Skip to content

feat: Add missed KMS support in msq durable storage and exports - #20543

Open
cryptoe wants to merge 1 commit into
apache:masterfrom
cryptoe:things
Open

cryptoe wants to merge 1 commit into
apache:masterfrom
cryptoe:things

Conversation

@cryptoe

@cryptoe cryptoe commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Description

MSQ durable storage and S3 exports write files with S3 multipart uploads, through RetryableS3OutputStream. KmsServerSideEncryption and S3ServerSideEncryption only added encryption settings to single
uploads and copies, not to the request that starts a multipart upload. Large durable-storage and export files therefore got the bucket's default encryption instead of the configured druid.storage.sse.*.
With kms, this meant keyId was never sent. Only files small enough for a single request were encrypted with the configured settings.

This PR adds the missing settings:

  • kms: adds aws:kms and ssekmsKeyId to the request that starts a multipart upload.
  • s3: adds AES256 to the request that starts a multipart upload.
  • custom: adds the customer key to both the start request and each part upload, because S3 needs the key on every part.

Release note

S3 server-side encryption (druid.storage.sse.type) now applies to multipart uploads in MSQ durable storage and S3 exports. Previously, large files fell back to the bucket's default encryption.

Upgrade notes:

  • Clusters using kms need no special upgrade order. Reading a KMS-encrypted object needs no extra request headers, so mixed versions and rollbacks work.
  • Before you upgrade, make sure that the KMS key policy grants kms:GenerateDataKey and kms:Decrypt to the roles that write these files, such as MSQ tasks. AWS requires kms:Decrypt for KMS-encrypted
    multipart uploads. Grant kms:Decrypt to everything that reads them, including Brokers that read MSQ query results and any systems outside Druid that read exported files.
  • With custom, large durable-storage objects that older tasks write during the upgrade may still fail to read, as they already do today. The failures stop once all services are upgraded.

Key changed/added classes in this PR
  • KmsServerSideEncryption
  • S3ServerSideEncryption
  • CustomServerSideEncryption
  • ServerSideEncryptionTest

This PR has:

  • been self-reviewed.
  • added documentation for new or modified features or behaviors.
  • a release note entry in the PR description.

@FrankChen021 FrankChen021 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No actionable issues found in this review. The multipart encryption decorators are correctly wired through the existing S3 wrapper; KMS and SSE-S3 apply at upload initiation, while SSE-C applies at initiation and to every part.

Reviewed 5 of 5 changed files.

Validation: git diff --check passed.


This is an automated review by Codex GPT-5.6-Luna(max)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants