feat(rustfs): key every declared identity and let Binjovi converge the tenant #472
Loading…
Reference in a new issue
No description provided.
Delete branch "sean/object-store-identities"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Stage 2 cluster half. Four identities (binjovi-logs, forgejo, loki, zot) generate and freeze a RustFS key; the tenant root credential reaches namespace binjovi alone, pinned by resourceNames; the converge agent gets one Secret with a key per identity. tests/rustfs-identities.sh is rewritten for the new split -- a file that still converges keeps every converge rule, a key-only file must generate, name and FREEZE its key -- and gains a both-directions check that every generated key is delivered to the converge and nothing else is. Five new negative controls, all confirmed red. Also adds the object-store agent OAuth client, and denies untrusted workloads the rustfs namespace as MinIO already is. Nothing converges yet. https://claude.ai/code/session_01KZoQin34jeyt6nDGqvJA76