Founder put ACCESS_KEY/SECRET_KEY. S3 prefix CRUD works. IAM write and ESO apply remain gated. WAL not enabled.
1.9 KiB
1.9 KiB
CCR-2026-0012 — scoped backup key verification
Date: 2026-08-14
Status: key live in OpenBao; cluster Secret not vended
CCR: approved in chat 2026-08-14
Path: platform/workloads/railiance/backup/object-storage (KV v2 version 1)
No secret values in this file.
What is in OpenBao
| Field | Present |
|---|---|
ACCESS_KEY |
yes (len 20, SCW…) |
SECRET_KEY |
yes |
DEFAULT_ORGANIZATION_ID |
yes |
DEFAULT_PROJECT_ID |
yes |
APPLICATION_ID |
no (bucket policy deferred) |
Distinct from the CCR-2026-0011 bootstrap key (keys_differ=yes).
Positive
scw object bucket list/get railiance-platform-pg-backupinnl-amssucceeded.- boto3 put/get/delete of a probe object under
platform-pg/succeeded; probe deleted. - Sibling prefix write also succeeded: no bucket policy yet, so prefix isolation is not enforced.
Negative
- Bogus secret against the same access key:
SignatureDoesNotMatch. scw iam application list/user list/api-key get: insufficient permissions.scw billing budget list: not allowed.scw k8s cluster list: insufficient permissions.
instance / vpc / rdb / registry / lb list returned empty success. That is consistent with a project that has no those resources; it is not a proven compute-write deny. Do not create a paid resource to prove it.
Not done
- OpenBao policy
workload-kv-read-backup-object-storage— this token cannotsys/policies/aclwrite (403). - ClusterSecretStore / ExternalSecret — railiance01 has no
platform-pg-backup-s3yet; applying the draft store would fail without ESO auth. - Bucket policy — needs
APPLICATION_ID. - WAL /
barmanObjectStoreonplatform-pg— T05.
Next
ops-mason (or a token that can write policies and ESO auth) applies the OpenBao policy and the databases-scoped store. Then ExternalSecret can project the Secret. After that, empty-WAL-archive preflight; still no continuous archiving until T05.