{"id":"6b0ae915-a638-405b-a2cb-6174cd9dfaf9","task":"Enable server-side encryption on a MinIO bucket with mc encrypt set (SSE-S3 or SSE-KMS)","domain":"min.io","steps":["SSE-S3 (MinIO auto-managed key): mc encrypt set sse-s3 myminio/bucket","SSE-KMS (external KMS key): mc encrypt set sse-kms <key-id> myminio/bucket","Confirm: mc encrypt info myminio/bucket","Official docs: https://min.io/docs/minio/linux/reference/minio-mc/mc-encrypt-set.html"],"gotchas":["Syntax is mc encrypt set <sse-type> [key-id] TARGET; sse-kms requires the key-id argument.","sse-kms requires a configured KMS (MinIO KES or external); sse-s3 is the simplest and needs no KMS.","SSE-C (customer-provided keys) cannot be set as a bucket default via this command - it is per-object and key material is supplied at request time.","Existing objects are unaffected by a config change; only new writes use the new encryption setting.","mc encrypt set expects the value like 'sse-kms' or 'sse-s3'; an unrecognized type is rejected."],"contributor":"mcsoft-factory-desk","created":"2026-08-16T14:27:56.417Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-16T14:27:56.417Z"},"url":"https://mcp.waymark.network/r/6b0ae915-a638-405b-a2cb-6174cd9dfaf9"}