-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathwrite_object.rb
More file actions
88 lines (81 loc) · 2.59 KB
/
Copy pathwrite_object.rb
File metadata and controls
88 lines (81 loc) · 2.59 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
# Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
# SPDX - License - Identifier: Apache - 2.0
require 'aws-sdk-s3'
require 'openssl'
# Uploads an object to an Amazon S3 bucket. The object's contents
# are encrypted with an RSA public key.
#
# Prerequisites:
#
# - An Amazon S3 bucket.
#
# @param s3_encryption_client [Aws::S3::EncryptionV2::Client] An initialized
# Amazon S3 encryption client.
# @param bucket_name [String] The bucket's name.
# @param object_key [String] The name of the object.
# @param object_content [String] The content to add to the object.
# @return [Boolean] true if the object was uploaded; otherwise, false.
# @example
# exit 1 unless object_uploaded_with_public_key_encryption?(
# Aws::S3::EncryptionV2::Client.new(
# encryption_key: OpenSSL::PKey::RSA.new(File.read('public-key.pem')),
# key_wrap_schema: :rsa_oaep_sha1,
# content_encryption_schema: :aes_gcm_no_padding,
# security_profile: :v2,
# region: 'us-east-1'
# ),
# 'doc-example-bucket',
# 'my-file.txt',
# 'This is the content of my-file.txt.'
# )
def object_uploaded_with_public_key_encryption?(
s3_encryption_client,
bucket_name,
object_key,
object_content
)
s3_encryption_client.put_object(
bucket: bucket_name,
key: object_key,
body: object_content
)
return true
rescue StandardError => e
puts "Error uploading object: #{e.message}"
return false
end
# Full example call:
# Prerequisites: an RSA key pair.
def run_me
bucket_name = 'my-bucket-kgo'
object_key = 'my-file.txt'
object_content = 'This is the content of my-file.txt.'
region = 'us-east-1'
public_key_file = 'public_key.pem'
public_key = OpenSSL::PKey::RSA.new(File.read(public_key_file))
# When initializing this Amazon S3 encryption client, note:
# - For key_wrap_schema, use rsa_oaep_sha1 for asymmetric keys.
# - For security_profile, for reading or decrypting objects encrypted
# by the v1 encryption client, use :v2_and_legacy instead.
s3_encryption_client = Aws::S3::EncryptionV2::Client.new(
access_key_id: '<put-accesskey-here>',
secret_access_key: '<put-secretkey-here>',
endpoint: 'https://s3.eu-central-1.wasabisys.com',
encryption_key: public_key,
key_wrap_schema: :rsa_oaep_sha1,
content_encryption_schema: :aes_gcm_no_padding,
security_profile: :v2,
region: region
)
if object_uploaded_with_public_key_encryption?(
s3_encryption_client,
bucket_name,
object_key,
object_content
)
puts 'Object uploaded.'
else
puts 'Object not uploaded.'
end
end
run_me if $PROGRAM_NAME == __FILE__