github.com/minio/minio@v0.0.0-20240328213742-3f72439b8a27/internal/kms/key-manager.go (about) 1 // Copyright (c) 2015-2022 MinIO, Inc. 2 // 3 // This file is part of MinIO Object Storage stack 4 // 5 // This program is free software: you can redistribute it and/or modify 6 // it under the terms of the GNU Affero General Public License as published by 7 // the Free Software Foundation, either version 3 of the License, or 8 // (at your option) any later version. 9 // 10 // This program is distributed in the hope that it will be useful 11 // but WITHOUT ANY WARRANTY; without even the implied warranty of 12 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 13 // GNU Affero General Public License for more details. 14 // 15 // You should have received a copy of the GNU Affero General Public License 16 // along with this program. If not, see <http://www.gnu.org/licenses/>. 17 18 package kms 19 20 import ( 21 "context" 22 23 "github.com/minio/kms-go/kes" 24 ) 25 26 // KeyManager is the generic interface that handles KMS key operations 27 type KeyManager interface { 28 // CreateKey creates a new key at the KMS with the given key ID. 29 CreateKey(ctx context.Context, keyID string) error 30 31 // DeleteKey deletes a key at the KMS with the given key ID. 32 // Please note that is a dangerous operation. 33 // Once a key has been deleted all data that has been encrypted with it cannot be decrypted 34 // anymore, and therefore, is lost. 35 DeleteKey(ctx context.Context, keyID string) error 36 37 // ListKeys lists all key names. 38 ListKeys(ctx context.Context) (*kes.ListIter[string], error) 39 40 // ImportKey imports a cryptographic key into the KMS. 41 ImportKey(ctx context.Context, keyID string, bytes []byte) error 42 43 // EncryptKey Encrypts and authenticates a (small) plaintext with the cryptographic key 44 // The plaintext must not exceed 1 MB 45 EncryptKey(keyID string, plaintext []byte, context Context) ([]byte, error) 46 47 // HMAC computes the HMAC of the given msg and key with the given 48 // key ID. 49 HMAC(ctx context.Context, keyID string, msg []byte) ([]byte, error) 50 }