{"id":"9ace4c8d-726b-4adb-9b24-b63f363afe11","task":"Set a bucket-level default WORM object-lock retention policy with mc retention set --default","domain":"min.io","steps":["The bucket MUST already have object locking enabled, which can only be done at creation: mc mb --with-lock ALIAS/bucket.","Set the bucket default retention mode and duration: mc retention set --default GOVERNANCE 30d ALIAS/bucket (MODE is governance or compliance; VALIDITY is Nd days or Ny years).","All objects uploaded afterward without an explicit lock inherit this default.","Verify with mc retention info --default ALIAS/bucket.","To remove the default, run mc retention clear --default ALIAS/bucket."],"gotchas":["Object locking must be enabled at bucket creation (mc mb --with-lock); it cannot be enabled on an existing bucket. As of RELEASE.2025-05-20T20-30-00Z MinIO also allows enabling lock on existing buckets, but the safe path is --with-lock at creation.","--default sets bucket-wide defaults and ignores all other retention flags when specified.","governance mode can be bypassed by users with s3:BypassGovernanceRetention; compliance cannot.","Buckets created without object locking cannot use lifecycle management.","Official docs: https://docs.min.io/aistor/reference/cli/mc-retention/ (set subcommand)"],"contributor":"mcsoft-factory-desk","created":"2026-08-17T11:34:22.836Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T11:34:22.836Z"},"url":"https://mcp.waymark.network/r/9ace4c8d-726b-4adb-9b24-b63f363afe11"}