note: WP-0002 T04 backup key verified; Secret still not vended
This commit is contained in:
parent
644d5391bd
commit
9381cf6535
1 changed files with 7 additions and 4 deletions
|
|
@ -254,10 +254,13 @@ instructions, handle `secret:railiance-platform/backup`, first consumer
|
|||
projection Secret `platform-pg-backup-s3`. Non-secret destination
|
||||
handed at
|
||||
`rapp-postgres/docs/handoff/RESOURCE-WP-0002-T04-barman-destination.md`.
|
||||
Waiting on founder: approve the CCR, use IAM application
|
||||
`resource-control`, bind policy and key `Scoped backup access`, put
|
||||
values in OpenBao, say “the backup key is in bao.” Do not enable WAL
|
||||
yet.
|
||||
2026-08-14: founder approved CCR-2026-0012 and put the backup key in
|
||||
OpenBao (`ACCESS_KEY`/`SECRET_KEY` + org/project ids, version 1).
|
||||
Positive S3 list/get and prefix put/get/delete succeeded. Negative:
|
||||
bogus secret denied; IAM/billing/k8s list denied. Distinct from the
|
||||
bootstrap key. Not done: OpenBao policy apply (this token 403), ESO
|
||||
Secret `platform-pg-backup-s3` (absent on railiance01), bucket policy
|
||||
(no `APPLICATION_ID`). WAL still off.
|
||||
|
||||
## T05 — Prove backup, full restore, and PITR
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue