Pyrite::Providers::AWSKMS
Inherits Pyrite::Provider < Reference < Object
Provider for AWS ECS, AWS Fargate, AWS Lambda, and EC2 instances using AWS KMS.
Unseals encrypted payloads using AWS Key Management Service (AWS KMS) Decrypt REST API
authenticated via native AWS Signature Version 4 (SigV4) from standard library, or
ambient ECS container task role credentials ($AWS_CONTAINER_CREDENTIALS_RELATIVE_URI).
Zero-Dependency Architecture
Decryption is performed directly over HTTPS (kms.<region>.amazonaws.com:443) using
Crystal's native standard library (http/client, openssl/hmac, digest/sha256).
External CLI binaries like aws are not required in container images.
Prerequisites
- IAM permissions for
kms:Decrypton the designated KMS Key ARN. - Ambient credentials from environment variables (
AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY), ambient ECS task credentials ($AWS_CONTAINER_CREDENTIALS_RELATIVE_URI), or AWS CLI fallback.
Example
provider = Pyrite::Providers::AWSKMS.new(key_id: "arn:aws:kms:us-east-1:123456789012:key/...")
config = Pyrite.bootstrap!(AppConfig, provider: provider)
Constants
ALLOWED_REGIONS = {"us-east-1", "us-east-2", "us-west-1", "us-west-2", "af-south-1", "ap-east-1", "ap-south-1", "ap-south-2", "ap-northeast-1", "ap-northeast-2", "ap-northeast-3", "ap-southeast-1", "ap-southeast-2", "ap-southeast-3", "ap-southeast-4", "ca-central-1", "ca-west-1", "eu-central-1", "eu-central-2", "eu-west-1", "eu-west-2", "eu-west-3", "eu-north-1", "eu-south-1", "eu-south-2", "il-central-1", "me-south-1", "me-central-1", "sa-east-1", "us-gov-east-1", "us-gov-west-1"}
Allowlist of recognized standard AWS regions