Parece que não há como fazer isso sem escrever código do sistema de arquivos / kernel personalizado.
Uma solução viável parece ser usar o Amazon Glacier com a opção de armazenamento em arquivo WORM. De acordo com o blog oficial da AWS em: link
[...] a new Glacier feature that allows you to lock your vault with a variety of compliance controls that are designed to support this important records retention use case. You can now create a Vault Lock policy on a vault and lock it down. Once locked, the policy cannot be overwritten or deleted. Glacier will enforce the policy and will protect your records according to the controls (including a predefined retention period) specified therein.
You cannot change the Vault Lock policy after you lock it. However, you can still alter and configure the access controls that are not related to compliance by using a separate vault access policy. For example, you can grant read access to business partners or designated third parties (as sometimes required by regulation).
Para mim, isso fornece exatamente o que é necessário sem a despesa de hardware da NetApp ou EMC, embora pareça atender aos requisitos de retenção de registros.