Open table of contents
Conclusion
Design deletion protection and post-compromise restoration together.
Context
Backups deletable with production credentials may be lost with production. Design retention together with an independent restoration path.
Design and verification scope
Assess the following responsibilities and boundaries when designing and verifying a configuration.
- Governance
- Compliance
- Retention
- Versioning
- Credentials
- Separation from production
- Recovery testing
Decision rationale
Compare Governance and Compliance retention and identify who can alter or bypass it. Separate object versions, backup writers, encryption keys and restoration identities, then examine reachability from compromised production authority.
Trade-offs
Strong retention resists deletion but also retains incorrect or unnecessary data, affecting cost and deletion obligations. Treat non-shortenable Compliance retention, lost KMS keys, restore speed and recovery procedures as separate concerns.
Limitations
Review retention modes, bypass permissions, accounts, KMS access, lifecycle and restore conditions. Object Lock does not protect keys or pre-ingestion integrity.
Related case context
These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.