KMS-managed keys for column encryption
Column encryption supports AWS KMS-managed keys through encryptionKMSConfig, and existing plaintext passphrase configurations keep working unchanged.
Column encryption previously required a plaintext passphrase in configuration. Customers who store their encryption passphrase in AWS KMS — as required by many security policies — could not use Artie's column encryption feature at all.
Column encryption now supports AWS KMS-managed keys via encryptionKMSConfig. The previous behavior (plaintext passphrase) continues to work unchanged.
Why this matters
- Unblocks column encryption for teams with KMS-enforced security policies
- No behavior change for existing plaintext-passphrase configurations