ops-warden/wiki/playbooks/scaleway-bootstrap.md
tegwick 817af8bc6e
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
catalog: draft scaleway-bootstrap lane
Pointer to the mason plan and playbook. Founder provision only;
warden does not execute the fetch.
2026-08-14 17:36:17 +02:00

34 lines
1.2 KiB
Markdown

# Scaleway bootstrap API key
Date: 2026-08-14
Catalog: `scaleway-bootstrap` (status `draft`)
Owner: `railiance-platform` (CCR-2026-0011) · consumer: `reef-storage`
Plan: `ops-mason/plans/reef-storage-scaleway-bootstrap.md`
Org/project API key used only to create the WP-0002 backup bucket.
Not the Barman runtime key.
## OpenBao pointers
| Field | Value |
| --- | --- |
| Mount | `platform` |
| Path | `platform/workloads/railiance/scaleway/bootstrap` |
| Fields | `ACCESS_KEY`, `SECRET_KEY`, `DEFAULT_ORGANIZATION_ID`, `DEFAULT_PROJECT_ID` |
| Terraform map | `access_key`, `secret_key`, `organization_id`, `project_id` |
## Worker checklist
1. Confirm metadata exists (no values):
`bao kv metadata get platform/workloads/railiance/scaleway/bootstrap`
2. Create the bucket with
`reef-storage/tools/create-platform-audit-bucket.sh`
(reads OpenBao, never prints keys).
3. Commit only non-secret YAML under `reef-storage/substrate/object-stores/`.
4. After T04 scoped key works, ask the founder to revoke this bootstrap key.
## Founder provision
Preferred: four paste-once desk writes (one field each), or one local ingest
of an existing `scaleway.auto.tfvars` — see the mason plan. Never paste
values into chat.