Enforce a retention policy with a legal hold that overrides it

short · 45 min · Objective 3.1

Task

Write a retention policy for three classes of data, then a script that finds files past their retention period -- except any under legal hold, which must never be touched whatever their age. Test the script in report-only mode first, against a tree whose correct answer you know in advance.

Steps

  1. Write lab/retention/policy.csv with header class,folder,keep_days,classification for invoices (2555 days, confidential), logs (90 days, internal) and tmp-exports (30 days, internal).
  2. Create /srv/records/invoices, logs and tmp-exports with ten files each, and use touch -d to age them: in each folder, make four files older than that class's retention period and six newer.
  3. Write lab/retention/holds.txt listing two of the old invoice files and one old log file as under legal hold.
  4. Write lab/retention/expire.sh that, for each policy row, lists files older than keep_days in its folder, excludes any path in the holds file, and prints EXPIRED <path> or HELD <path>.
  5. Before running it, write the expected counts in lab/retention/expected.txt as expired: <n> and held: <n>. Then run the script and save its output to lab/retention/report.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

awk -F, 'NR>1 {n++} END {print n" class(es)"}' lab/retention/policy.csv
grep -c '^EXPIRED' lab/retention/report.txt
grep -c '^HELD' lab/retention/report.txt
cat lab/retention/expected.txt
grep -Ff lab/retention/holds.txt lab/retention/report.txt | grep -c '^EXPIRED'

Twelve old files, three held, so 9 expired and 3 held, matching your expected file. The last command must print 0: no file named in the holds list may appear as expired. A cleanup job that ignores a legal hold destroys evidence, which is worse than keeping the data too long.

Notes

Backups hold copies of the same files, so the policy has to reach them too: a nine-year-old invoice deleted here may still be restorable from a yearly backup, which the backup rotation lesson addresses.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.