Resources

Encrypt Object Storage data with your own keys

Published on: October 8, 2026

Managed Object Storage encrypts all data at rest with keys that UpCloud manages. To keep the encryption keys under your own control, use one of the following methods:

MethodWhere data is encryptedFile names encryptedClient
Customer-provided keys (SSE-C)In Object Storage, with a key you send with each requestNoAWS CLI and other S3 clients that support SSE-C
rclone cryptOn your computer, before uploadYesrclone
s3cmd with GPGOn your computer, before uploadNos3cmd

With every method, losing the key or password means losing access to the data. Store them somewhere safe, separate from the data.

The examples use the bucket example-bucket and the endpoint abcd1.upcloudobjects.com. Replace them with your own. To find your endpoint and create access keys, see Get started with Managed Object Storage.

Customer-provided keys (SSE-C)

With SSE-C, you send your own 256-bit key with each upload and download request. An object uploaded with a key can only be read by requests that include the same key.

  1. Set up the AWS CLI for your Object Storage instance. Add the following lines to your profile in ~/.aws/config:

    request_checksum_calculation = when_required
    response_checksum_validation = when_required
  2. Generate a random 256-bit key:

    openssl rand -out sse-c.key 32

    The key file must contain the 32 raw bytes that this command creates. A base64-encoded key, such as the output of openssl rand -base64 32, doesn't work, and uploads with it fail:

    upload failed: ./report.pdf to s3://example-bucket/report.pdf An error occurred (InternalError) when calling the PutObject operation (reached max retries: 2): We encountered an internal error. Please try again.
  3. Upload a file with the key:

    aws s3 cp report.pdf s3://example-bucket/report.pdf --sse-c AES256 --sse-c-key fileb://sse-c.key
  4. Download the file with the same key:

    aws s3 cp s3://example-bucket/report.pdf report.pdf --sse-c AES256 --sse-c-key fileb://sse-c.key

    A request without the key, or with a different key, fails:

    fatal error: An error occurred (400) when calling the HeadObject operation: Bad Request

To see the encryption details of an object, include the key with head-object:

aws s3api head-object --bucket example-bucket --key report.pdf --sse-customer-algorithm AES256 --sse-customer-key fileb://sse-c.key
{
    "LastModified": "2026-10-08T11:32:10+00:00",
    "ContentLength": 1048576,
    "ETag": "\"0c5aa83b91201fee45425e3b2d0ce3b1\"",
    "ContentType": "application/octet-stream",
    "Metadata": {},
    "SSECustomerAlgorithm": "AES256",
    "SSECustomerKeyMD5": "WqANna27MhljjbfdoH+JMw=="
}

You can use a different key for each object. Keep track of which key belongs to which object, because requests with any other key fail.

rclone crypt

rclone can encrypt file contents and file names on your computer before uploading them. You set up a regular S3 remote for your Object Storage instance, and a crypt remote on top of it that encrypts everything passing through.

  1. Install rclone.

  2. Create a remote for your Object Storage instance. Replace the access key, secret key, and endpoint with your own:

    rclone config create upcloud s3 provider=Other access_key_id=<access-key> secret_access_key=<secret-key> endpoint=https://abcd1.upcloudobjects.com
  3. Create a crypt remote that stores encrypted files in a folder in your bucket. Replace the password with your own:

    rclone config create upcloud-crypt crypt remote=upcloud:example-bucket/encrypted password=<your-password>
  4. Copy files through the crypt remote:

    rclone copy documents upcloud-crypt:documents

Listing the files through the crypt remote shows the original names:

rclone ls upcloud-crypt:
  1048576 documents/sample.bin
       17 documents/report-2026-q3.txt

In the bucket itself, the names and contents are encrypted:

rclone ls upcloud:example-bucket/encrypted
  1048864 2f2thu2e58gl8q5jvr8aujkhgg/o89df4ks4ujapn6qhc4455pevk
       65 2f2thu2e58gl8q5jvr8aujkhgg/qqumhgejgmd0n4bblnmton6tn9lbn9tm59mp3fcg6ppk9rr5qge0

To download and decrypt the files, copy them back through the crypt remote:

rclone copy upcloud-crypt:documents restored

To check that the uploaded files match the local ones, run:

rclone cryptcheck documents upcloud-crypt:documents
NOTICE: Encrypted drive 'upcloud-crypt:documents': 0 differences found
NOTICE: Encrypted drive 'upcloud-crypt:documents': 2 matching files

To read the files on another computer, create the same remotes there with the same password.

s3cmd with GPG

s3cmd can encrypt files with GPG before uploading them.

  1. Set up s3cmd for your Object Storage instance. When the configuration wizard asks for an Encryption password, enter the password to encrypt files with. You can also set it later as gpg_passphrase in ~/.s3cfg.

  2. Upload a file with the --encrypt option:

    s3cmd put --encrypt report-2026-q3.txt s3://example-bucket/report-2026-q3.txt
  3. Download the file. s3cmd decrypts it automatically:

    s3cmd get s3://example-bucket/report-2026-q3.txt

The object is stored as a GPG-encrypted file, so you can also decrypt it with GPG and the same password after downloading it with any S3 client:

gpg --decrypt report-2026-q3.txt > report-decrypted.txt

File names are not encrypted. s3cmd also stores some details of the original file as object metadata, including its MD5 checksum, owner, and timestamps.

Contributed by: Samir Haliru

Can't find what you're looking for?

For more help you can contact our awesome 24/7 support team