1. Enable Object Locking in the Bucket:
Access the AWS Management Console and navigate to the S3 service.
- Choose the desired bucket for Immutable Storage configuration.
- Navigate to the "Management" tab.
- Under "Object lock," click "Edit."
- Enable "Object Lock" and save the changes.
2. Remove Default Retention Settings (if any):
While configuring Object Locking, ensure no default retention settings are applied to the bucket, allowing objects to be classified as immutable without predefined retention periods.
3. Implement IAM User Policy:
- Create an IAM User Policy with necessary permissions to designate the bucket as Immutable Storage.
- Access the IAM console in the AWS Management Console.
- Navigate to "Policies" and click "Create Policy."
- Select the "JSON" tab and utilize the provided template
- JSON policy Template
- Review and save the policy.
4. Attach the Policy to IAM User:
In the IAM console, navigate to the "Users" section.
- Select the IAM user responsible for configuring Immutable Storage.
- Access the "Permissions" tab and click "Attach Policies."
- Search and attach the previously created IAM User Policy.
Immutable cloud storage solutions such as Wasabi and MinIO are supported in BDRShield. For other S3-compatible clouds, follow similar steps.
1. Enable Object Locking in the Bucket.
2. Remove Default Retention Settings (if any).
3. Implement IAM User Policy.
4. Attach the Policy to IAM User.