuration tab.
- In the Data protection block, in the Object Lock line, click Edit.
- Clear the Enable default retention checkbox.
- Click Save.