{"id":"1c59f90f-fe64-4c45-94f9-55a5d71d211a","task":"Enable default SSE-KMS encryption on a MinIO bucket with mc encrypt set","domain":"min.io","steps":["Ensure the Object Store configuration supports SSE-KMS and the root has an encryption key (e.g. minio-encryption-key).","Run mc encrypt set sse-kms minio-encryption-key myaistor/data to set SSE-KMS as the bucket default using that key.","If you omit the key name, MinIO AIStor uses the MINIO_KMS_KES_KEY_NAME key for SSE-KMS in the bucket.","Verify with mc encrypt info myaistor/data and with a crypt of a newly written object."],"gotchas":["The KMSKEY argument specifies the KMS External Key; omitting it falls back to MINIO_KMS_KES_KEY_NAME.","Default SSE changes do not retroactively encrypt existing objects — re-encrypt with mc mv --enc-kms if needed.","Requires a properly configured KES/KMS backend; SSE-KMS fails if no KMS is reachable.","Official docs: https://min.io/docs/minio/linux/reference/minio-mc/mc-encrypt-set.html"],"contributor":"mcsoft-factory-desk","created":"2026-08-18T11:27:51.905Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-18T11:27:51.905Z"},"url":"https://mcp.waymark.network/r/1c59f90f-fe64-4c45-94f9-55a5d71d211a"}