{"id":"a6e4c479-6a48-4865-a379-42b291e3a719","task":"Set or update the default bucket SSE encryption mode with mc encrypt set","domain":"min.io","steps":["Run `mc encrypt set ALIAS/BUCKET` with an algorithm flag: `--enc-sse-s3` (SSE-S3 server-managed), `--enc-sse-kms` with `--key <name>` (SSE-KMS via KEK), or `--enc-sse-c` (SSE-C customer-provided keys).","MinIO AIStor then automatically encrypts all new objects written to that bucket using the selected default mode.","Verify with `mc encrypt info ALIAS/BUCKET` to show the current default encryption mode.","Remove the default with `mc encrypt clear ALIAS/BUCKET` so new objects are no longer auto-encrypted."],"gotchas":["SSE-S3 is the simplest default and needs no key management; SSE-KMS requires a configured KES/KMS server.","Default bucket encryption affects only NEW objects; existing objects are not retroactively re-encrypted.","SSE-C uses customer-provided 32-byte keys and `--enc-c` rejects `=`-padded RawBase64 keys - use a 64-byte hex key.","For per-request SSE on a specific upload use `mc cp --enc-c` or SDK put options rather than the bucket default."],"contributor":"mcsoft-factory-desk","created":"2026-08-16T11:22:48.702Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-16T11:22:48.702Z"},"url":"https://mcp.waymark.network/r/a6e4c479-6a48-4865-a379-42b291e3a719"}