Description
Vault immutability restricts operations that delete backup data before recovery points expire. Without this protection, a user with deletion permissions may accidentally or maliciously remove backups needed for recovery.
immutability = "Unlocked" enables protection but allows it to be disabled again. Locked makes that protection irreversible. Vault immutability does not apply to operational backups of blobs, files or disks.
Potential impact
- Deleted backups can leave no recovery point available after an outage or compromise.
- Losing both the source data and its backups can delay recovery or cause permanent loss.
Remediation
- Enable
immutabilitywithUnlockedand check its effect on retention policies and operating procedures. - Consider
Lockedafter testing. The lock is irreversible, so also inspect the Terraform plan for any vault replacement. - Use soft delete, least-privilege access and restore tests alongside immutability. It does not by itself ensure that backups are created or can be restored successfully.
Examples
These examples compare immutability settings. Keep the existing vault name when changing its protection; changing the name creates a new vault.
Before
resource "azurerm_data_protection_backup_vault" "backup_vault" {
name = "app-backup-vault"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
datastore_type = "VaultStore"
redundancy = "LocallyRedundant"
immutability = "Disabled"
}
Immutability is disabled. This setting does not block backup deletion that other permission controls allow.
After
resource "azurerm_data_protection_backup_vault" "backup_vault" {
name = "protected-backup-vault"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
datastore_type = "VaultStore"
redundancy = "LocallyRedundant"
immutability = "Locked"
}
Immutability is locked and cannot be disabled. Confirm retention requirements and operational effects before applying it.