mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-07 13:53:12 +00:00
feat(kms): accept the AWS backend through KMS configuration (#5592)
* feat(kms): accept the AWS backend through KMS configuration The AWS KMS backend could be constructed but not selected: the admin configure API had no AWS variant and startup rejected the backend name. The configure request pins the region rather than defaulting it, because that configuration is persisted once and replayed on every node: leaving the region to each node's ambient provider chain would let nodes address different regions, and therefore different keys, while reporting an identical configuration. The request accepts no credential fields, so credentials stay with the aws-config provider chain on each node, and `deny_unknown_fields` refuses attempts to submit them anyway. * test(kms): cover AWS backend selection through the service manager An end-to-end check that an admin configure request selects the AWS backend, builds a client, and passes the startup health check. Marked #[ignore]: it needs real AWS credentials, though it creates no key and is therefore not billable on its own.
This commit is contained in:
@@ -170,7 +170,9 @@ Two consequences follow from that last row: **SSE-S3 key auto-creation and the s
|
||||
|
||||
Key versions are opaque. AWS addresses backing keys internally and picks the right one to decrypt with, so RustFS reports `key_version` as 1 and cannot enumerate versions. Rotation uses `RotateKeyOnDemand`, which retains prior backing keys for decryption; AWS's separate automatic yearly rotation is neither enabled nor reported on by RustFS.
|
||||
|
||||
The AWS backend is not configurable through the KMS admin API — use the environment variables above at startup.
|
||||
The KMS admin API accepts the AWS backend as `"backend_type": "AWS"` (aliases `aws`, `aws-kms`, `aws_kms`, `AwsKms`) on `/v3/kms/configure` and `/v3/kms/reconfigure`. The body carries `region` (**required**), and optionally `endpoint_url`, `default_key_id`, and the shared timeout/retry/cache settings. It accepts no credential fields at all — unknown fields are rejected — because every node resolves credentials through its own provider chain.
|
||||
|
||||
`region` is mandatory on this path even though `RUSTFS_KMS_AWS_REGION` is optional at startup: the admin configuration is persisted once and replayed on every node, so a request that left the region to each node's ambient chain would let nodes address different regions, and therefore different keys, while reporting an identical configuration. `default_key_id` must be an AWS key id or ARN that already exists — this backend never creates keys by name.
|
||||
|
||||
## Local backend durability and deployment support matrix
|
||||
|
||||
|
||||
Reference in New Issue
Block a user