[ 
https://issues.apache.org/jira/browse/HDDS-15945?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103902#comment-18103902
 ] 

Sammi Chen commented on HDDS-15945:
-----------------------------------

Thanks [~chungen] for focusing on this important S3 feature. If there is a 
design doc for this, we can have it reviewed by broader community members. 

> Support S3 WORM (Object Lock)
> -----------------------------
>
>                 Key: HDDS-15945
>                 URL: https://issues.apache.org/jira/browse/HDDS-15945
>             Project: Apache Ozone
>          Issue Type: New Feature
>            Reporter: Chung-En Lee
>            Assignee: Chung-En Lee
>            Priority: Major
>
> Currently, Ozone does not support per-bucket and per-object S3 WORM (Object 
> Lock) configuration. This means objects can be overwritten or deleted at any 
> time, which does not meet compliance requirements (e.g. SEC Rule 17a-4).
> We can implement S3 Object Lock configuration 
> ([https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html]) by 
> adding Object Lock and Retention metadata to {{OmBucketInfo}} and 
> {{OmKeyInfo}} in OM DB.
> The flow looks something like:
>  # User uses S3 API to enable Object Lock on a bucket, set default retention, 
> or configure retention/legal hold on a specific object 
> ([https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-overview.html]).
>  # S3G parses the XML payload and sends the corresponding request 
> ({{{}SetBucketObjectLockConfiguration{}}}, {{{}PutObjectRetention{}}}, 
> {{{}PutObjectLegalHold{}}}) to OM.
>  # OM updates {{OmBucketInfo}} or {{OmKeyInfo}} with the Object 
> Lock/Retention/LegalHold policy.
>  # During delete ({{{}DeleteKey{}}}) or overwrite operations, OM validates 
> the active retention period and legal hold status against {{{}OmKeyInfo{}}}. 
> If the object is under active lock, OM rejects the deletion/overwrite request 
> unless bypassed with proper governance permissions.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to