Client-side field level encryption (CSFLE) - #2887
Open
gedaiu wants to merge 6 commits into
Open
Conversation
…nitoring, primary write-routing Reworks the MongoDB driver onto a Server Discovery and Monitoring (SDAM) foundation: single-pass topology discovery, background health monitoring, writes routed to the primary, per-query read preferences, and read-preference tag server selection. Adds the wire/codec and topology infrastructure (serverdescription, monitor, wire, wireversion, compression, commands, clustertime) and reworks connection/client/collection/database/cursor onto it. Base of a stacked series: client sessions, multi-document transactions and retryable writes follow in the next PR, and the self-contained MongoDB 8 features (change streams, client bulkWrite, GridFS, CSFLE, Stable API, mongodb+srv, load-balancer mode) as PRs on top of that. Closes vibe-d#2845, vibe-d#2847, vibe-d#2848, vibe-d#2849, vibe-d#2851
…writes Adds client session support (logical session ids backed by a server session pool), multi-document transactions (start/commit/abort), and retryable writes — including write retry when the primary steps down — on top of the SDAM core. Stacked on mongo-driver-core-improvements. Closes vibe-d#2850, vibe-d#2854, vibe-d#2855, vibe-d#2856
Adds change streams via watch() on MongoClient (whole deployment), MongoDatabase (all collections), and MongoCollection. The returned ChangeStream input range tracks resume tokens and automatically resumes on transient/resumable errors; requires a replica set or sharded cluster. Stacked on mongo-sessions-and-transactions. Closes vibe-d#2860
Adds MongoClient.bulkWrite() — the MongoDB 8.0 server-level bulkWrite command spanning multiple collections and databases in a single request. Builds the command, drains the result cursor via getMore (killing it on a mid-drain failure), and parses the summary plus per-operation verbose results; honours ordered/verboseResults/writeConcern and surfaces partial results on error. Stacked on mongo-change-streams. Closes vibe-d#2861
Adds GridFS support via GridFSBucket for storing and retrieving large files as chunked documents: upload/download, chunk split and assembly, and the files/chunks collection bookkeeping with their indexes. Stacked on mongo-client-bulkwrite. Closes vibe-d#2862 Merge after vibe-d#2861
Adds the CSFLE configuration and data model: AutoEncryptionOptions, ClientEncryption with a key-vault integration, a MongoCryptProvider seam, KeyVault for managing data encryption keys, and EncryptOptions/DataKeyOptions — plus a MongoClientSettings.autoEncryption field to opt in. Stacked on mongo-gridfs. Closes vibe-d#2863 Merge after vibe-d#2862
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hey @s-ludwig! This builds on the GridFS PR and adds the client-side field-level encryption layer.
It introduces the CSFLE configuration and data model — AutoEncryptionOptions, ClientEncryption with key-vault integration, a MongoCryptProvider seam, KeyVault for managing data encryption keys, and EncryptOptions/DataKeyOptions — plus a MongoClientSettings.autoEncryption field to opt in.
It's stacked on mongo-gridfs, so please review that one first; the diff here is just the CSFLE feature (one new module, a collection re-export, the settings field, and an integration test).
Builds clean and all unit tests pass.
Closes #2863
Merge after #2862