Encrypt Object Storage data with your own keys
Managed Object Storage encrypts all data at rest with keys that UpCloud manages. To keep the encryption keys under your own control, use one of the following methods:
| Method | Where data is encrypted | File names encrypted | Client |
|---|---|---|---|
| Customer-provided keys (SSE-C) | In Object Storage, with a key you send with each request | No | AWS CLI and other S3 clients that support SSE-C |
| rclone crypt | On your computer, before upload | Yes | rclone |
| s3cmd with GPG | On your computer, before upload | No | s3cmd |
With every method, losing the key or password means losing access to the data. Store them somewhere safe, separate from the data.
The examples use the bucket example-bucket and the endpoint abcd1.upcloudobjects.com. Replace them with your own. To find your endpoint and create access keys, see Get started with Managed Object Storage.
Customer-provided keys (SSE-C)
With SSE-C, you send your own 256-bit key with each upload and download request. An object uploaded with a key can only be read by requests that include the same key.
Set up the AWS CLI for your Object Storage instance. Add the following lines to your profile in
~/.aws/config:request_checksum_calculation = when_required response_checksum_validation = when_requiredGenerate a random 256-bit key:
openssl rand -out sse-c.key 32The key file must contain the 32 raw bytes that this command creates. A base64-encoded key, such as the output of
openssl rand -base64 32, doesn't work, and uploads with it fail:upload failed: ./report.pdf to s3://example-bucket/report.pdf An error occurred (InternalError) when calling the PutObject operation (reached max retries: 2): We encountered an internal error. Please try again.Upload a file with the key:
aws s3 cp report.pdf s3://example-bucket/report.pdf --sse-c AES256 --sse-c-key fileb://sse-c.keyDownload the file with the same key:
aws s3 cp s3://example-bucket/report.pdf report.pdf --sse-c AES256 --sse-c-key fileb://sse-c.keyA request without the key, or with a different key, fails:
fatal error: An error occurred (400) when calling the HeadObject operation: Bad Request
To see the encryption details of an object, include the key with head-object:
aws s3api head-object --bucket example-bucket --key report.pdf --sse-customer-algorithm AES256 --sse-customer-key fileb://sse-c.key{
"LastModified": "2026-10-08T11:32:10+00:00",
"ContentLength": 1048576,
"ETag": "\"0c5aa83b91201fee45425e3b2d0ce3b1\"",
"ContentType": "application/octet-stream",
"Metadata": {},
"SSECustomerAlgorithm": "AES256",
"SSECustomerKeyMD5": "WqANna27MhljjbfdoH+JMw=="
}You can use a different key for each object. Keep track of which key belongs to which object, because requests with any other key fail.
rclone crypt
rclone can encrypt file contents and file names on your computer before uploading them. You set up a regular S3 remote for your Object Storage instance, and a crypt remote on top of it that encrypts everything passing through.
Create a remote for your Object Storage instance. Replace the access key, secret key, and endpoint with your own:
rclone config create upcloud s3 provider=Other access_key_id=<access-key> secret_access_key=<secret-key> endpoint=https://abcd1.upcloudobjects.comCreate a
cryptremote that stores encrypted files in a folder in your bucket. Replace the password with your own:rclone config create upcloud-crypt crypt remote=upcloud:example-bucket/encrypted password=<your-password>Copy files through the
cryptremote:rclone copy documents upcloud-crypt:documents
Listing the files through the crypt remote shows the original names:
rclone ls upcloud-crypt: 1048576 documents/sample.bin
17 documents/report-2026-q3.txtIn the bucket itself, the names and contents are encrypted:
rclone ls upcloud:example-bucket/encrypted 1048864 2f2thu2e58gl8q5jvr8aujkhgg/o89df4ks4ujapn6qhc4455pevk
65 2f2thu2e58gl8q5jvr8aujkhgg/qqumhgejgmd0n4bblnmton6tn9lbn9tm59mp3fcg6ppk9rr5qge0To download and decrypt the files, copy them back through the crypt remote:
rclone copy upcloud-crypt:documents restoredTo check that the uploaded files match the local ones, run:
rclone cryptcheck documents upcloud-crypt:documentsNOTICE: Encrypted drive 'upcloud-crypt:documents': 0 differences found
NOTICE: Encrypted drive 'upcloud-crypt:documents': 2 matching filesTo read the files on another computer, create the same remotes there with the same password.
s3cmd with GPG
s3cmd can encrypt files with GPG before uploading them.
Set up s3cmd for your Object Storage instance. When the configuration wizard asks for an Encryption password, enter the password to encrypt files with. You can also set it later as
gpg_passphrasein~/.s3cfg.Upload a file with the
--encryptoption:s3cmd put --encrypt report-2026-q3.txt s3://example-bucket/report-2026-q3.txtDownload the file. s3cmd decrypts it automatically:
s3cmd get s3://example-bucket/report-2026-q3.txt
The object is stored as a GPG-encrypted file, so you can also decrypt it with GPG and the same password after downloading it with any S3 client:
gpg --decrypt report-2026-q3.txt > report-decrypted.txtFile names are not encrypted. s3cmd also stores some details of the original file as object metadata, including its MD5 checksum, owner, and timestamps.
