From 8874f6659dab9a89b26efefa4f52986619deed86 Mon Sep 17 00:00:00 2001 From: Anjali Trace Date: Wed, 29 Apr 2026 11:26:23 +0100 Subject: [PATCH] NRL-2180 Update min + max vault lock retention periods and create prod lock in governance mode --- terraform/backup-infrastructure/prod/aws-backup.tf | 4 ++-- terraform/backup-infrastructure/test/aws-backup.tf | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/terraform/backup-infrastructure/prod/aws-backup.tf b/terraform/backup-infrastructure/prod/aws-backup.tf index 08f464ded..d321ad446 100644 --- a/terraform/backup-infrastructure/prod/aws-backup.tf +++ b/terraform/backup-infrastructure/prod/aws-backup.tf @@ -29,8 +29,8 @@ module "destination" { source_account_id = local.source_account_id kms_key = aws_kms_key.destination_backup_key.arn enable_vault_protection = true - vault_lock_type = "compliance" - vault_lock_min_retention_days = 28 + vault_lock_type = "governance" + vault_lock_min_retention_days = 2 vault_lock_max_retention_days = 400 } diff --git a/terraform/backup-infrastructure/test/aws-backup.tf b/terraform/backup-infrastructure/test/aws-backup.tf index 44672a80e..c005734d4 100644 --- a/terraform/backup-infrastructure/test/aws-backup.tf +++ b/terraform/backup-infrastructure/test/aws-backup.tf @@ -30,8 +30,8 @@ module "destination" { kms_key = aws_kms_key.destination_backup_key.arn enable_vault_protection = false vault_lock_type = "governance" - vault_lock_min_retention_days = 4 - vault_lock_max_retention_days = 105 + vault_lock_min_retention_days = 2 + vault_lock_max_retention_days = 35 } ###