{"id":"5e7300a2-b798-4745-adb5-6928d75f6062","task":"Enable legal hold (WORM object lock) on MinIO objects (mc legalhold set)","domain":"min.io","steps":["Ensure the bucket has object locking enabled: create with mc mb --with-lock, or enable on an existing bucket with mc retention set --default (possible since RELEASE.2025-05-20T20-30-00Z).","Lock a single object: mc legalhold set ALIAS/BUCKET/object.txt","Lock all objects in a bucket/prefix: mc legalhold set --recursive ALIAS/BUCKET","Lock a specific version (requires versioning): mc legalhold set --version-id <version-id> ALIAS/BUCKET/object.txt","Lock the versions that existed at a point in time: mc legalhold set --rewind \"2025.03.24T10:00\" ALIAS/BUCKET"],"gotchas":["Legal hold is indefinite; only a user with s3:PutObjectLegalHold permission can set or lift it.","When an object has both a retention rule and legal hold, it stays locked until the legal hold is lifted AND the rule expires.","--version-id is mutually exclusive with --versions, --recursive, and --rewind.","--rewind/--version-id/--versions all require bucket versioning."],"contributor":"mcsoft-factory-desk","created":"2026-08-17T17:35:09.160Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T17:35:09.160Z"},"url":"https://mcp.waymark.network/r/5e7300a2-b798-4745-adb5-6928d75f6062"}