{
  "schema_version": 1,
  "status_definitions": {
    "supported": "Implemented in X2 Node for the release and subject to the documented provider limitations.",
    "adapter-required": "Not implemented by X2 Node directly; a compatible external adapter is required."
  },
  "kmi_providers": [
    { "id": "disabled", "status": "supported", "guide": "encryption.html", "limitations": "Provider-backed object encryption is disabled." },
    { "id": "x2-kms", "status": "supported", "guide": "x2-kms.html", "limitations": "Requires a shared X2 KMS service and a configured connection from every X2 node; node access material is managed automatically." },
    { "id": "hashicorp-vault", "status": "supported", "guide": "encryption.html#vault", "limitations": "Uses Vault Transit and a supported token, AppRole, or client-certificate authentication method." },
    { "id": "aws-kms", "status": "supported", "guide": "encryption.html#aws-kms", "limitations": "Requires a region, static access key credentials on each node, and a full key ARN per encrypted bucket or request; S3 Bucket Keys are not supported." },
    { "id": "azure-key-vault", "status": "adapter-required", "guide": "encryption.html#provider-status", "limitations": "No direct X2 Node provider implementation is published." },
    { "id": "gcp-cloud-kms", "status": "adapter-required", "guide": "encryption.html#provider-status", "limitations": "No direct X2 Node provider implementation is published." }
  ]
}
