Enable S3 Object Lock in StorageGRID
If an S3 tenant account needs to comply with regulatory requirements when saving object data, you must enable S3 Object Lock for your entire StorageGRID system. Enabling the global S3 Object Lock setting allows any S3 tenant user to create and manage buckets and objects with S3 Object Lock.
-
You have the Root access permission.
-
You are signed in to the Grid Manager using a supported web browser.
-
You have reviewed the S3 Object Lock workflow, and you understand the considerations.
-
You have confirmed that the default rule in the active ILM policy is compliant. Refer to Create a default ILM rule for details.
A grid administrator must enable the global S3 Object Lock setting to allow tenant users to create new buckets that have S3 Object Lock enabled. After this setting is enabled, it can't be disabled.
After enabling the S3 Object Lock, a grid administrator can also allow tenant users to enable S3 Object Lock on an existing bucket. After a grid administrator enables this setting, they can disable it. For more information, refer to S3 Object Lock requirements.
Review the compliance settings of existing tenants after you enable the global S3 Object Lock setting. When you enable this setting, the S3 Object Lock per-tenant settings depend on the StorageGRID release at the time the tenant was created.
|
|
The global Compliance setting is deprecated. If you enabled this setting using a previous version of StorageGRID, the S3 Object Lock setting is enabled automatically. You can continue to use StorageGRID to manage the settings of existing compliant buckets; however, you can't create new compliant buckets. For details, refer to NetApp Knowledge Base: How to manage legacy Compliant buckets in StorageGRID 11.5. |
-
Select Configuration > System > S3 Object Lock.
The S3 Object Lock Settings page appears.
-
Select Enable S3 Object Lock to enable S3 Object Lock for your entire StorageGRID system.
-
Optionally, select Allow S3 Object Lock to be enabled on existing buckets.
Enabling S3 Object Lock on an existing bucket might cause unintended data migration from a Cloud Storage Pool back to StorageGRID, depending on your ILM rules. You can't stop this migration after it starts.For more information, refer to S3 Object Lock requirements. -
Select Apply.
A confirmation dialog box appears and reminds you that you can't disable S3 Object Lock after it is enabled.
-
If you are sure you want to permanently enable S3 Object Lock for your entire system, select OK.
When you select OK:
-
If the default rule in the active ILM policy is compliant, S3 Object Lock is now enabled for the entire grid and can't be disabled.
-
If the default rule is not compliant, an error appears. You must create and activate a new ILM policy that includes a compliant rule as its default rule. Select OK. Then, create a new policy, simulate it, and activate it. Refer to Create ILM policy for instructions.
-