AWS services or capabilities described in AWS Documentation may vary by region/location. Click Getting Started with Amazon AWS to see specific differences applicable to the China (Beijing) Region.
Container for the parameters to the InitiateVaultLock operation. This operation initiates the vault locking process by doing the following:
Installing a vault lock policy on the specified vault.
Setting the lock state of vault lock to InProgress
.
Returning a lock ID, which is used to complete the vault locking process.
You can set one vault lock policy for each vault and this policy can be up to 20 KB in size. For more information about vault lock policies, see Amazon Glacier Access Control with Vault Lock Policies.
You must complete the vault locking process within 24 hours after the vault lock enters
the InProgress
state. After the 24 hour window ends, the lock ID expires, the
vault automatically exits the InProgress
state, and the vault lock policy is
removed from the vault. You call CompleteVaultLock to complete the vault locking
process by setting the state of the vault lock to Locked
.
After a vault lock is in the Locked
state, you cannot initiate a new vault
lock for the vault.
You can abort the vault locking process by calling AbortVaultLock. You can get the state of the vault lock by calling GetVaultLock. For more information about the vault locking process, Amazon Glacier Vault Lock.
If this operation is called when the vault lock is in the InProgress
state,
the operation returns an AccessDeniedException
error. When the vault lock is
in the InProgress
state you must call AbortVaultLock before you can
initiate a new vault lock policy.
Namespace: Amazon.Glacier.Model
Assembly: AWSSDK.Glacier.dll
Version: 3.x.y.z
public class InitiateVaultLockRequest : AmazonGlacierRequest IAmazonWebServiceRequest
The InitiateVaultLockRequest type exposes the following members
Name | Description | |
---|---|---|
InitiateVaultLockRequest() |
Name | Type | Description | |
---|---|---|---|
AccountId | System.String |
Gets and sets the property AccountId.
The |
|
Policy | Amazon.Glacier.Model.VaultLockPolicy |
Gets and sets the property Policy. The vault lock policy as a JSON string, which uses "\" as an escape character. |
|
VaultName | System.String |
Gets and sets the property VaultName. The name of the vault. |
The example initiates the vault locking process for the vault named my-vault.
var client = new AmazonGlacierClient(); var response = client.InitiateVaultLock(new InitiateVaultLockRequest { AccountId = "-", Policy = new VaultLockPolicy { Policy = "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Sid\":\"Define-vault-lock\",\"Effect\":\"Deny\",\"Principal\":{\"AWS\":\"arn:aws:iam::999999999999:root\"},\"Action\":\"glacier:DeleteArchive\",\"Resource\":\"arn:aws:glacier:us-west-2:999999999999:vaults/examplevault\",\"Condition\":{\"NumericLessThanEquals\":{\"glacier:ArchiveAgeinDays\":\"365\"}}}]}" }, VaultName = "my-vault" }); string lockId = response.LockId;
.NET:
Supported in: 8.0 and newer, Core 3.1
.NET Standard:
Supported in: 2.0
.NET Framework:
Supported in: 4.5 and newer, 3.5