Skip to content

docs(compadre): document native input object permissions - #57

Merged
imsherrill merged 1 commit into
mainfrom
docs/native-input-storage-rollout
Sep 11, 2026
Merged

imsherrill merged 1 commit into
mainfrom
docs/native-input-storage-rollout

Conversation

@imsherrill

Copy link
Copy Markdown

The live 20 MiB image canary exposed a missing IAM grant for the new native-input prefix. HeadBucket and central uploads succeeded, but native PutObject failed safely before run creation.

The existing CompadreAttachmentBucketAccess policy now additionally allows only GetObject/PutObject on compadre/attachments/native-inputs/v1/*, preserving existing grants and public-access blocks. Document the exact scope and require a real native upload in the deployment preflight. No credentials, deletion grants, or public access changed.

Model/harness: GPT-5 / Codex.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S labels Sep 11, 2026
@imsherrill
imsherrill merged commit aa57ba9 into main Sep 11, 2026
14 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant