Decision: encryption scheme + key custody (Cloudflare Secret Manager) #5

Closed
opened 2026-07-02 17:44:23 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-02 17:44:23 +00:00 (Migrated from github.com)

Context

Part of JMR-dev/LibreMail#11 and its open question: "Encryption scheme + key custody for R2 objects." This is a decision/spike ticket, not implementation — it unblocks #9 (encrypted storage).

Scope

  • Evaluate options (e.g. Worker-side envelope encryption with a key from Cloudflare Secret Manager, vs. R2 server-side encryption) and pick one.
  • Document: which scheme, where the key lives (Cloudflare Secret Manager), how the Worker retrieves/uses it, and what happens if the key needs rotation.
  • Write the decision up (e.g. docs/decisions/encryption.md) so #9 can implement directly against it.

Acceptance criteria

  • A written decision doc exists covering scheme, key custody, and rotation, and is linked from the README.

Dependencies

None to start (blocks #9).

## Context Part of [JMR-dev/LibreMail#11](https://github.com/JMR-dev/LibreMail/issues/11) and its open question: "Encryption scheme + key custody for R2 objects." This is a decision/spike ticket, not implementation — it unblocks #9 (encrypted storage). ## Scope - [ ] Evaluate options (e.g. Worker-side envelope encryption with a key from Cloudflare Secret Manager, vs. R2 server-side encryption) and pick one. - [ ] Document: which scheme, where the key lives (Cloudflare Secret Manager), how the Worker retrieves/uses it, and what happens if the key needs rotation. - [ ] Write the decision up (e.g. `docs/decisions/encryption.md`) so #9 can implement directly against it. ## Acceptance criteria - A written decision doc exists covering scheme, key custody, and rotation, and is linked from the README. ## Dependencies None to start (blocks #9).
Sign in to join this conversation.