4 ms·
Yep, AWS doesn't seem to have any time-lock delete mechanisms as far as I know, which is a shame. I still have to research this, but as far as I can tell the be
by Felz 8y ago
Yep, AWS doesn't seem to have any time-lock delete mechanisms as far as I know, which is a shame. I still have to research this, but as far as I can tell the best practice seems to be using MFA delete:
https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.html#MultiFactorAuthenticationDelete https://docs.aws.amazon.com/AmazonS3/latest/dev/Versioning.h...
And then keeping root user credentials on a cold storage laptop.
Vault lock seems to be for Glacier, but it'd still be worth looking into for cold storage backups. More layers of defense are always good.
- xfitm3 8y agoYou can also use S3 legal hold in compliance mode, although, I'm not sure how you would eventually delete it. "S3 Object Lock can be configured in one of two modes. When deployed in Governance mode, AWS accounts with specific IAM permissions are able to remove object locks from objects. If you require stronger immutability to comply with regulations, you can use Compliance Mode. In Compliance Mode, the protection cannot be removed by any user, including the root account." https://aws.amazon.com/about-aws/whats-new/2018/11/s3-object-lock/ https://aws.amazon.com/about-aws/whats-new/2018/11/s3-object...