Lyo.KeyStore.Aws 1.0.0

There is a newer version of this package available.
See the version list below for details.
dotnet add package Lyo.KeyStore.Aws --version 1.0.0
                    
NuGet\Install-Package Lyo.KeyStore.Aws -Version 1.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Lyo.KeyStore.Aws" Version="1.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Lyo.KeyStore.Aws" Version="1.0.0" />
                    
Directory.Packages.props
<PackageReference Include="Lyo.KeyStore.Aws" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Lyo.KeyStore.Aws --version 1.0.0
                    
#r "nuget: Lyo.KeyStore.Aws, 1.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Lyo.KeyStore.Aws@1.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Lyo.KeyStore.Aws&version=1.0.0
                    
Install as a Cake Addin
#tool nuget:?package=Lyo.KeyStore.Aws&version=1.0.0
                    
Install as a Cake Tool

Lyo.KeyStore.Aws

AwsKeyStore (an IAmazonSecretsManager client + secret-name prefix) implements both Lyo.KeyStore.IKeyStore and Lyo.KeyStore.IKeyInventoryStore, so admin UIs and key-rotation jobs can both encrypt against it and enumerate available keyIds / versions.

The backing secret is stored as JSON ({ "<keyId>": "plaintext-or-derived-material", ... }) under a single secret per prefix. Logical version strings map onto AWS VersionId stages; unresolved version requests fall through to AWSCURRENT. String values run through key derivation so callers receive cryptographic-length KEK bytes usable by AesGcmEncryptionService and the other symmetric services in Lyo.Encryption.

AwsKeyStore API

  • IKeyStoreGetKey, GetCurrentKey, GetCurrentVersion, AddKey, UpdateKey, HasKey, metadata, salt-for-version (all sync + async variants).
  • IKeyInventoryStoreGetAvailableKeyIdsAsync(CancellationToken), GetAvailableVersionsAsync(string keyId, CancellationToken) so listings, rotation reports, and DEK migrations can pivot off the live store rather than a local index.

Options — AwsKeyStoreOptions

Property Default Notes
SectionName AwsKeyStore Default appsettings subsection.
AccessKeyId / SecretAccessKey unset Static credentials. When both are set they win over Profile. Omit to use Profile or the AWS default credential chain (IAM role, env vars, default profile).
Profile unset Named profile from ~/.aws/credentials / ~/.aws/config. Used when static keys are omitted. If set but missing, registration fails rather than falling back to default.
Region us-east-2 (when unspecified) Resolved via RegionEndpoint.GetBySystemName.
SecretNamePrefix lyo/kek fallback Logical secret prefix used to scope keys across environments (dev/MyApp/KeyStore, prod/MyApp/KeyStore, …).

Dependency injection

Extension Purpose
services.AddAwsKeyStore(Func<IServiceProvider,string> resolvePrefix) Resolve the prefix from DI (multi-tenant hosts), register AwsKeyStore as a singleton.
services.AddAwsKeyStoreFromConfiguration(IConfiguration, configSectionName = "AwsKeyStore") Bind AwsKeyStoreOptions + register IAmazonSecretsManager (when missing) + register AwsKeyStore and IKeyStore.
services.AddAmazonSecretsManagerFromConfiguration(IConfiguration, configSectionName = "AwsKeyStore") Standalone IAmazonSecretsManager registration (no keystore). Honours static keys, then Profile, then the default credential chain; also honours region.
services.AddTwoKeyEncryptionServiceKeyed(keyedServiceName, secretNamePrefix) / <TKeyStore> Register a full keyed ITwoKeyEncryptionService stack using AwsKeyStore + paired AesGcmEncryptionService for both DEK and KEK.
services.AddTwoKeyEncryptionServiceKeyed(keyedServiceName, secretNamePrefix, AwsKeyStoreOptions?) Same, but with explicit AWS options (region/credentials) rather than configuration binding.
services.AddTwoKeyEncryptionFromConfiguration(IConfiguration, keyedServiceName, configSectionName) / <TKeyStore> Bind AwsKeyStoreOptions from configuration and wire the keyed two-key stack in one call.

Note that AddAwsKeyStore(Func<...>) registers AwsKeyStore as a concrete singleton only (no IKeyStore indirection); AddAwsKeyStoreFromConfiguration and the two-key extensions also register IKeyStore so the rest of Lyo.Encryption can resolve it generically.

See also

  • Lyo.KeyStore — interfaces and local store.
  • Lyo.Encryption — encryption services that consume IKeyStore.
  • ../README.md — encryption umbrella (algorithms, stream formats, threat model).

Dependencies

Generated from ProjectReference / PackageReference (same model as docs/Lyo.ProjectGraph.html).

  • Lyo.Encryption — (direct, lyo)
  • Lyo.KeyStore — (direct, lyo)
  • AWSSDK.SecretsManager 4.0.100.3 — (direct, third-party)
  • Microsoft.Extensions.Configuration.Binder 10.0.5 — (direct, microsoft)
  • Microsoft.Extensions.DependencyInjection.Abstractions 10.0.5 — (direct, microsoft)
  • Lyo.Common — (transitive, lyo)
  • Lyo.Exceptions — (transitive, lyo)
  • Lyo.Hashing — (transitive, lyo)
  • Lyo.Result — (transitive, lyo)
  • Lyo.Streams — (transitive, lyo)
  • BouncyCastle.Cryptography 2.6.2 — (transitive, third-party, netstandard2.0)
  • Konscious.Security.Cryptography.Argon2 1.3.1 — (transitive, third-party)
  • Microsoft.Bcl.AsyncInterfaces 10.0.5 — (transitive, microsoft, netstandard2.0)
  • Microsoft.Extensions.Logging.Abstractions 10.0.5 — (transitive, microsoft)
  • System.Buffers 4.6.1 — (transitive, microsoft, netstandard2.0)
  • System.IO.Hashing 10.0.5 — (transitive, microsoft, net10.0)
  • System.Memory 4.6.3 — (transitive, microsoft, netstandard2.0)
  • System.Text.Json 10.0.5 — (transitive, microsoft, netstandard2.0)
  • System.Threading.Tasks.Extensions 4.6.3 — (transitive, microsoft, netstandard2.0)
Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.3 0 8/19/2026
1.0.2 0 8/19/2026
1.0.1 44 8/18/2026
1.0.0 107 8/16/2026