Server-Side Encryption (SSE-C)
Relution can encrypt the objects it stores in an S3-compatible bucket using Server-Side Encryption with a Customer-Provided Key (SSE-C). With SSE-C, Relution sends the encryption key with every request, and the storage backend uses it to encrypt objects on write and decrypt them on read. The backend never stores the key itself - keeping it safe is solely the administrator’s responsibility.
Prerequisites
- A working S3-compatible object storage setup - see Connect object storage →.
- An object storage backend that supports SSE-C. We have verified support with SeaweedFS and Hetzner Object Storage. Other S3-compatible backends may work but have not been tested.
- A 256-bit encryption key (see below).
Generating the Key
SSE-C requires a 256-bit (32-byte) key, provided as a Base64-encoded string. Generate one with openssl:
openssl rand -base64 32
Store the resulting value securely. If this key is lost, all encrypted objects in the S3 bucket can no longer be decrypted and are permanently lost.
Configuration
SSE-C is activated as soon as a key is configured. The key can either be provided inline via the relution.storage.s3.serverSideEncryption.key property (options A and B) or supplied as a file via relution.storage.s3.serverSideEncryption.keyFile (option C). If both are set, the key file takes precedence.
Option A: Using application.yml
Add the serverSideEncryption block to the application.yml:
relution:
storage:
resourceStorageType: S3
s3:
customEndpoint: http://seaweedfs:8333
accessKey: %YOUR-ACCESS-KEY%
secretKey: %YOUR-SECRET-KEY%
bucketName: relution
serverSideEncryption:
key: %YOUR-BASE64-KEY%
Option B: Using Environment Variables
Add the following environment variable to the relution service in the compose.yml:
services:
relution:
environment:
- RELUTION_STORAGE_S3_SERVERSIDEENCRYPTION_KEY=%YOUR-BASE64-KEY%
Option C: Key as a file
New in 26.5Instead of providing the key inline, it can be read from a file. This is particularly useful when the key is mounted into the container as a Docker or Kubernetes secret. The path to the key file is configured via relution.storage.s3.serverSideEncryption.keyFile:
relution:
storage:
s3:
serverSideEncryption:
keyFile: /path/to/ssec.key
Or via the corresponding environment variable:
services:
relution:
environment:
- RELUTION_STORAGE_S3_SERVERSIDEENCRYPTION_KEYFILE=/path/to/ssec.key
The file must contain the same Base64-encoded 256-bit key as the inline value (for example, generated with openssl rand -base64 32). A trailing newline is harmless because the value is trimmed; binary or hexadecimal keys are rejected.
On startup, Relution logs the read with Reading SSE-C key from file <path>. If the file is missing or does not contain a 32-byte key, startup aborts with a corresponding error message.