From 067cbd8373efc0f5d40f5315d07aa74ae8468c0d Mon Sep 17 00:00:00 2001 From: krys-cf Date: Mon, 21 Sep 2026 11:54:16 -0500 Subject: [PATCH 1/2] docs(r2): clarify bucket lock enforcement boundary --- src/content/docs/r2/buckets/bucket-locks.mdx | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/content/docs/r2/buckets/bucket-locks.mdx b/src/content/docs/r2/buckets/bucket-locks.mdx index 464a1623fef..17430148758 100644 --- a/src/content/docs/r2/buckets/bucket-locks.mdx +++ b/src/content/docs/r2/buckets/bucket-locks.mdx @@ -148,6 +148,7 @@ If multiple rules apply to the same prefix or object key, the strictest (longest ## Notes - Rules without prefix apply to all objects in the bucket. -- Rules apply to both new and existing objects in the bucket. +- Bucket locks protect both existing objects and objects created after the rule is enabled. They do not prevent new object creation. +- A successful rule update is the enforcement boundary. Mutations to existing keys are denied if they commit after the update succeeds. This includes overwrites, deletes, copies, multipart completions, and lifecycle deletions that began earlier. - Bucket lock rules take precedence over [lifecycle rules](/r2/buckets/object-lifecycles/). For example, if a lifecycle rule attempts to delete an object at 30 days but a bucket lock rule requires it be retained for 90 days, the object will not be deleted until the 90-day requirement is met. - A bucket cannot be emptied while any bucket lock rules are configured. Remove all lock rules before [emptying a bucket](/r2/buckets/delete-buckets/#empty-a-bucket). Bucket lock rules also apply when [deleting folders](/r2/objects/delete-objects/) from the dashboard. From dd8f33eae02318d28a21b391ed167c2c3a9410b1 Mon Sep 17 00:00:00 2001 From: krys-cf Date: Mon, 21 Sep 2026 12:00:54 -0500 Subject: [PATCH 2/2] docs(r2): use active voice for lock enforcement --- src/content/docs/r2/buckets/bucket-locks.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/content/docs/r2/buckets/bucket-locks.mdx b/src/content/docs/r2/buckets/bucket-locks.mdx index 17430148758..b34cf7aab7b 100644 --- a/src/content/docs/r2/buckets/bucket-locks.mdx +++ b/src/content/docs/r2/buckets/bucket-locks.mdx @@ -149,6 +149,6 @@ If multiple rules apply to the same prefix or object key, the strictest (longest - Rules without prefix apply to all objects in the bucket. - Bucket locks protect both existing objects and objects created after the rule is enabled. They do not prevent new object creation. -- A successful rule update is the enforcement boundary. Mutations to existing keys are denied if they commit after the update succeeds. This includes overwrites, deletes, copies, multipart completions, and lifecycle deletions that began earlier. +- A successful rule update is the enforcement boundary. R2 denies mutations to existing keys if they commit after the update succeeds. This includes overwrites, deletes, copies, multipart completions, and lifecycle deletions that began earlier. - Bucket lock rules take precedence over [lifecycle rules](/r2/buckets/object-lifecycles/). For example, if a lifecycle rule attempts to delete an object at 30 days but a bucket lock rule requires it be retained for 90 days, the object will not be deleted until the 90-day requirement is met. - A bucket cannot be emptied while any bucket lock rules are configured. Remove all lock rules before [emptying a bucket](/r2/buckets/delete-buckets/#empty-a-bucket). Bucket lock rules also apply when [deleting folders](/r2/objects/delete-objects/) from the dashboard.