Download the PHP package laravel-chronicle/kms-aws without Composer

On this page you can find all versions of the php package laravel-chronicle/kms-aws. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package kms-aws

laravel-chronicle/kms-aws

Tests PHPStan Latest Version Total Downloads

AWS KMS custody for the Chronicle audit ledger.

Keeps Chronicle's cryptographic key material inside AWS KMS instead of on the application server. The package provides two independent providers:

Use either or both. The signing setup is covered first; KEK custody has its own section below.


Installation

The package auto-discovers its service provider via Laravel's package discovery.


Requirements


AWS Setup

This section sets up the signing provider. If you also want KEK custody for crypto-shredding, you'll need a separate symmetric key - see KEK encryption provider below. The two providers use different key types and are configured independently.

Create a KMS key (signing)

Create an asymmetric KMS key with:

Required IAM actions

Attach the following IAM policy to the role that runs your application:

kms:GetPublicKey is not required at runtime - the public key is cached in your application config and never fetched from KMS during verification.

Retrieve and cache the public key

Retrieve your KMS key's public key once and store it in your config:

This outputs a PEM string like:

Store this as the public_key in your Chronicle signing config (see below).


Configuration

Register the KMS key in config/chronicle.php under signing.keys:

Set the corresponding environment variables:


How it works

Operation Where it runs
sign() Remote - calls KMS Sign API with MessageType: DIGEST
verify() Local - openssl_verify against the cached PEM public key

The private key never leaves AWS KMS. Verification is offline and instant.


Key rotation

Chronicle's key rotation works identically for KMS-backed keys. Retire the old key by keeping only its public_key in the ring (omit key_arn), then add the new KMS key as active. Historic checkpoints and exports continue to verify offline against the retained public key.

Example two-key ring after rotation:

Note: AwsKmsSigningProvider requires key_arn at construction - it cannot be used as a verify-only provider. For retired KMS keys, switch the entry to Chronicle\Signing\EcdsaSigningProvider (from core) with only public_key set, as shown above. Core's EcdsaSigningProvider handles the local-verify-only case.


KEK encryption provider (crypto-shredding)

Chronicle v1.12 can encrypt PII payload fields under a per-subject DEK, wrapping those DEKs under a Key Encryption Key (KEK). This package can hold the KEK in AWS KMS so wrapped DEKs are protected outside the application.

Point chronicle.encryption.kek at the KMS provider:

Required IAM actions on the KEK: kms:Encrypt, kms:Decrypt. The KmsClient is resolved from the container (region from AWS_DEFAULT_REGION), so no extra wiring is needed beyond installing this package.

KmsClient options

The KmsClient singleton is shaped from config/chronicle-kms.php. All keys have sensible defaults - set nothing, and you get a standard region-derived client.

Credentials are never read from this config - they flow through the standard AWS credential chain (env vars, IAM roles, etc.). For anything these keys don't cover - a custom credential provider, or a fully custom client - re-bind Aws\Kms\KmsClient in your application's AppServiceProvider; that binding wins over this provider's default.


License

MIT


All versions of kms-aws with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
ext-openssl Version *
laravel-chronicle/core Version ^1.12
aws/aws-sdk-php Version ^3.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package laravel-chronicle/kms-aws contains the following files

Loading the files please wait ...