Configuring Bucket Encryption
Function
After you enable encryption for a bucket, the objects you upload to this bucket will be encrypted with the specified encryption method before they are stored in OBS. When you later download these encrypted objects, OBS decrypts them first and then returns them to you. This API is used to configure or update encryption for a bucket.
Restrictions
- To configure encryption for a bucket, you must be the bucket owner or have the required permission (obs:bucket:PutEncryptionConfiguration in IAM or PutEncryptionConfiguration in a bucket policy). For details, see Introduction to OBS Access Control, IAM Custom Policies, and Creating a Custom Bucket Policy.
- The mapping between OBS regions and endpoints must comply with what is listed in Regions and Endpoints.
Method
obsClient.setBucketEncryption(SetBucketEncryptionRequest request)
Request Parameters
| Parameter | Type | Mandatory (Yes/No) | Description |
|---|---|---|---|
| request | Yes | Explanation: Request parameters for configuring encryption for a bucket. For details, see Table 2. |
| Parameter | Type | Mandatory (Yes/No) | Description |
|---|---|---|---|
| bucketName | String | Yes | Explanation: Bucket name. Restrictions:
Default value: None |
| bucketEncryption | Yes | Explanation: Bucket encryption configuration. Value range: For details, see Table 3. Default value: None |
| Parameter | Type | Mandatory (Yes/No) | Description |
|---|---|---|---|
| sseAlgorithm | Yes | Explanation: Server-side encryption method. Value range: See Table 4. Default value: None | |
| kmsKeyId | String | No | Explanation: KMS master key used for SSE-KMS. Value range: Valid value formats are as follows:
In the preceding formats:
Default value: If this parameter is not specified, the default master key will be used. |
Responses
| Parameter | Type | Description |
|---|---|---|
| statusCode | int | Explanation: HTTP status code. Value range: A status code is a group of digits that can be 2xx (indicating successes) or 4xx or 5xx (indicating errors). It indicates the status of a response. For more information, see Status Code. Default value: None |
| responseHeaders | Map<String, Object> | Explanation: HTTP response header list, composed of tuples. In a tuple, the String key indicates the name of the header, and the Object value indicates the value of the header. Default value: None |
Sample Code
This example sets a bucket's encryption method to KMS.
import android.util.Log;
import com.obs.services.ObsClient;
import com.obs.services.exception.ObsException;
import com.obs.services.model.BucketEncryption;
import com.obs.services.model.HeaderResponse;
import com.obs.services.model.SSEAlgorithmEnum;
// Note: Network operations must be performed in a child thread. Otherwise, NetworkOnMainThreadException will be thrown.
new Thread(() -> {
// Security warning: Hard-coded AK and SK are risky. You are advised to obtain the AK and SK from the security credential management system.
String ak = System.getenv("ACCESS_KEY_ID");
String sk = System.getenv("SECRET_ACCESS_KEY");
String endPoint = "https://your-endpoint";
ObsClient obsClient = null;
try {
obsClient = new ObsClient(ak, sk, endPoint);
String bucketName = "examplebucket";
// Set the bucket's encryption method to KMS.
BucketEncryption encryption = new BucketEncryption();
encryption.setSseAlgorithm(SSEAlgorithmEnum.KMS);
HeaderResponse response = obsClient.setBucketEncryption(bucketName, encryption);
Log.i("ObsDemo", "Configured the bucket encryption successfully. statusCode: " + response.getStatusCode());
} catch (ObsException e) {
Log.e("ObsDemo", "Failed to configure the bucket encryption. HTTP status code: " + e.getResponseCode()
+ ". Error code: " + e.getErrorCode()
+ ". Error message: " + e.getErrorMessage());
} finally {
if (obsClient != null) {
try {
obsClient.close();
} catch (Exception e) {
Log.e("ObsDemo", "Failed to close ObsClient.", e);
}
}
}
}).start(); What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot