Configuring Bucket Encryption
Function
After you enable encryption for a bucket, the objects you upload to this bucket will be encrypted with the specified encryption method before they are stored in OBS. When you later download these encrypted objects, OBS decrypts them first and then returns them to you.
This API is used to configure or update encryption for a bucket.
Restrictions
- To configure encryption for a bucket, you must be the bucket owner or have the required permission (obs:bucket:PutEncryptionConfiguration granted using IAM or PutEncryptionConfiguration granted using a bucket policy). For details, see Introduction to OBS Access Control, IAM Custom Policies, and Creating a Custom Bucket Policy.
- The mapping between OBS regions and endpoints must comply with what is listed in Regions and Endpoints.
Method
ObsClient.setBucketEncryption(params)
Request Parameters
| Parameter | Type | Mandatory (Yes/No) | Description |
|---|---|---|---|
| Bucket | string | Yes | Explanation: Bucket name Restrictions:
Default value: None |
| Rule | object | Yes | Explanation: Bucket encryption configuration rule. For details, see Table 2. |
| Parameter | Type | Mandatory (Yes/No) | Description |
|---|---|---|---|
| ApplyServerSideEncryptionByDefault | object | Yes | Explanation: Default encryption configuration of the bucket. For details, see Table 3. |
| BucketKeyEnabled | bool | No | Explanation: Whether to enable the OBS bucket key feature Restrictions:
Value range:
Default value: false |
| Parameter | Type | Mandatory (Yes/No) | Description |
|---|---|---|---|
| SSEAlgorithm | String | Yes | Explanation: Server-side encryption algorithm used for the default encryption configuration of a bucket Restrictions: N/A Value range:
Default value: N/A |
| KMSDataEncryption | String | No | Explanation: Encryption algorithm used in SSE-KMS mode Restrictions: N/A Value range: SM4: SM4 algorithm Default value: N/A |
| KMSMasterKeyID | String | No | Explanation: ID of the KMS master key used in SSE-KMS mode Restrictions:
Value range:
In the preceding formats:
Default value: N/A |
| ProjectID | String | No | Explanation: ID of the project where the KMS master key belongs in SSE-KMS mode Restrictions:
Value range: Project ID that matches KMSMasterKeyID, that is, the ID of the project to which the master key with the specified KMSMasterKeyID belongs Default value: N/A |
Responses
| Parameter | Type | Description |
| Status | number | Explanation: HTTP status code returned by the OBS server Value range: A status code is a group of digits indicating the status of a response. It ranges from 2xx (indicating successes) to 4xx or 5xx (indicating errors). For details, see Status Codes. |
| Code | string | Explanation: Error code returned by the OBS server |
| Message | string | Explanation: Error description returned by the OBS server |
| HostId | string | Explanation: Request server ID returned by the OBS server |
| RequestId | string | Explanation: Request ID returned by the OBS server |
| Id2 | string | Explanation: Request ID2 returned by the OBS server |
| Indicator | string | Explanation: Error code details returned by the OBS server |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot