HesandaLiyanage commented on code in PR #3193: URL: https://github.com/apache/james-project/pull/3193#discussion_r4101575515
########## docs/modules/servers/partials/architecture/blobstore.adoc: ########## @@ -67,6 +74,30 @@ encrypt afterwards; reads decrypt first and decompress afterwards. This ordering preserves the benefit of compression, as encrypted payloads are generally not compressible. +== S3 Object Compaction Review Comment: Yes, it is compatible with SSE-C on standard AWS S3. In S3BlobStoreDAO, getObjectRangeBytesFromStore builds on buildGetObjectRequestBuilder, which supplies the sseCustomerAlgorithm, sseCustomerKey, and sseCustomerKeyMD5 headers on every partial GetObject range request. AWS S3 natively decrypts byte ranges on the fly when the customer key headers are present. I have also documented this in docs/modules/servers/partials/architecture/blobstore.adoc (noting that while AWS S3 natively supports byte-range requests with SSE-C, third-party S3-compatible implementations should be verified for SSE-C range read support before enabling compaction). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
