S3 Platform Services — PostgreSQL HA, Valkey, object storage
QONTO-WP-0004-T06. Requests a second, workload-scoped access lane into the existing tenants/binky/qonto-api credential (CCR-2026-0008 is human/OIDC admin access only, not usable by a running pod). Mirrors CCR-2026-0003's llm-connect pattern: External Secrets Operator reads the KV path into a namespace-scoped Kubernetes Secret via a ClusterSecretStore restricted to the new qonto-assistant namespace; the pod never touches the OpenBao token directly. Status: proposed, not approved -- requires platform-operator and binky-tenant-owner sign-off before the auth role/policy are applied. Draft ClusterSecretStore manifest included, following the same "deployed separately, not via this kustomization" pattern as the existing activity-core/forgejo/reuse stores. Validated against schemas/credential-change-request.schema.yaml. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| argocd | ||
| credential-change-requests | ||
| credential-grants | ||
| docs | ||
| helm | ||
| lib | ||
| openbao | ||
| registry | ||
| schemas | ||
| scripts | ||
| tests | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| CLAUDE.md | ||
| INTENT.md | ||
| Makefile | ||
| SCOPE.md | ||