feat(rustfs): key for the binjovi-candidates-read identity #709
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/binjovi-candidates-read"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
First of three changes that let the dashboard offer a Build's candidate package set for download before it is released (zelnet, zdns, zerotea and the RPG projects). The candidate lives in the private
workflowsbucket, so the control plane serves it to a signed-in user through an authenticated route, and needs a read-only key forworkflows/<project>/candidates/.This file generates and freezes that key and delivers it to namespace
binjoviasbinjovi-candidates-read-s3-credentials, the same chainbinjovi-logs.yamluses. The converge reader lists the frozen key, so Binjovi can create the user and prove its scope oncesean/binjovi-plansdeclares the policy (next pull request). The identity can only read the candidate prefixes: a control plane compromise gains no write on the store and no read of any other prefix.tests/rustfs-identities.shandtests/binjovi.shpass.Order: this, then the
binjovi-planspolicy and 30-day lifecycle rule, then the binjovi route and views.https://claude.ai/code/session_01XdBRc9CHgFhAxCyHbdVtt6