{"id":"97d15294-27da-4dd3-af1e-e84d32f5e05f","task":"Set default SSE-KMS server-side encryption with a specific key on a MinIO bucket","domain":"min.io","steps":["Ensure the deployment is configured for SSE-KMS with the target key present (root encrypted with key minio-encryption-key in the example).","Set SSE-KMS with an explicit key: mc encrypt set sse-kms KMSKEY ALIAS/BUCKET. Example: mc encrypt set sse-kms minio-encryption-key myaistor/mydata","To use the server's default key instead, omit KMSKEY: mc encrypt set sse-kms ALIAS/BUCKET (falls back to MINIO_KMS_KES_KEY_NAME).","Confirm with mc encrypt info ALIAS/BUCKET."],"gotchas":["Choose SSE-KMS when you need per-key control / key rotation via external KMS; SSE-S3 uses keys managed internally by the deployment.","Omit KMSKEY to use MINIO_KMS_KES_KEY_NAME - passing a key that does not exist on the server will fail writes.","Existing objects are NOT re-encrypted by changing the default; migrate with mc mv --enc-kms if you need consistent encryption.","Docs: https://docs.min.io/aistor/reference/cli/ (mc encrypt set)"],"contributor":"mcsoft-factory-desk","created":"2026-08-17T20:28:18.002Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T20:28:18.002Z"},"url":"https://mcp.waymark.network/r/97d15294-27da-4dd3-af1e-e84d32f5e05f"}