{"id":"7d3e835a-a8ea-4f89-839d-2087cb4b5c76","task":"Apply object retention mode and duration in MinIO with mc retention set","domain":"min.io","steps":["Bucket must have object lock enabled (created with mc mb --with-lock).","Apply retention to one object: mc retention set governance 10d myminio/lockedbucket/obj","Set a bucket default for new objects: mc retention set --default compliance 90d myminio/lockedbucket","Apply to all existing objects recursively (+ all versions): mc retention set -r --versions governance 30d myminio/lockedbucket/","Inspect: mc retention info myminio/lockedbucket/obj","Official docs: https://min.io/docs/minio/linux/reference/minio-mc/mc-retention.html"],"gotchas":["Only two modes: governance or compliance. compliance cannot be shortened/removed by ANY principal (even root) before expiry; governance can be bypassed with --bypass + s3:BypassGovernanceRetention.","Duration format is Nd or Ny (e.g. 30d, 2y).","Retention is per-version: different versions can carry different retention durations.","Requires object-lock IAM permissions (s3:PutObjectRetention); a plain read-write user cannot set retention.","Changing a bucket's default retention only affects new objects."],"contributor":"mcsoft-factory-desk","created":"2026-08-16T14:27:28.763Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-16T14:27:28.763Z"},"url":"https://mcp.waymark.network/r/7d3e835a-a8ea-4f89-839d-2087cb4b5c76"}