Copyright | (c) 2013-2021 Brendan Hay |
---|---|
License | Mozilla Public License, v. 2.0. |
Maintainer | Brendan Hay <brendan.g.hay+amazonka@gmail.com> |
Stability | auto-generated |
Portability | non-portable (GHC extensions) |
Safe Haskell | None |
Synopsis
Documentation
data BucketServerSideEncryption Source #
Provides information about the default server-side encryption settings for an S3 bucket. For detailed information about these settings, see Setting default server-side encryption behavior for Amazon S3 buckets in the Amazon Simple Storage Service User Guide.
See: newBucketServerSideEncryption
smart constructor.
BucketServerSideEncryption' | |
|
Instances
newBucketServerSideEncryption :: BucketServerSideEncryption Source #
Create a value of BucketServerSideEncryption
with all optional fields omitted.
Use generic-lens or optics to modify other optional fields.
The following record fields are available, with the corresponding lenses provided for backwards compatibility:
$sel:kmsMasterKeyId:BucketServerSideEncryption'
, bucketServerSideEncryption_kmsMasterKeyId
- The Amazon Resource Name (ARN) or unique identifier (key ID) for the KMS
key that's used by default to encrypt objects that are added to the
bucket. This value is null if the bucket uses an Amazon S3 managed key
to encrypt new objects or the bucket doesn't encrypt new objects by
default.
$sel:type':BucketServerSideEncryption'
, bucketServerSideEncryption_type
- The type of server-side encryption that's used by default when storing
new objects in the bucket. Possible values are:
- AES256 - New objects are encrypted with an Amazon S3 managed key. They use SSE-S3 encryption.
- aws:kms - New objects are encrypted with an KMS key (kmsMasterKeyId), either an Amazon Web Services managed key or a customer managed key. They use SSE-KMS encryption.
- NONE - New objects aren't encrypted by default. Default encryption is disabled for the bucket.
bucketServerSideEncryption_kmsMasterKeyId :: Lens' BucketServerSideEncryption (Maybe Text) Source #
The Amazon Resource Name (ARN) or unique identifier (key ID) for the KMS key that's used by default to encrypt objects that are added to the bucket. This value is null if the bucket uses an Amazon S3 managed key to encrypt new objects or the bucket doesn't encrypt new objects by default.
bucketServerSideEncryption_type :: Lens' BucketServerSideEncryption (Maybe Type) Source #
The type of server-side encryption that's used by default when storing new objects in the bucket. Possible values are:
- AES256 - New objects are encrypted with an Amazon S3 managed key. They use SSE-S3 encryption.
- aws:kms - New objects are encrypted with an KMS key (kmsMasterKeyId), either an Amazon Web Services managed key or a customer managed key. They use SSE-KMS encryption.
- NONE - New objects aren't encrypted by default. Default encryption is disabled for the bucket.