-
-
Notifications
You must be signed in to change notification settings - Fork 4.2k
add S3 native bucket encryption and AWS KMS managed key #8800
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
e35c322
to
504c433
Compare
81449f1
to
c093df0
Compare
6abdab2
to
08162e0
Compare
c093df0
to
2e33061
Compare
08162e0
to
1fd8bd6
Compare
7da064e
to
0283e23
Compare
1fd8bd6
to
e77d9bf
Compare
0283e23
to
af89c04
Compare
e77d9bf
to
61947dd
Compare
af89c04
to
86ed54e
Compare
61947dd
to
0888220
Compare
86ed54e
to
d526d3c
Compare
0888220
to
e86455d
Compare
d526d3c
to
da072db
Compare
macnev2013
approved these changes
Aug 10, 2023
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great PR. 🚀 LGTM
Just a minor question.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
aws:s3
Amazon Simple Storage Service
semver: minor
Non-breaking changes which can be included in minor releases, but not in patch releases
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR implements Bucket Encryption, and sets the new default to
AES256
like AWS does since April 2023.It also implements a feature we've been missing, when not specifying a KMS KeyId when using
aws:kms
encryption, we're now creating and keeping the reference to the AWS managed key. We're however missing an internal way to specify that the key is "AWS managed", and not customer managed.