Install the KMS instance SDK (Java)
The KMS instance SDK for Java lets you perform cryptographic operations and retrieve secret values using keys managed by Key Management Service (KMS).
Prerequisites
Before you begin, ensure that you have:
A KMS instance purchased and enabled. See Purchase and enable a KMS instance
A key (software-protected or hardware-protected) created in the KMS instance. See Get started with key management (software-protected keys) or Get started with key management (hardware-protected keys)
(Optional) A secret created in the KMS instance. See Create a secret
Java 8 or later installed. Run
java -versionto checkNetwork access to your KMS instance endpoint. See Network requirements
Network requirements
Your application must be able to reach the KMS instance Virtual Private Cloud (VPC) address: <KMS_INSTANCE_ID>.cryptoservice.kms.aliyuncs.com.
The required setup depends on where your application runs:
| Scenario | Action required |
|---|---|
| Same region and same VPC as the KMS instance | No additional setup required. The two are connected by default. |
| Same region but a different VPC | Associate the application's VPC with the KMS instance. See Access a KMS instance from multiple VPCs in the same region. |
| Local IDC (Internet Data Center) | Configure network connectivity so your IDC can reach the KMS instance without relying on domain name resolution. See Application access FAQ. |
Install the SDK
Add the following Maven dependencies to your project's pom.xml. Maven downloads the packages automatically from the Maven repository.
<dependency>
<groupId>com.aliyun</groupId>
<artifactId>alibabacloud-dkms-gcs-sdk</artifactId>
<version>xx.xx.xx</version>
</dependency>
<dependency>
<groupId>com.aliyun</groupId>
<artifactId>tea</artifactId>
<version>[1.2.3)</version>
</dependency>Replace xx.xx.xx with the latest SDK version. For the latest release and source code, see alibabacloud-dkms-gcs-java-sdk on GitHub.
The com.aliyun.tea dependency must be version 1.2.3 or later.
What's next
After installing the SDK, use the KMS instance SDK to perform cryptographic operations and retrieve secret values with your keys.