1.6 KiB
1.6 KiB
Put the Scaleway bootstrap key (founder, local only)
Do this on a trusted terminal. Do not paste ACCESS_KEY or SECRET_KEY into chat, Git, or State Hub.
CCR: railiance-platform/credential-change-requests/CCR-2026-0011-scaleway-object-storage-bootstrap.yaml
Path: platform/workloads/railiance/scaleway/bootstrap
- In console.scaleway.com create or reuse the Railiance (or GmbH) project. IAM → API keys: create a key that can create Object Storage buckets in that project. Copy org id and project id from the project dashboard (those two are not as sensitive as the secret key, but still keep them out of git).
- On this host, with a token that can write the
platformmount:
bao kv put platform/workloads/railiance/scaleway/bootstrap \
ACCESS_KEY='SCWxxxxxxxx' \
SECRET_KEY='xxxxxxxx' \
DEFAULT_ORGANIZATION_ID='xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx' \
DEFAULT_PROJECT_ID='xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx'
- Confirm without printing values:
bao kv metadata get platform/workloads/railiance/scaleway/bootstrap
You should see a current version. Then tell the agent “bootstrap is in
OpenBao.” They will run tools/create-platform-audit-bucket.sh, which
creates the private Multi-AZ bucket, 30-day lifecycle, and writes only
endpoint/bucket/region into substrate/object-stores/platform-audit-storage.yaml.
The scoped backup key is a different path
(platform/workloads/railiance/backup/object-storage) and is T04.
After the scoped key works, delete or lock down this bootstrap key.