cloudnative-pg / cloudnative-pg/plugin-barman-cloud

[Feature request] Support for S3 SSE-C - Server-Side Encryption with Customer-provided keys

Ouverte
#646 8 commentaires 34 réactions 0 personnes assignées Voir sur GitHub
enhancement
Langage dominant
Go
Étoiles
191
Forks
72
Merge moyen
1 j 16 h
PR mergées (30 j)
18

Description

I'm using k3s on Hetzner Cloud (https://docs.hetzner.com/storage/object-storage/faq/general#what-configuration-and-security-features-are-currently-supported) and running a PostgreSQL cluster with cnpg. I tried to configure barman-cloud for automatic backups to Hetzner S3 storage, but it seems that this is only possible without encryption.

Currently, Hetzner S3 only supports SSE-C (which means you have to provide an encryption key). I don't really understand what the option `encryption: AES256` means in context of S3 encryption, but I assume for SSE-C there are more options required - at least for providing a secret containing the SSE-C key.

Any chance to get SSE-C support in barman-cloud? I've spend much time in securing my k8s setup (node encryption, pv encryption etc.) and storing plaintext backups in external storage makes this whole effort pointless 😞

BTW: if I just enable `encryption: ASE265`, barman-cloud fails with this log line:

````
{"level":"info","ts":"2025-11-06T19:57:05.717632266Z","logger":"barman-cloud-wal-archive","msg":"2025-11-06 19:57:05,717 [947] ERROR: Barman cloud WAL archiver exception: An error occurred (InvalidArgument) when calling the PutObject operation: None","pipe":"stderr","logging_pod":"my-pg-cluster-1"}
````

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez au point d’entrée de barman-cloud WAL archiver et suivez la gestion existante de `encryption: AES256` jusqu’à l’appel S3 `PutObject` présenté dans le rapport. Examinez comment les secrets de configuration sont fournis, puis identifiez les tests d’upload pertinents ou ajoutez une couverture pour les entrées SSE-C demandées. C’est terminé lorsque les uploads SSE-C fonctionnent pour le stockage compatible avec S3 signalé, sans l’erreur `InvalidArgument`.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
go, postgresql
Domaine
cloud, databases
Type d'issue
Fonctionnalité
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Calme
Clarté
Plutôt claire
Accessibilité débutants
45/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.