SIGN IN SIGN UP

[KeyManagement] Add KeyManagementBundle and register it in FrameworkBundle

The component ships its own bundle, the way every component the
FrameworkBundle used to wire now does, and FrameworkBundle registers it when
the package is installed. The configuration lives under the `key_management`
root key. Each entry of `clients` is a DSN, built through the factory
registry, and exposed both as a named service and as a named argument, with
the single client of a one-client application becoming the default without
having to say so; a bare DSN at the root is that single client.

Configuring `store` is what an application does to stop carrying a wrapped
data key in every payload, so the store-backed encrypter becomes what the
envelope interfaces resolve to. Nothing is lost by that: it is given the
default client's encrypter as a fallback, so it reads the payloads written
before it as well as the ones it writes. The per-client encrypters stay
reachable under their own name for whoever wants the other regime explicitly.

Each bridge factory is removed from the container when its package is absent,
and configuring a store without symfony/doctrine-dbal-key-management fails at
compile time with the command to run.

Autoconfiguration tags every blind index the application registers, and the
compiler pass of symfony/doctrine-orm-key-management hands them to the listener
filling the index columns, which is removed when there is none.

The four console commands are registered alongside when the Console component
is installed.

In debug mode, the data collector is registered and kept only when a profiler
collects it; a compiler pass then wraps every tagged client, its envelope
encrypter and the store in traceable decorators feeding
`KeyManagementDataCollector`, which aggregates what a request encrypted per
call site, per key and per service, and puts the counters on the toolbar. The
collector records byte counts, ids and durations, never payloads, AAD or key
material. The WebProfilerBundle panel renders those three views.
F
Florent Morselli committed
03fc82dc78bf75c41b2bd9cd555cabe909385fe0
Parent: cb423dc
Committed by Nicolas Grekas <nicolas.grekas@gmail.com> on 9/14/2026, 8:33:05 AM