forked from minio/minio-go
-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathputobject-client-encryption.go
90 lines (77 loc) · 2.72 KB
/
putobject-client-encryption.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
// +build ignore
/*
* Minio Go Library for Amazon S3 Compatible Cloud Storage
* Copyright 2018 Minio, Inc.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package main
import (
"log"
"os"
"path"
"github.com/minio/minio-go"
"github.com/minio/sio"
"golang.org/x/crypto/argon2"
)
const (
// SSE DARE package block size.
sseDAREPackageBlockSize = 64 * 1024 // 64KiB bytes
// SSE DARE package meta padding bytes.
sseDAREPackageMetaSize = 32 // 32 bytes
)
// EncryptedSize returns the size of the object after encryption.
// An encrypted object is always larger than a plain object
// except for zero size objects.
func getEncryptedSize(size int64) int64 {
ssize := (size / sseDAREPackageBlockSize) * (sseDAREPackageBlockSize + sseDAREPackageMetaSize)
if mod := size % (sseDAREPackageBlockSize); mod > 0 {
ssize += mod + sseDAREPackageMetaSize
}
return ssize
}
func main() {
// Note: YOUR-ACCESSKEYID, YOUR-SECRETACCESSKEY, my-testfile, my-bucketname and
// my-objectname are dummy values, please replace them with original values.
// Requests are always secure (HTTPS) by default. Set secure=false to enable insecure (HTTP) access.
// This boolean value is the last argument for New().
// New returns an Amazon S3 compatible client object. API compatibility (v2 or v4) is automatically
// determined based on the Endpoint value.
s3Client, err := minio.New("s3.amazonaws.com", "YOUR-ACCESSKEYID", "YOUR-SECRETACCESSKEY", true)
if err != nil {
log.Fatalln(err)
}
object, err := os.Open("my-testfile")
if err != nil {
log.Fatalln(err)
}
defer object.Close()
objectStat, err := object.Stat()
if err != nil {
log.Fatalln(err)
}
password := []byte("myfavoritepassword") // Change as per your needs.
salt := []byte(path.Join("my-bucketname", "my-objectname")) // Change as per your needs.
encrypted, err := sio.EncryptReader(object, sio.Config{
// generate a 256 bit long key.
Key: argon2.IDKey(password, salt, 1, 64*1024, 4, 32),
})
if err != nil {
log.Fatalln(err)
}
_, err = s3Client.PutObject("my-bucketname", "my-objectname", encrypted, getEncryptedSize(objectStat.Size()), minio.PutObjectOptions{})
if err != nil {
log.Fatalln(err)
}
log.Println("Successfully encrypted 'my-objectname'")
}