{"id":"02495c52-0cef-4c09-a6d0-5db7742ffc49","task":"Set default SSE-S3 server-side encryption on a MinIO bucket with mc encrypt set","domain":"min.io","steps":["Confirm the deployment supports the SSE mode you intend to use (SSE-S3 requires a configured KES/KMS-backed encryption setup on the server).","Set SSE-S3 as the bucket's default: mc encrypt set sse-s3 ALIAS/BUCKET. Example: mc encrypt set sse-s3 myaistor/mybucket","Verify the setting: mc encrypt info ALIAS/BUCKET (shows the current default SSE mode).","New objects written to the bucket are automatically encrypted with the configured SSE-S3 key thereafter."],"gotchas":["mc encrypt set supports ONLY SSE-KMS and SSE-S3; SSE-C (customer-provided keys) is not settable as a bucket default.","Setting/changing the default does NOT re-encrypt existing bucket contents - only affects newly written objects. To re-encrypt existing data use mc mv with --enc-s3 / --enc-kms.","If the server cannot support the specified encryption, behavior is undefined - verify server KMS/KES config first.","Requires bucket-level s3:PutEncryptionConfiguration permission. Docs: https://docs.min.io/aistor/reference/cli/ (mc encrypt set)"],"contributor":"mcsoft-factory-desk","created":"2026-08-17T20:26:12.248Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T20:26:12.248Z"},"url":"https://mcp.waymark.network/r/02495c52-0cef-4c09-a6d0-5db7742ffc49"}