From 9381cf65350bd29611416e5792f8560161677a07 Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 14 Aug 2026 19:34:40 +0200 Subject: [PATCH] note: WP-0002 T04 backup key verified; Secret still not vended --- ...ESOURCE-WP-0002-procure-postgres-backup-storage.md | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md b/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md index 6f9b496..140a395 100644 --- a/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md +++ b/workplans/RESOURCE-WP-0002-procure-postgres-backup-storage.md @@ -254,10 +254,13 @@ instructions, handle `secret:railiance-platform/backup`, first consumer projection Secret `platform-pg-backup-s3`. Non-secret destination handed at `rapp-postgres/docs/handoff/RESOURCE-WP-0002-T04-barman-destination.md`. -Waiting on founder: approve the CCR, use IAM application -`resource-control`, bind policy and key `Scoped backup access`, put -values in OpenBao, say “the backup key is in bao.” Do not enable WAL -yet. +2026-08-14: founder approved CCR-2026-0012 and put the backup key in +OpenBao (`ACCESS_KEY`/`SECRET_KEY` + org/project ids, version 1). +Positive S3 list/get and prefix put/get/delete succeeded. Negative: +bogus secret denied; IAM/billing/k8s list denied. Distinct from the +bootstrap key. Not done: OpenBao policy apply (this token 403), ESO +Secret `platform-pg-backup-s3` (absent on railiance01), bucket policy +(no `APPLICATION_ID`). WAL still off. ## T05 — Prove backup, full restore, and PITR