feat: propose CCR-2026-0012 for platform-pg Barman key

Workload KV path and ESO drafts for Secret platform-pg-backup-s3.
Founder mints the project-scoped Scaleway application; values stay
out of git.
This commit is contained in:
codex 2026-08-14 19:01:08 +02:00
parent 015f0e43a9
commit 2769258631
5 changed files with 219 additions and 1 deletions

View file

@ -0,0 +1,72 @@
# Put the scoped Barman key (founder, local only)
Do this on a trusted terminal. **Do not paste ACCESS_KEY_ID or
ACCESS_SECRET_KEY into chat, Git, or State Hub.**
CCR: `credential-change-requests/CCR-2026-0012-platform-pg-backup-s3.yaml`
Path: `platform/workloads/railiance/backup/platform-pg-backup-s3`
This is **not** the bootstrap key (`…/scaleway/bootstrap`). That key
created the bucket. This key is the CNPG/Barman runtime identity.
## 1. Create a dedicated IAM application
In [console.scaleway.com](https://console.scaleway.com) → IAM → Applications:
1. Create application `railiance-barman-platform-pg`.
2. Create an API key **on that application** (not on your user):
- Description: `platform-pg Barman runtime`
- **Preferred Project for Object Storage:** the project that owns
bucket `railiance-platform-pg-backup`
3. Copy the access key and secret key into a local scratch file
(`chmod 600`). The secret is shown once.
## 2. Attach a project-scoped Object Storage policy
IAM → Policies → create `railiance-barman-platform-pg-objects`:
- Principal: the application from step 1
- Scope: **that one project**, not the whole Organization
- Permission sets, if the console lists them:
- `ObjectStorageBucketsRead`
- `ObjectStorageObjectsRead`
- `ObjectStorageObjectsWrite`
- `ObjectStorageObjectsDelete`
- If those sets are not listed, `ObjectStorageFullAccess` **on this
project only** is acceptable because the project should contain only
this backup bucket.
Do **not** attach `IAM*` or compute permission sets.
## 3. Put the values in OpenBao
On this host, with a token that can write the `platform` mount:
```bash
bao kv put platform/workloads/railiance/backup/platform-pg-backup-s3 \
ACCESS_KEY_ID='SCWxxxxxxxx' \
ACCESS_SECRET_KEY='xxxxxxxx' \
APPLICATION_ID='xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx'
```
Or replace the `xxx` placeholders in the OpenBao UI on that same path.
`APPLICATION_ID` is the IAM application UUID (not a secret). It is needed
later for the bucket policy.
## 4. Confirm without printing values
```bash
bao kv metadata get platform/workloads/railiance/backup/platform-pg-backup-s3
```
You should see a current version greater than any placeholder version.
Then tell the agent: **“the Barman key is in bao.”** Also say the
application name if `APPLICATION_ID` is in bao.
Do not enable WAL archiving yourself. T04 still has to prove a negative
key cannot access the bucket and to vend Secret `platform-pg-backup-s3`.
T05 enables continuous archiving.
After the scoped key works, delete or lock down the bootstrap key from
CCR-2026-0011.

View file

@ -180,7 +180,7 @@ shape unless it *is* a secrets engine.
| --- | --- | --- | --- |
| `rapp-openbao` | none | none — package is the store | correct |
| `rapp-postgres` | `consumer_contract` + `openbao-database-secrets-engine` | `rapp-postgres/audit-core-runtime`, `rapp-postgres/audit-core-migration` | bound |
| `rapp-postgres` | `s3-backup-target` | no lane yet; Secret `platform-pg-backup-s3` is S3 custody after RESOURCE-WP-0002 | fail-closed on purpose |
| `rapp-postgres` | `s3-backup-target` / `secret_references: platform/workloads/railiance/backup/platform-pg-backup-s3` | `CCR-2026-0012` | pointer set; CCR `proposed`; Secret not vended |
| `rapp-qonto` | `secret_references: tenants/binky/qonto-api` | `CCR-2026-0009` | pointer set; CCR itself is still `proposed` |
Live CCRs without `target.rapp` are un-rapped workloads. They stay on