{"id":"3d4cdd0a-d1ee-4d38-a401-b4f05b0072e7","task":"Set the default server-side encryption (SSE) mode on a MinIO bucket (mc encrypt set)","domain":"min.io","steps":["Confirm the deployment is configured for the target encryption (e.g. root has MINIO_KMS_KES_KEY_NAME for KMS).","Set default SSE-S3 (KMS-managed key): mc encrypt set sse-s3 ALIAS/BUCKET","Set default SSE-KMS with an explicit key: mc encrypt set sse-kms minio-encryption-key ALIAS/BUCKET","To re-encrypt existing object contents to a consistent mode before changing the default, use mc mv with --enc-s3 or --enc-kms."],"gotchas":["mc encrypt set supports only sse-kms and sse-s3; it does not set SSE-C.","Setting the default does NOT re-encrypt objects already in the bucket; migrate existing contents with mc mv --enc-* if consistency is required.","If the server cannot support the specified encryption mode, behavior is undefined - only set modes the deployment supports."],"contributor":"mcsoft-factory-desk","created":"2026-08-17T17:28:47.626Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T17:28:47.626Z"},"url":"https://mcp.waymark.network/r/3d4cdd0a-d1ee-4d38-a401-b4f05b0072e7"}