Skip to content

feat(object-storage): document Key Manager permissions required for SSE-KMS - #6788

Open
dulacp wants to merge 3 commits into
scaleway:mainfrom
dulacp:ext-add-object-storage
Open

feat(object-storage): document Key Manager permissions required for SSE-KMS#6788
dulacp wants to merge 3 commits into
scaleway:mainfrom
dulacp:ext-add-object-storage

Conversation

@dulacp

@dulacp dulacp commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Your checklist for this pull request

Description

Enabling SSE-KMS on a bucket requires the IAM principal that reads and writes objects to hold Key Manager permission sets, in addition to its Object Storage ones. That requirement is not documented on the SSE-KMS pages, and it costs a failed deployment to discover.

I was able to confirm it on a small project, failing to upload a document on S3 without KeyManagerKeyEncrypt.

@dulacp
dulacp requested review from a team as code owners August 13, 2026 11:24
Comment thread pages/iam/reference-content/permission-sets.mdx Outdated
Comment thread pages/object-storage/api-cli/enable-sse-kms.mdx Outdated
Comment thread pages/object-storage/how-to/enable-sse-kms.mdx Outdated
@vanda-scw vanda-scw added do not merge PR that shouldn't be merged before a specific date (eg release) status: tech review Waiting for technical review labels Aug 13, 2026
Co-authored-by: vanda-scw <villyes@scaleway.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do not merge PR that shouldn't be merged before a specific date (eg release) status: tech review Waiting for technical review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants