Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Including overwrite protection? No admin access to those policies from the server?


The NAS’s user has ListObject, PutObject, and DeleteObject. The bucket has versioning enabled, and DeleteObject doesn’t allow deleting prior versions. So the NAS can delete what’s immediately visible in the bucket, but it can’t permanently delete things.

The other way to set this up is to configure Object Lock on your S3 bucket: https://docs.aws.amazon.com/AmazonS3/latest/userguide/object...

The upside of versioning over Object Lock, for my use case, is that the backup scripts can be very simple, because they don’t have to deal with what happens if they want to clean up a file but don’t have permissions to. They just do their thing, and I’m confident that old versions are retained. The downside of this approach is that my S3 usage will increase over time, because I’m retaining all old content. So eventually it’ll cost enough for me to decide to either switch to Object Lock or figure out a safe way to prune old content.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: