Advanced
Content encryption and key rotation
Configure versioned server-managed file encryption and rotate keys safely.
Content encryption is separate from security.data-key.
Enable
encryption:
active-key-version: 1
keys:
1: "YOUR_RANDOM_SECRET"Generate a 256-bit secret:
openssl rand -base64 32Environment form:
TELDRIVE_ENCRYPTION_ACTIVE_KEY_VERSION=1
TELDRIVE_ENCRYPTION_KEYS='1:YOUR_RANDOM_SECRET'Teldrive records the key version with encrypted file parts, so old data continues to depend on the key version used when it was written.
Rotate
Add the new key before changing the active version:
encryption:
active-key-version: 2
keys:
1: "OLD_KEY"
2: "NEW_KEY"Then:
- run
teldrive check; - restart Teldrive;
- verify a new encrypted upload;
- verify an older encrypted download.
Do not remove old key versions while files still reference them.
Validation
Configuration is rejected when:
- keys exist but
active-key-versionis0; - the active version is missing;
- a key version is non-positive;
- a key value is empty.
Backup
Back up every key version still in use. Losing one makes files encrypted with that version unreadable.
See Backup and restore.
Disable for future uploads
Remove the active version and key map only after data that depends on those keys has been removed or migrated.