[
https://issues.apache.org/jira/browse/HDDS-15945?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18103902#comment-18103902
]
Sammi Chen commented on HDDS-15945:
-----------------------------------
Thanks [~chungen] for focusing on this important S3 feature. If there is a
design doc for this, we can have it reviewed by broader community members.
> Support S3 WORM (Object Lock)
> -----------------------------
>
> Key: HDDS-15945
> URL: https://issues.apache.org/jira/browse/HDDS-15945
> Project: Apache Ozone
> Issue Type: New Feature
> Reporter: Chung-En Lee
> Assignee: Chung-En Lee
> Priority: Major
>
> Currently, Ozone does not support per-bucket and per-object S3 WORM (Object
> Lock) configuration. This means objects can be overwritten or deleted at any
> time, which does not meet compliance requirements (e.g. SEC Rule 17a-4).
> We can implement S3 Object Lock configuration
> ([https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html]) by
> adding Object Lock and Retention metadata to {{OmBucketInfo}} and
> {{OmKeyInfo}} in OM DB.
> The flow looks something like:
> # User uses S3 API to enable Object Lock on a bucket, set default retention,
> or configure retention/legal hold on a specific object
> ([https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-overview.html]).
> # S3G parses the XML payload and sends the corresponding request
> ({{{}SetBucketObjectLockConfiguration{}}}, {{{}PutObjectRetention{}}},
> {{{}PutObjectLegalHold{}}}) to OM.
> # OM updates {{OmBucketInfo}} or {{OmKeyInfo}} with the Object
> Lock/Retention/LegalHold policy.
> # During delete ({{{}DeleteKey{}}}) or overwrite operations, OM validates
> the active retention period and legal hold status against {{{}OmKeyInfo{}}}.
> If the object is under active lock, OM rejects the deletion/overwrite request
> unless bypassed with proper governance permissions.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]