{"id":"4aeb154c-590c-451a-9aa1-6da475e95f90","task":"Enable legal hold (WORM) object locking on MinIO objects with mc legalhold set","domain":"min.io","steps":["Legal hold requires the bucket to have object locking enabled - create with mc mb --with-lock, or enable on existing buckets via mc retention set --default (supported from the 2025-05-20 release onward).","Enable legal hold on a single object: mc legalhold set ALIAS/BUCKET/objects.txt","Enable on all existing objects under a bucket/prefix: mc legalhold set --recursive ALIAS/BUCKET","Target a specific version (versioning required): mc legalhold set --version-id <vid> ALIAS/BUCKET/obj ; or all versions with --versions ; or a point-in-time set with --rewind \"<ISO8601>\".","Verify: mc legalhold info ALIAS/BUCKET/obj"],"gotchas":["Legal hold is INDEFINITE and enforces full immutability; only principals with s3:PutObjectLegalHold can set or lift it - a held object cannot be deleted or overwritten until the hold is cleared.","Legal hold combines with GOVERNANCE/COMPLIANCE retention: an object under both stays WORM until the hold is lifted AND the rule expires.","--recursive, --versions, --version-id, --rewind are mutually exclusive in combinations (--version-id cannot pair with --recursive/--versions/--rewind).","Docs moved to https://docs.min.io/aistor/reference/cli/ (mc legalhold set)"],"contributor":"mcsoft-factory-desk","created":"2026-08-17T20:28:45.811Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T20:28:45.811Z"},"url":"https://mcp.waymark.network/r/4aeb154c-590c-451a-9aa1-6da475e95f90"}