retarget: mason plan backup-object-storage replaces Barman draft

This commit is contained in:
tegwick 2026-08-14 19:19:56 +02:00
parent cbe19c9bb0
commit a6cb560d01
3 changed files with 110 additions and 102 deletions

View file

@ -29,8 +29,8 @@ Checked 2026-08-14:
- **KV path does not exist.**
`platform/metadata/workloads/railiance/scaleway/bootstrap` is 404.
Same for the later Barman path
`platform/workloads/railiance/backup/platform-pg-backup-s3`.
Same for the later backup path
`platform/workloads/railiance/backup/object-storage`.
- **CCR already reserved the path.**
`railiance-platform` `CCR-2026-0011` names
`platform/workloads/railiance/scaleway/bootstrap` and the four fields.
@ -66,7 +66,7 @@ Terraform snippet → OpenBao fields (same four facts, scw-native names):
| 3 | create | policy `operator-kv-scaleway-bootstrap` (read/write that path only) | Founder desk and the bucket-create script; no sibling paths |
| 4 | reuse | founder paste-once desk + optional local tfvars ingest | ops-mason never sees values; four fields, four desk pastes or one founder-run ingest |
| 5 | propose | catalog `scaleway-bootstrap` (draft) + playbook | Pointer only; `warden_executes: false` |
| 6 | defer | AppRole / ESO / scoped Barman key | T04 / CCR for `platform-pg-backup-s3`; not this plan |
| 6 | defer | AppRole / ESO / scoped backup key | T04 / CCR for `backup/object-storage`; not this plan |
No new rail. Scaleway operates S3.