build: backup-object-storage AppRole lane delivered
This commit is contained in:
parent
deb8f4e119
commit
24c6b433ed
1 changed files with 19 additions and 7 deletions
|
|
@ -3,9 +3,9 @@ id: backup-object-storage
|
|||
demand_source: resource-control/workplans/RESOURCE-WP-0002-T04
|
||||
consumer_repo: rapp-postgres
|
||||
credential_type: openbao-kv-founder-provision
|
||||
status: draft
|
||||
approved_by: null
|
||||
approved_at: null
|
||||
status: built
|
||||
approved_by: "Bernd Worsch"
|
||||
approved_at: "2026-08-14"
|
||||
created: "2026-08-14"
|
||||
updated: "2026-08-14"
|
||||
---
|
||||
|
|
@ -102,7 +102,19 @@ the KV version, rotate.
|
|||
**Cost to reverse:** delete the KV path, policy, and unused drafts.
|
||||
WAL is not enabled yet, so there is no production archive to migrate.
|
||||
|
||||
**Decision:** approve, reject, or send back to phase 1.
|
||||
Approval authorizes structure (empty path, policy). It does not
|
||||
authorize ops-mason to handle the Scaleway secret values, and it does
|
||||
not enable continuous archiving.
|
||||
**Decision:** approved in chat 2026-08-14 (“Lets go”).
|
||||
|
||||
## 6. Build result
|
||||
|
||||
Built 2026-08-14:
|
||||
|
||||
- policy `workload-kv-read-backup-object-storage` (read on the KV data
|
||||
and metadata paths only)
|
||||
- AppRole `external-secrets-backup-object-storage` (15m/30m, 8 uses)
|
||||
- Kubernetes Secret `external-secrets/openbao-backup-object-storage-approle`
|
||||
delivered; local files shredded
|
||||
- ClusterSecretStore `openbao-backup-object-storage` Valid
|
||||
- ExternalSecret synced `databases/platform-pg-backup-s3` (two keys,
|
||||
values not read)
|
||||
|
||||
Did not write Scaleway secret values. Did not enable WAL.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue