Back up a server to Wasabi with Object Lock
Wasabi has Object Lock over the S3 API and accepts the same access policy as AWS, so the agent's key can have only what it uses. Mind one rule: on Wasabi, Object Lock can only be turned on when the bucket is created.
Console steps checked against the provider's official documentation on October 4, 2026. Screens change: if something doesn't match, follow the documentation linked in each step.
Before you start
- An email address for the Wasabi account.
- A Linux, Windows or macOS server with admin access, to install the agent.
- An Arkame panel account.
Create the account
Create the bucket with versioning and Object Lock
- In the Wasabi console, click Create Bucket, enter the name and pick the region from the list.
- Go on to the properties and turn on Bucket Versioning. Versioning must be on before Object Lock.
- Turn on Object Lock and create the bucket.
On Wasabi, Object Lock can only be enabled at bucket creation, not on an existing bucket. Once it is on, versioning can't be turned off. Wasabi has no South America region: its regions are in the US, Canada, Europe and Asia-Pacific.
Turn on default retention in Compliance mode
- On the bucket, open the Object Lock tab and enable Default Object Retention.
- It defaults to Governance Mode: select Compliance Mode. In that mode nobody can delete or overwrite a version before the period ends, not even with the key in hand.
- In Retention Time, enter the period (in days or years). 30 days is a good start; pick a period longer than it would take you to notice an attack.
- Click Apply and confirm by typing CONFIRM.
Don't confuse this with Wasabi's Compliance feature (the bucket's Compliance tab): it applies to the whole bucket and can't coexist with Object Lock on the same bucket. For Arkame, what counts is Object Lock with default retention.
Create the agent's access policy
- In the console, under Policies, click Create Policy and give it a name.
- Paste the policy below, replacing the bucket name. When Wasabi says the policy is valid, click Create Policy.
Access policy — replace YOUR-BUCKET with your bucket name:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:ListBucketVersions",
"s3:ListBucketMultipartUploads",
"s3:GetBucketLocation",
"s3:GetBucketVersioning",
"s3:GetBucketObjectLockConfiguration",
"s3:GetLifecycleConfiguration"
],
"Resource": "arn:aws:s3:::YOUR-BUCKET"
},
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:GetObjectVersion",
"s3:PutObject",
"s3:DeleteObjectVersion",
"s3:RestoreObject",
"s3:AbortMultipartUpload",
"s3:ListMultipartUploadParts"
],
"Resource": "arn:aws:s3:::YOUR-BUCKET/*"
}
]
}It's the same policy as in /docs/armazenamento: list the bucket and its versions, read the settings, read and write files, delete old versions and request cold-storage rehydration. It can't create or delete buckets, or change settings. s3:DeleteObjectVersion is what Arkame's retention cleanup uses, and that cleanup only runs on buckets without Object Lock; with Object Lock, you can drop that line.
Create Arkame's user and key
- Under Users, click Create User, enter a name and choose programmatic access (by API key), without console access.
- Attach the policy from the previous step to the user, and only that one.
- Create the user's access key and save the Access Key and Secret Key right away: Wasabi warns that if you don't download or copy them now, you can't retrieve them later.
Add the bucket in Arkame
- In the panel, open Storages → Add storage and pick Wasabi.
- Fill in the bucket name and the endpoint, as in the box below. You can leave the region blank: Arkame reads it from the endpoint.
- You do not type the key here. The installer asks for the Access Key and the Secret Key on the server itself, and they stay there.
In Arkame, under Storages → Add storage:
- Provider
- Wasabi
- Bucket name
- the name you chose
- Endpoint
- https://s3.us-east-1.wasabisys.com (your bucket's region)
- Region
- blank — Arkame reads it from the endpoint
Install the agent and run the first backup
- Under Agents → New agent, give it a name, choose the bucket and copy the command the panel shows for the server's system (installation).
- Run the command on the server. The installer asks for the Access Key and the Secret Key, tests the key against the bucket before going on and, if the bucket refuses it, tells you why and asks again.
- Back in the panel, check the server's key fingerprint and approve it. Then use Test connection.
- Under Plans → New plan, choose the folders, the destination bucket and a schedule (plans). To skip the wait, use Run now on the plan page and follow it in History.
- When the backup finishes, restore one file to a new folder under Restore (restore). A backup that has never been restored is still a hypothesis.
Before you go: cost and old versions
- On the Pay as You Go plan, Wasabi charges each file for at least 90 days: delete it sooner and it charges the remaining days (pricing FAQ). For backups, which keep versions for weeks, this matters little; for files that change all the time, it matters.
- In a bucket with Object Lock, Arkame deletes no versions at all. So old versions don't pile up forever, create a rule in the bucket's Lifecycle tab (Create New Rule) that deletes noncurrent versions after a period — that period is how far back you'll be able to go. Wasabi won't delete an object still under Object Lock.
- What will it cost at your size? Compare providers.
Try it on your server
14-day free trial, no card. Backups go to your bucket, with your keys.