Amazon FSx for NetApp ONTAP was launched in late 2021. With FSx for ONTAP you get the favored options, efficiency, and APIs of ONTAP file methods, with the agility, scalability, safety, and resilience of AWS, all as a completely managed service.
As we speak we’re including assist for SnapLock, an ONTAP characteristic that provides you the ability to create volumes that present Write As soon as Learn Many (WORM) performance. SnapLock volumes forestall modification or deletion of information inside a specified retention interval, and can be utilized to fulfill regulatory necessities and to guard business-critical knowledge from ransomware assaults and different malicious makes an attempt at alteration or deletion. FSx for ONTAP is the one cloud-based file system that helps SnapLock Compliance mode. FSx for ONTAP additionally helps tiering of WORM knowledge to lower-cost storage for all SnapLock volumes.
Defending Information with SnapLock
SnapLock offers you a further layer of knowledge safety, and may be regarded as a part of your group’s general knowledge safety technique. If you create a quantity and allow SnapLock, you select one of many following retention modes:
Compliance – This mode is used to deal with mandates resembling SEC Rule 17a-4(f), FINRA Rule 4511 and CFTC Regulation 1.31. You should use this mode to make sure a WORM file can’t be deleted by any consumer till after its retention interval expires. Volumes on this mode can’t be renamed and can’t be deleted till the retention intervals of all WORM information on the quantity have expired.
Enterprise – This mode is used to implement organizational knowledge retention insurance policies or to check retention settings earlier than creating volumes in Compliance mode. You should use this mode to stop most customers from deleting WORM knowledge, whereas permitting licensed customers to carry out deletions, if mandatory. Volumes on this mode may be deleted even when they include WORM information below an lively retention interval.
You additionally select a default retention interval. This era signifies the size of time that every file have to be retained after it’s dedicated to the WORM state, and may be so long as 100 years, and there’s additionally an Infinite choice. You may also set a customized retention interval for particular information or particular timber of information and it’ll apply to these information on the time that they’re dedicated to the WORM state.
Information are dedicated to the WORM state once they turn into read-only (chmod -w on Linux or attrib +r on Home windows). You may configure a per-volume autocommit interval (5 minutes to 10 years) to mechanically commit information which have remained as-is for the interval, and you may as well provoke a Authorized Maintain in Compliance mode with a purpose to retain particular information for authorized functions.
You even have one other fascinating knowledge safety and compliance choice. You may create one quantity with out SnapLock enabled, and one other one with it enabled, after which periodically replicate from the primary one to the second utilizing NetApp SnapVault. This provides you with snapshot copies of complete volumes that you may retain for months, years, or many years as wanted.
Talking of fascinating choices, you may make use of FSx for ONTAP quantity knowledge tiering to maintain lively information on high-performance SSD storage and the opposite information on storage that’s cost-optimized for knowledge that’s accessed occasionally.
Creating SnapLock Volumes
I can create new volumes and allow SnapLock with a few clicks. I enter the quantity title, measurement, and path as ordinary:

As I discussed earlier, I also can make use of a capability pool (that is set to Auto by default, and I set a ten day cooling interval):

I scroll all the way down to the Superior part and click on Enabled, then choose Enterprise retention mode. I additionally arrange my retention intervals, allow autocommit after 9 days, and go away the opposite choices as-is:

I add a tag, and click on Create quantity to maneuver forward:

I take a fast break, and once I come again my quantity is able to use:

At this level I can mount it within the ordinary approach, create information, and permit SnapLock to do its factor!
Issues to Know
Listed below are a few issues that you need to find out about this highly effective new characteristic:
Current Volumes – You can not allow this characteristic for an current quantity, however you possibly can create a brand new, SnapLock-enabled quantity, and replica or migrate the info to it.
Quantity Deletion – As I famous earlier, you can’t delete a SnapLock Compliance quantity if it incorporates WORM information with an unexpired retention interval. Take care when setting this to keep away from creating volumes that can last more than wanted.
Pricing – There’s a further GB/month license cost for the usage of SnapLock volumes; try the Amazon FSx for NetApp ONTAP Pricing web page for extra data.
Areas – This characteristic is accessible in all AWS Areas the place Amazon FSx for NetApp ONTAP is accessible.
— Jeff;

