Declare the binjovi-candidates-read key and candidate expiry #284
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/candidates-read-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Second of three changes that let the dashboard offer a Build's candidate package set for download before it is released.
binjovi-candidates-read:s3:GetObjectonworkflows/<project>/candidates/*for the sevenpackage_setprojects (zdns, zelnet, zerotea, rpg-demo, rpg-hello, rpg-lemonade, rpg-munchers), plusGetBucketLocationonworkflows. Explicit prefixes, asbinjovi-rpg-readdeclares them, so the converge proves each grant at its own prefix. The credential is delivered to namespacebinjoviasbinjovi-candidates-read-s3-credentials(seanfarm #709 generates and freezes the key, and lists it for the converge reader).workflows: one 30-day expiry rule percandidates/prefix. A candidate older than the current base cannot be released anyway (candidate_catalogs_divergedneeds a rebuild), so the rule removes nothing the release train could still use.tests/object-store-testpasses (20 identities, 10 buckets, 26 negative controls). The catalog contract cannot state "a read identity must not gain PutObject", because a trailing wildcard makes PutObject legal on any prefix, so no new negative control was added.Release order: after seanfarm #709 is deployed (the converge needs the frozen key), then the binjovi route.
https://claude.ai/code/session_01XdBRc9CHgFhAxCyHbdVtt6