class

Pyrite::Providers::AWSKMS

Inherits Pyrite::Provider < Reference < Object

Provider for AWS ECS, AWS Fargate, AWS Lambda, and EC2 instances using AWS KMS.

Unseals encrypted payloads using AWS Key Management Service (AWS KMS) Decrypt REST API authenticated via native AWS Signature Version 4 (SigV4) from standard library, or ambient ECS container task role credentials ($AWS_CONTAINER_CREDENTIALS_RELATIVE_URI).

Zero-Dependency Architecture

Decryption is performed directly over HTTPS (kms.<region>.amazonaws.com:443) using Crystal's native standard library (http/client, openssl/hmac, digest/sha256). External CLI binaries like aws are not required in container images.

Prerequisites

  • IAM permissions for kms:Decrypt on the designated KMS Key ARN.
  • Ambient credentials from environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), ambient ECS task credentials ($AWS_CONTAINER_CREDENTIALS_RELATIVE_URI), or AWS CLI fallback.

Example

provider = Pyrite::Providers::AWSKMS.new(key_id: "arn:aws:kms:us-east-1:123456789012:key/...")
config = Pyrite.bootstrap!(AppConfig, provider: provider)

Constants

ALLOWED_REGIONS = {"us-east-1", "us-east-2", "us-west-1", "us-west-2", "af-south-1", "ap-east-1", "ap-south-1", "ap-south-2", "ap-northeast-1", "ap-northeast-2", "ap-northeast-3", "ap-southeast-1", "ap-southeast-2", "ap-southeast-3", "ap-southeast-4", "ca-central-1", "ca-west-1", "eu-central-1", "eu-central-2", "eu-west-1", "eu-west-2", "eu-west-3", "eu-north-1", "eu-south-1", "eu-south-2", "il-central-1", "me-south-1", "me-central-1", "sa-east-1", "us-gov-east-1", "us-gov-west-1"}

Allowlist of recognized standard AWS regions

Constructors

new(key_id : String = ENV.fetch("AWS_KMS_KEY_ID", ""), region : String = "")

Initializes the provider with an optional KMS Key ARN and region.

Source

Instance methods

key_id

AWS KMS Key ARN or Alias

Source
name

Human-readable name

Source
region

AWS Region (e.g. "us-east-1")

Source
unwrap(envelope_path : String) : String

Decrypts the AWS KMS ciphertext file at envelope_path.

Source