Configuring Google Cloud Storage Object Retention (Bucket Lock) for cloud-container storage pools
Google Cloud Storage (GCS) Bucket Lock and Object Retention policies add an additional layer of protection for data that is stored in cloud‑container storage pools. These capabilities prevent objects from being modified or deleted during a specified retention period. Object Lock allows you to specify a fixed period during which an object remains immutable and cannot be overwritten or deleted. Object Retention helps organizations meet regulatory requirements that mandate Write Once Read Many (WORM) data protection.
Before you begin
- Database backup to cloud and retention to cloud storage pools are not supported in pools that use GCS Object Lock.
- GCS buckets with enforced retention policies must be used by only one IBM Storage Protect storage pool. Do not share a locked bucket across multiple pools.
- Container objects with referenced data at the end of the retention period will have their lock extended by the IBM Storage Protect server until all referenced data expires or is no longer required. Once expired, the container is deleted.
- IBM Storage Protect policy settings are independent of the GCS lock duration.
About this task
- Data ingested directly from clients
- Data tiered from another storage pool
GCS provides two retention modes similar to AWS Object Lock:
- Retention Modes
-
- Governance Mode: Users with specific IAM permissions can override retention settings to delete or modify protected objects.
- Compliance Mode: No users, including administrators, can override the lock before retention expiration. (Not currently supported)
Procedure
To configure GCS Object Retention by using the command-line administrative client, complete the following steps:
What to do next
Once the configuration is complete, the storage pool is ready to receive data. Containers are locked when they are written to the GCS bucket and remain locked as long as they are referenced by IBM Storage Protect clients.
- Cloud Data Locking status
- Cloud Data Lock Duration