mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-03 11:57:43 +00:00
5a195e8da0
KMS key management has no event vocabulary, so an audit consumer cannot name what happened to a key. Add the eight management-plane events at the tail of `EventName`, keeping every existing discriminant — and therefore every `mask()` bit — unchanged. The events live in their own `kms:` namespace and no compound `s3:` selector expands to them, so a bucket notification rule can never start matching key management activity. Regressions cover both directions of that isolation, plus the mask bit budget that a future tail append would otherwise overflow silently. Refs rustfs/backlog#1583 (part of rustfs/backlog#1562)