refactor(sse): decouple ecstore and harden KMS lifecycle (#5435)

* refactor(sse): decouple encryption from ecstore

* feat(kms): enhance KMS service manager with runtime state and persistence support

* feat(kms): add local key export functionality for SSE-S3 migration tests

* fix(kms): keep local key export narrowly scoped

* fix(sse): validate copy source customer algorithm

---------

Co-authored-by: Zhengchao An <anzhengchao@gmail.com>
This commit is contained in:
唐小鸭
2026-07-30 12:39:25 +08:00
committed by GitHub
parent 6e6b38ad8e
commit ad7663afd1
30 changed files with 1486 additions and 1951 deletions
@@ -137,7 +137,7 @@ tests read):
./capture_via_docker.sh
RUSTFS_MINIO_STATIC_KMS_KEY_B64=IyqsU3kMFloCNup4BsZtf/rmfHVcTgznO2F25CkEH1g= \
cargo test -p rustfs-ecstore --features rio-v2 --test minio_generated_read_test -- --ignored
cargo test -p rustfs --features rio-v2 storage::minio_generated_read_test --lib -- --ignored
```
This is exactly what the nightly `minio-interop` GitHub Actions workflow runs