P6: S3 blob store, Helm chart, air-gapped installer verify loop
- S3BlobStore (object_store, path-style) behind the same BlobStore trait, tested against a REAL MinIO container (round trip, overwrite, NotFound on get and delete, nested keys); [storage] backend=local|s3 config with validation + server-side selection (S3 creds via env overlay) - Helm chart: server pod with the secret broker as a SIDECAR sharing a private emptyDir unix socket (no network hop carries credentials), frontend, optional local PVC vs S3, OIDC/oauth values, unbuffered-SSE ingress annotations, NetworkPolicies (frontend->server only), hardened securityContexts; ci/check-helm.sh lints AND asserts the rendered topology properties - deploy/airgapped/install.sh: offline signature+checksum verification via the bundled teamclaw-bundler BEFORE any docker load; --verify-only mode; ci/test-install.sh rehearses clean/tampered/wrong-key paths with the real binary - CI: helm gate + installer rehearsal wired in 149 Rust tests; helm lint + rendered assertions green; installer verify-path rehearsal green. Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
co-authored by
Claude Fable 5
parent
ccf96053e6
commit
70ec39f696
@@ -69,9 +69,20 @@ async fn run() -> Result<(), String> {
|
||||
}
|
||||
|
||||
let provider = build_provider(&config)?;
|
||||
let blob = std::sync::Arc::new(tc_files::LocalBlobStore::new(PathBuf::from(
|
||||
&config.storage.data_dir,
|
||||
)));
|
||||
let blob: std::sync::Arc<dyn tc_files::BlobStore> = match config.storage.backend {
|
||||
tc_config::StorageBackend::Local => std::sync::Arc::new(tc_files::LocalBlobStore::new(
|
||||
PathBuf::from(&config.storage.data_dir),
|
||||
)),
|
||||
tc_config::StorageBackend::S3 => std::sync::Arc::new(
|
||||
tc_files::S3BlobStore::connect(
|
||||
config.storage.s3_endpoint.as_deref().expect("validated"),
|
||||
config.storage.s3_bucket.as_deref().expect("validated"),
|
||||
config.storage.s3_access_key.as_deref().unwrap_or_default(),
|
||||
config.storage.s3_secret_key.as_deref().unwrap_or_default(),
|
||||
)
|
||||
.map_err(|e| format!("s3 storage: {e}"))?,
|
||||
),
|
||||
};
|
||||
let runtime = Runtime::with_blob_store(
|
||||
pool.clone(),
|
||||
provider,
|
||||
|
||||
Reference in New Issue
Block a user