feat(rpg): the RPG keys come from RustFS only; the MinIO half was a timed landmine #535
Loading…
Reference in a new issue
No description provided.
Delete branch "sean/retire-rpg-minio-half"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
binjovi/ibmi-rpg-storage.yaml still carried three generated keys in namespace minio, a reader ServiceAccount/Role/RoleBinding, a ClusterSecretStore and a Job that converged them into the deleted tenant. The Job succeeded at 03:31, minutes before the deletion; its TTL is 86400 s, so Flux would have recreated it a day later and it would have failed, taking the binjovi Kustomization to Ready: False. The guard that read that Job's script is replaced by what is now true: one scoped RustFS store per role, exactly one store declared, no MinIO outside a comment -- the policies themselves are declared in binjovi-plans and proved by the converge. The Job was the last minio/mc pin, so the inventory record goes too. Full tests/check.sh green. https://claude.ai/code/session_01KZoQin34jeyt6nDGqvJA76