Part of JMR-dev/LibreMail#11 and its open question: "Encryption scheme + key custody for R2 objects." This is a decision/spike ticket, not implementation — it unblocks #9 (encrypted storage).
Scope
Evaluate options (e.g. Worker-side envelope encryption with a key from Cloudflare Secret Manager, vs. R2 server-side encryption) and pick one.
Document: which scheme, where the key lives (Cloudflare Secret Manager), how the Worker retrieves/uses it, and what happens if the key needs rotation.
Write the decision up (e.g. docs/decisions/encryption.md) so #9 can implement directly against it.
Acceptance criteria
A written decision doc exists covering scheme, key custody, and rotation, and is linked from the README.
## Context
Part of [JMR-dev/LibreMail#11](https://github.com/JMR-dev/LibreMail/issues/11) and its open question: "Encryption scheme + key custody for R2 objects." This is a decision/spike ticket, not implementation — it unblocks #9 (encrypted storage).
## Scope
- [ ] Evaluate options (e.g. Worker-side envelope encryption with a key from Cloudflare Secret Manager, vs. R2 server-side encryption) and pick one.
- [ ] Document: which scheme, where the key lives (Cloudflare Secret Manager), how the Worker retrieves/uses it, and what happens if the key needs rotation.
- [ ] Write the decision up (e.g. `docs/decisions/encryption.md`) so #9 can implement directly against it.
## Acceptance criteria
- A written decision doc exists covering scheme, key custody, and rotation, and is linked from the README.
## Dependencies
None to start (blocks #9).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
Part of JMR-dev/LibreMail#11 and its open question: "Encryption scheme + key custody for R2 objects." This is a decision/spike ticket, not implementation — it unblocks #9 (encrypted storage).
Scope
docs/decisions/encryption.md) so #9 can implement directly against it.Acceptance criteria
Dependencies
None to start (blocks #9).