feat(object-store): declare the outline bucket and identity #279
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/outline-object-store"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Declares the
outlinebucket and its identity, so Binjovi's object-storeconverge creates them and proves the scoping.
Outline stores every attachment and avatar in S3. The identity holds
s3:*overoutlineandoutline/*only — the same shapeforgejohas — and is denied theisolation canary, so each release of this catalog proves the key reaches its own
bucket and is refused another.
The seanfarm side ships beside this one (
sean/seanfarm#705):rustfs-identities/outline.yamlgenerates and freezes the key and opens aClusterSecretStorethat admits namespaceoutlineonly;outline-argocd/credentials.yamldelivers it as Secretoutline-s3-credentialsunder
AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY.Those are the names Outline's own storage driver reads (
server/env.tsatv1.10.1) and they are recorded in the
secretblock here so the two ends can bechecked against each other.
scripts/checkpasses,tests/object-store-testincluded: 19 identities, 10buckets, 26 negative controls.
https://claude.ai/code/session_01JGe4pyhQ36AhgDfPJry4d3