, , ,

Nutanix Objects WORM, Object Lock, and Legal Hold Explained

3 min read

Backups and archives are only useful if an attacker, administrator, or application cannot silently change them before they are needed. Nutanix Objects includes immutability and retention controls designed for cyber resilience and regulated data.

The terms WORM, Object Lock, retention, versioning, and legal hold are related but not interchangeable. Understanding the difference is essential before building a compliant archive.

WORM: Write Once, Read Many: WORM protects objects from modification or deletion for a defined retention period. Once a bucket’s WORM configuration is finalized, its protection cannot simply be turned off by an administrator.

During the retention period:

  • Object content cannot be overwritten
  • Protected metadata cannot be modified
  • The object cannot be deleted
  • The retention period cannot be shortened

Administrators may be able to extend retention, but not reduce it. That one-way behavior is intentional: a user with elevated privileges should not be able to weaken the policy once data has been written.

Object Lock Retention Dates: An Object Lock retain-until date can apply retention to an individual object version. This provides more granular control than relying only on a bucket-wide default.

The date can be extended when records must be kept longer. It cannot be moved backward to make an object eligible for early deletion.

This is useful when data in one bucket has different retention requirements. For example, ordinary records may be retained for seven years, while a subset must be preserved for ten years.

Legal Hold: A legal hold suspends deletion eligibility independently of the normal retention date. The hold can remain in place while litigation, an investigation, or a regulatory request is active.

Unlike a fixed retention period, a legal hold does not need a predetermined expiration date. It remains active until an authorized process clears it.

A legal hold should have a documented approval and audit process. Technical access alone should not determine who can place or remove a hold.

Two parallel timelines. The retention period runs from object creation to a retain-until date that can be extended but never moved backward, after which the object becomes eligible for deletion. The legal hold timeline starts and ends independently with no expiry date, cleared only by an authorized process. A summary shows the object is deletable only when both retention has expired and no hold is active.

Why Versioning Matters: With versioning enabled, an application can write a new version of an object without changing the protected version. A delete operation may create a delete marker that hides older versions from an ordinary listing, but the retained versions remain protected.

Versioning helps protect against accidental overwrites and gives backup applications a safer target. It also increases capacity consumption, so retention and lifecycle policies must be reflected in sizing.

Design Questions to Answer First: Before enabling WORM, involve security, compliance, backup, and application owners. Agree on:

  • Which data requires immutable retention
  • The default retention period
  • Who can extend retention
  • Who can apply or clear legal holds
  • Whether versioning is required
  • How capacity growth will be monitored
  • How protected records will be searched and retrieved

Test with a nonproduction bucket. Because WORM controls are intentionally difficult to reverse, a configuration mistake can leave test data consuming capacity until its retention expires.

Immutability Is Not The Entire Backup Strategy: WORM helps prevent alteration and deletion, but it does not replace backup architecture. Organizations still need:

  • Multiple failure domains
  • Recovery testing
  • Credential separation
  • Monitoring for unusual access
  • Documented restore procedures

Immutability is strongest when implemented as a single layer within a broader cyber-recovery design.

Summary: WORM ensures durable retention; Object Lock can apply dates to specific object versions; legal hold pauses deletion eligibility; and versioning preserves earlier copies. Together, these features can protect backups and records from both malicious and accidental change.

Plan carefully before enabling them. Retention that cannot be shortened is valuable only when the original policy is correct.

Official Resources

Nutanix Objects OverviewNutanix Objects Datasheet


What Do You Think? Are you using immutable object storage primarily for backup, compliance, or both?