minio/pkg/fips
Andreas Auernhammer 3455f786fa kms: encrypt IAM/config data with the KMS (#12041)
This commit changes the config/IAM encryption
process. Instead of encrypting config data
(users, policies etc.) with the root credentials
MinIO now encrypts this data with a KMS - if configured.

Therefore, this PR moves the MinIO-KMS configuration (via
env. variables) to a "top-level" configuration.
The KMS configuration cannot be stored in the config file
since it is used to decrypt the config file in the first
place.

As a consequence, this commit also removes support for
Hashicorp Vault - which has been deprecated anyway.

Signed-off-by: Andreas Auernhammer <aead@mail.de>
2021-04-22 09:51:09 -07:00
..
api.go add new pkg/fips for FIPS 140-2 (#12051) 2021-04-14 08:29:56 -07:00
fips.go kms: encrypt IAM/config data with the KMS (#12041) 2021-04-22 09:51:09 -07:00
no_fips.go add new pkg/fips for FIPS 140-2 (#12051) 2021-04-14 08:29:56 -07:00