Skip to content

Instantly share code, notes, and snippets.

View ideepika's full-sized avatar
🎯
Focusing

Deepika Upadhyay ideepika

🎯
Focusing
View GitHub Profile
@ideepika
ideepika / rgw_sse_s3_kmip.md
Created November 23, 2025 22:06 — forked from irq0/rgw_sse_s3_kmip.md
Proposal: KMIP Backend for SSE-S3

Proposal: KMIP Backend for SSE-S3

This document proposes adding support for the Key Management Interoperability Protocol (KMIP) as a backend for RGW's Server-Side Encryption with S3-Managed Keys (SSE-S3).

This feature will mirror the functionality of the existing HashiCorp Vault Transit backend, allowing a KMIP server to manage bucket-level Key Encryption Keys (KEKs) while RGW manages the creation and lifecycle of per-object Data Encryption Keys (DEKs).