Locking backups with S3 Object Lock
Make backups that nobody can delete or change for a set number of days: not an attacker, not a stolen key, not VPS Snaps.
S3 Object Lock is a setting on your own bucket. With a default retention period, storage itself refuses to delete or overwrite each backup until that many days after it was written. That holds against someone with root on your server, someone with your storage key, and someone signed in to your VPS Snaps account. VPS Snaps never turns it on or changes it: it uploads into a locked bucket and shows you the lock on the Storage page.
Which storage supports it
- AWS S3: yes. You can turn it on when you create the bucket or later, from the bucket's Properties tab.
- Backblaze B2: yes, on a new or an existing bucket.
- Wasabi: yes, but only when the bucket is created.
- Custom S3-compatible storage, such as MinIO: yes, if it implements S3 Object Lock.
- Cloudflare R2: R2 has its own bucket lock rules instead. VPS Snaps can't read them, so the Storage page shows no lock, but they still protect your backups. Retention tries again each day until a backup's lock ends.
- DigitalOcean Spaces and Google Drive: no.
Object Lock can't be turned off once a bucket has it, and versioning can't be suspended. In compliance mode, nobody can shorten a lock, including your cloud account's root user. Start with a short period.
Turn it on in AWS S3
- Open the bucket, then Properties. Versioning must be enabled first.
- Under Object Lock, choose Edit and enable it.
- Turn on Default retention. Choose Compliance mode, and a number of days, for example 14.
- In VPS Snaps, add the bucket as a destination, or add it again to test it. The Storage page then shows it as locked.
Governance mode can be bypassed by an account user with the s3:BypassGovernanceRetention permission. Compliance mode can't be bypassed by anyone, which is what protects you if your cloud account itself is compromised.
How retention works with a locked bucket
VPS Snaps still removes a backup from the job's list when it passes your retention. In a locked bucket that delete only adds a delete marker: storage keeps the backup itself until its lock ends, and bills you for it until then. Add a lifecycle rule that permanently deletes noncurrent versions, set to at least your lock period, so each locked copy is removed once its lock has ended.
- Retention 30 days, lock 14 days: each backup is unlocked long before VPS Snaps removes it.
- Retention 7 days, lock 30 days: backups leave the job's list after 7 days, and storage keeps them, and bills for them, for 30.
What has to support it
Every upload into a bucket with a default retention must carry an integrity checksum. VPS Snaps sends one on backups over SSH, backups made by the VPS Snaps agent, Railway and Render database dumps, and the WordPress plugin from version 1.0.2. An older plugin's upload into a locked bucket is refused: update the plugin from your WordPress dashboard.
Permissions
To show the lock on the Storage page, the key needs s3:GetBucketObjectLockConfiguration, which is in the policy on Configuring AWS S3. It only reads the setting. Without it backups still work, and the Storage page says it couldn't read the lock.