ccr: CCR-2026-0011 Scaleway bootstrap key lane
Reserve platform/workloads/railiance/scaleway/bootstrap for the WP-0002 bucket create. Founder puts the value; agent does not accept it in chat.
This commit is contained in:
parent
6e744b0adb
commit
5a0c2da501
1 changed files with 68 additions and 0 deletions
|
|
@ -0,0 +1,68 @@
|
|||
id: CCR-2026-0011
|
||||
kind: credential-change-request
|
||||
schema_version: 1
|
||||
request_type: workload-kv-read
|
||||
title: Scaleway bootstrap API key for reef-storage / WP-0002 bucket create
|
||||
status: proposed
|
||||
created: '2026-08-14'
|
||||
updated: '2026-08-14'
|
||||
requester:
|
||||
agent: grok
|
||||
reason: >-
|
||||
RESOURCE-WP-0002 T03 is human-approved to create a private Scaleway
|
||||
Multi-AZ bucket in nl-ams. This session has no Scaleway CLI profile.
|
||||
Founder will provision a bootstrap org/project API key into OpenBao;
|
||||
the agent reads it only to create the bucket and then writes the
|
||||
scoped bucket key to a separate path. Values must not appear in Git
|
||||
or chat.
|
||||
review:
|
||||
required: true
|
||||
required_approvers:
|
||||
- platform-operator
|
||||
comments:
|
||||
- at: '2026-08-14T00:00:00+00:00'
|
||||
reviewer: bernd.worsch
|
||||
decision: approved
|
||||
comment: >-
|
||||
Approved in chat (Grok session): put Scaleway bootstrap key in
|
||||
OpenBao first, then create the bucket.
|
||||
target:
|
||||
domain: financials
|
||||
tenant: railiance
|
||||
workload: scaleway-bootstrap
|
||||
environment: production
|
||||
purpose: Create reef-storage object-store members; not the Barman runtime key
|
||||
openbao:
|
||||
mount: platform
|
||||
kv_path: platform/workloads/railiance/scaleway/bootstrap
|
||||
fields:
|
||||
- ACCESS_KEY
|
||||
- SECRET_KEY
|
||||
- DEFAULT_ORGANIZATION_ID
|
||||
- DEFAULT_PROJECT_ID
|
||||
policy_name: operator-kv-scaleway-bootstrap
|
||||
access_frontdoor:
|
||||
type: operator-local
|
||||
catalog_id: scaleway-bootstrap
|
||||
selector: scaleway bootstrap api
|
||||
command: bao kv put platform/workloads/railiance/scaleway/bootstrap
|
||||
resolvable: false
|
||||
readiness: waiting-on-founder-put
|
||||
delivery:
|
||||
surface: operator-workstation
|
||||
target: reef-storage/tools/create-platform-audit-bucket.sh (reads, never prints)
|
||||
risk:
|
||||
classification: high
|
||||
notes:
|
||||
- Bootstrap key can create projects/buckets; rotate or delete after scoped key exists.
|
||||
- Scoped Barman key is a different path: platform/workloads/railiance/backup/platform-pg-backup-s3
|
||||
- Values must not appear in Git, State Hub, or chat.
|
||||
verification:
|
||||
positive:
|
||||
- Field names present on the KV path; values not printed.
|
||||
negative:
|
||||
- default-policy token denied on the data path.
|
||||
lifecycle:
|
||||
deactivate: Delete bootstrap key at Scaleway after the scoped bucket key works.
|
||||
rotate: Put a new bootstrap key; do not reuse the Barman key.
|
||||
compromised: Revoke both Scaleway keys; rotate bucket policy.
|
||||
Loading…
Add table
Add a link
Reference in a new issue