Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion hosted/compadre/docs/production-cutover-checklist.md
Original file line number Diff line number Diff line change
Expand Up @@ -279,7 +279,9 @@ Canonical endpoints:
- [x] Create the private `s3://compadre` bucket in Comprehensive AWS account
`629591269808`, block public access, enable encryption and versioning, and
grant the Render `compadre` identity `s3:GetBucketLocation`/`s3:ListBucket`
plus `s3:GetObject`/`s3:PutObject` on `attachments/v1/*` only.
plus `s3:GetObject`/`s3:PutObject` on `attachments/v1/*`,
`attachments/native-inputs/v1/*`, and `backups/t3-state/v1/*`; no bucket-wide
object grant or delete permission.
- [x] Set `COMPADRE_T3_ARTIFACT_BUCKET=compadre` and
`COMPADRE_T3_ARTIFACT_REGION=us-west-2` on the Comprehensive production API
service.
Expand Down
15 changes: 15 additions & 0 deletions hosted/compadre/docs/production-secrets.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,3 +117,18 @@ existing disk's browser/asset/upload signing secrets and stable environment ID.
Their managed-secret migration is a disk-removal blocker. Do not retire
`COMPADRE_BACKUP_TOKEN` until both sides have switched and the final immutable
SQLite backup is archived. Follow the central PostgreSQL cutover runbook.

## Native input objects

Controller run inputs use `COMPADRE_T3_ARTIFACT_BUCKET=compadre` and region
`us-west-2`. The Render `compadre` IAM identity also needs `s3:GetObject` and
`s3:PutObject` on `arn:aws:s3:::compadre/attachments/native-inputs/v1/*`.
This is a separate prefix from central attachments; access to `attachments/v1/*`
does not cover it. Keep the bucket private and preserve the existing attachment
and backup grants when updating `CompadreAttachmentBucketAccess`. Do not grant
bucket-wide object access or add delete permission for this feature.

Verify an actual native input upload and hydrated worker request, not only
HeadBucket or central attachment upload. Missing prefix permission must fail
before run creation; it must never fall back to inline database bytes. See
[API reliability verification](runbooks/api-reliability-verification.md).
5 changes: 5 additions & 0 deletions hosted/compadre/docs/runbooks/api-reliability-verification.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,11 @@ remain after terminal completion. Verify the private `compadre` bucket
object's existence and normal attachment access. The GET endpoint deliberately
does not expose object bytes or storage credentials.

Preflight the controller IAM identity's GetObject/PutObject access to
`attachments/native-inputs/v1/*`; HeadBucket and central attachment uploads
alone do not prove that grant. The existing `attachments/v1/*` permission does
not include this prefix. See [production bindings](../production-secrets.md).

## Recovery implementation and rollout limits

New request attachments use the existing private artifact bucket under
Expand Down
Loading