Policy and AppRole applied. Store Valid, ExternalSecret SecretSynced. Prefix empty. WAL not enabled.
Founder put ACCESS_KEY/SECRET_KEY. S3 prefix CRUD works. IAM write and ESO apply remain gated. WAL not enabled.
Use IAM application resource-control and policy Scoped backup access. OpenBao path is platform/workloads/railiance/backup/object-storage. rapp-postgres keeps Secret platform-pg-backup-s3 as the first projection.