Updated on 2026-08-14 GMT+08:00

Configuring Bucket Encryption (SDK for Java)

Function

After you enable encryption for a bucket, the objects you upload to this bucket will be encrypted with the specified encryption method before they are stored in OBS. When you later download these encrypted objects, OBS decrypts them first and then returns them to you. This API is used to configure or update encryption for a bucket.

Restrictions

Method

obsClient.setBucketEncryption(SetBucketEncryptionRequest request)

Request Parameters

Table 1 List of request parameters

Parameter

Type

Mandatory (Yes/No)

Description

request

Table 2

Yes

Explanation:

Request parameters for configuring encryption for a bucket. For details, see Table 2.

Table 2 SetBucketEncryptionRequest

Parameter

Type

Mandatory (Yes/No)

Description

bucketName

String

Yes

Explanation:

Bucket name.

Restrictions:

  • A bucket name must be unique across all accounts and regions.
  • A bucket name:
    • Must be 3 to 63 characters long and start with a digit or letter. Lowercase letters, digits, hyphens (-), and periods (.) are allowed.
    • Cannot be formatted as an IP address.
    • Cannot start or end with a hyphen (-) or period (.).
    • Cannot contain two consecutive periods (..), for example, my..bucket.
    • Cannot contain a period (.) and a hyphen (-) adjacent to each other, for example, my-.bucket or my.-bucket.
  • If you repeatedly create buckets with the same name in the same region, no error will be reported and the bucket properties comply with those set in the first creation request.

Default value:

None

bucketEncryption

BucketEncryption

Yes

Explanation:

Bucket encryption configuration.

Value range:

For details, see Table 3.

Default value:

None

Table 3 BucketEncryption

Parameter

Type

Mandatory (Yes/No)

Description

sseAlgorithm

SSEAlgorithmEnum

Yes

Explanation:

Server-side encryption method.

Value range:

See Table 4.

Default value:

None

kmsKeyId

String

No

Explanation:

KMS master key used for SSE-KMS.

Value range:

Valid value formats are as follows:

  • regionID:domainID:key/key_id
  • key_id

In the preceding formats:

Default value:

If this parameter is not specified, the default master key will be used.

Table 4 SSEAlgorithmEnum

Constant

Default Value

Description

KMS

kms

Objects are encrypted using SSE-KMS.

AES256

AES256

Objects are encrypted using SSE-OBS.

Responses

Table 5 Common response headers

Parameter

Type

Description

statusCode

int

Explanation:

HTTP status code.

Value range:

A status code is a group of digits that can be 2xx (indicating successes) or 4xx or 5xx (indicating errors). It indicates the status of a response.

For more information, see Status Code.

Default value:

None

responseHeaders

Map<String, Object>

Explanation:

HTTP response header list, composed of tuples. In a tuple, the String key indicates the name of the header, and the Object value indicates the value of the header.

Default value:

None

Code Examples

This example sets a bucket's encryption method to KMS.
import com.obs.services.ObsClient;
import com.obs.services.exception.ObsException;
import com.obs.services.model.AccessControlList;
import com.obs.services.model.BucketEncryption;
import com.obs.services.model.ObsBucket;
import com.obs.services.model.SSEAlgorithmEnum;

public class SetBucketEncryption {
    public static void main(String[] args) {
        // Obtain an AK/SK pair using environment variables or import the AK/SK pair in other ways. Using hard coding may result in leakage.
        // Obtain an AK/SK pair on the management console.
        String ak = System.getenv("ACCESS_KEY_ID");
        String sk = System.getenv("SECRET_ACCESS_KEY_ID");
        // (Optional) If you are using a temporary AK/SK pair and a security token to access OBS, you are advised not to use hard coding, which may result in information leakage.
        // Obtain an AK/SK pair and a security token using environment variables or import them in other ways.
        // String securityToken = System.getenv("SECURITY_TOKEN");
        // Enter the endpoint corresponding to the bucket. CN-Hong Kong is used here as an example. Replace it with the one currently in use.
        String endPoint = "https://obs.ap-southeast-1.myhuaweicloud.com";
        // Obtain an endpoint using environment variables or import it in other ways.
        // String endPoint = System.getenv("ENDPOINT");
        
        // Create an ObsClient instance.
        // Use a permanent AK/SK pair to initialize the client.
        ObsClient obsClient = new ObsClient(ak, sk, endPoint);
        // Use a temporary AK/SK pair and security token to initialize the client.
        // ObsClient obsClient = new ObsClient(ak, sk, securityToken, endPoint);
        try {
            String exampleBucket = "examplebucket";
            // Specify the encryption method. SSE-KMS is used as an example.
            BucketEncryption encryption = new BucketEncryption(SSEAlgorithmEnum.KMS);
            obsClient.setBucketEncryption(exampleBucket, encryption);
            System.out.println("SetBucketEncryption successfully");
        } catch (ObsException e) {
            System.out.println("SetBucketEncryption failed");
            // Request failed. Print the HTTP status code.
            System.out.println("HTTP Code:" + e.getResponseCode());
            // Request failed. Print the server-side error code.
            System.out.println("Error Code:" + e.getErrorCode());
            // Request failed. Print the error details.
            System.out.println("Error Message:" + e.getErrorMessage());
            // Request failed. Print the request ID.
            System.out.println("Request ID:" + e.getErrorRequestId());
            System.out.println("Host ID:" + e.getErrorHostId());
            e.printStackTrace();
        } catch (Exception e) {
            System.out.println("SetBucketEncryption failed");
            // Print other error information.
            e.printStackTrace();
        }
    }
}