Files
buckit/docs
abuckit 822d5d374d docs(kms): add KES replacement design
Design for replacing deprecated MinIO KES with an open-source approach:
a cached per-cluster encryption key in Buckit (L1) plus a stateless
KMS-auth proxy (Fargate, L2) that holds the cloud credentials so they
never live in Buckit. Covers cost analysis, the two-tier cache, security
boundary (credential isolation vs. key-material exposure), and open
decisions.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 22:52:51 -04:00
..
2026-06-01 22:52:51 -04:00
2026-04-30 16:08:31 -04:00