Skip to content

How to configure server-side encryption

How-to · Updated Jul 2026
Before this

How to configure server-side encryption

Use Server-Side Encryption with Customer-Provided Keys (SSE-C) to encrypt an object with a 256-bit key that you manage. Quake AI Object Storage applies AES-256 encryption and requires the same key for later read and metadata requests.

Prerequisites

Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.

  • An existing object storage bucket
  • S3 credentials with access to the bucket
  • AWS CLI configured with those credentials
  • OpenSSL for generating a key

Set the object details and generate a key#

Set variables for your bucket, local file, and object key. Generate a 256-bit, Base64-encoded encryption key:

bash
export BUCKET_NAME="YOUR_BUCKET_NAME"
export SOURCE_FILE="PATH_TO_YOUR_FILE"
export OBJECT_KEY="YOUR_OBJECT_KEY"
export SSE_C_KEY="$(openssl rand -base64 32)"

Store SSE_C_KEY in your key-management system before uploading the object. The shell variable lasts only for the current shell session.

Upload the encrypted object#

Verify the encrypted object#

Provide the same algorithm and key when you request object metadata:

bash
aws s3api head-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --sse-customer-algorithm AES256 \
  --sse-customer-key "$SSE_C_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud"

The response includes the object's content length, content type, last-modified time, ETag, and customer-key MD5. The ETag for an SSE-C object is not an MD5 hash of the object data.

The gateway returns 400 Bad Request if a head-object request omits the SSE-C headers. A get-object request without those headers returns InvalidArgument.

Download the encrypted object#

Provide the key with each download request:

bash
aws s3api get-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --sse-customer-algorithm AES256 \
  --sse-customer-key "$SSE_C_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud" \
  "DECRYPTED_OUTPUT_FILE"

Compare the downloaded file with the source:

bash
cmp "$SOURCE_FILE" "DECRYPTED_OUTPUT_FILE"

cmp exits without output when the files match.

Delete an encrypted object#

Deleting an SSE-C object requires permission to delete the object. It does not require the encryption key:

bash
aws s3api delete-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud"

Restrict delete permissions separately from access to the encryption key. Enable object versioning if you need to recover an object after an accidental delete.

Troubleshoot SSE-C requests#

  • The AWS CLI reports an unknown option: Use --sse-customer-algorithm and --sse-customer-key. The longer --server-side-encryption-customer-* option names are not valid AWS CLI flags.
  • The gateway rejects the key: Generate a 256-bit, Base64-encoded key with openssl rand -base64 32.
  • A read or metadata request fails: Provide the algorithm and key used for the upload.
  • The downloaded file does not match: Confirm that the request targets the correct bucket and object key, then compare it with cmp.
  • The request uses HTTP: Change the endpoint to HTTPS. SSE-C requests require an encrypted connection.

Next steps#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 10.07.2026

Was this page helpful?