OBS allows users to encrypt objects using server-side encryption so that the objects can be securely stored in OBS.
In the region where OBS is deployed, the KMS Administrator permission has been added to the user group. For details about how to add permissions, see the IAM User Guide.
If the default encryption is enabled for a bucket, uploaded objects are automatically encrypted.
After KMS encryption is selected, obs/default is selected by default as the key for the encryption. You can also click Create KMS Key to switch to the management console of KMS and create customer master keys. Then back to OBS Console and select the key from the drop-down list box for KMS encryption.
After the object is uploaded successfully, you can view its encryption status in the object list.