P6: S3 blob store, Helm chart, air-gapped installer verify loop

- S3BlobStore (object_store, path-style) behind the same BlobStore trait,
  tested against a REAL MinIO container (round trip, overwrite, NotFound
  on get and delete, nested keys); [storage] backend=local|s3 config with
  validation + server-side selection (S3 creds via env overlay)
- Helm chart: server pod with the secret broker as a SIDECAR sharing a
  private emptyDir unix socket (no network hop carries credentials),
  frontend, optional local PVC vs S3, OIDC/oauth values, unbuffered-SSE
  ingress annotations, NetworkPolicies (frontend->server only), hardened
  securityContexts; ci/check-helm.sh lints AND asserts the rendered
  topology properties
- deploy/airgapped/install.sh: offline signature+checksum verification via
  the bundled teamclaw-bundler BEFORE any docker load; --verify-only mode;
  ci/test-install.sh rehearses clean/tampered/wrong-key paths with the
  real binary
- CI: helm gate + installer rehearsal wired in

149 Rust tests; helm lint + rendered assertions green; installer
verify-path rehearsal green.

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-10 08:19:43 -05:00
co-authored by Claude Fable 5
parent ccf96053e6
commit 70ec39f696
20 changed files with 851 additions and 3 deletions
+4
View File
@@ -2,6 +2,10 @@
//! filesystem implementation serves dev and the air-gapped target; an
//! S3-compatible implementation slots in behind the same trait for cloud.
mod s3;
pub use s3::S3BlobStore;
use std::path::{Component, Path, PathBuf};
#[derive(Debug, thiserror::Error)]
+84
View File
@@ -0,0 +1,84 @@
//! S3-compatible blob store (cloud target). The same `BlobStore` contract
//! as the local filesystem implementation; MinIO serves it in tests and
//! self-hosted installs, AWS S3 in managed clouds.
use object_store::aws::AmazonS3;
use object_store::path::Path as ObjectPath;
use object_store::{ObjectStore, PutPayload};
use crate::{BlobError, BlobStore};
pub struct S3BlobStore {
store: AmazonS3,
}
impl S3BlobStore {
/// `endpoint` is the S3 API base (http allowed for in-cluster MinIO);
/// credentials come from deployment secrets.
pub fn connect(
endpoint: &str,
bucket: &str,
access_key: &str,
secret_key: &str,
) -> Result<S3BlobStore, BlobError> {
let store = object_store::aws::AmazonS3Builder::new()
.with_endpoint(endpoint)
.with_allow_http(true)
.with_bucket_name(bucket)
.with_access_key_id(access_key)
.with_secret_access_key(secret_key)
.with_region("us-east-1")
// MinIO and most self-hosted S3s require path-style addressing.
.with_virtual_hosted_style_request(false)
.build()
.map_err(|e| BlobError::Io(e.to_string()))?;
Ok(S3BlobStore { store })
}
fn key(key: &str) -> Result<ObjectPath, BlobError> {
if key.is_empty() || key.split('/').any(|part| part.is_empty() || part == "..") {
return Err(BlobError::InvalidKey(key.to_owned()));
}
ObjectPath::parse(key).map_err(|e| BlobError::InvalidKey(e.to_string()))
}
}
#[async_trait::async_trait]
impl BlobStore for S3BlobStore {
async fn put(&self, key: &str, bytes: &[u8]) -> Result<(), BlobError> {
let path = Self::key(key)?;
self.store
.put(&path, PutPayload::from_bytes(bytes.to_vec().into()))
.await
.map_err(|e| BlobError::Io(e.to_string()))?;
Ok(())
}
async fn get(&self, key: &str) -> Result<Vec<u8>, BlobError> {
let path = Self::key(key)?;
match self.store.get(&path).await {
Ok(result) => Ok(result
.bytes()
.await
.map_err(|e| BlobError::Io(e.to_string()))?
.to_vec()),
Err(object_store::Error::NotFound { .. }) => Err(BlobError::NotFound),
Err(e) => Err(BlobError::Io(e.to_string())),
}
}
async fn delete(&self, key: &str) -> Result<(), BlobError> {
let path = Self::key(key)?;
// object_store's S3 delete is idempotent; the drive UX wants an
// honest NotFound, so probe first (head).
match self.store.head(&path).await {
Ok(_) => {}
Err(object_store::Error::NotFound { .. }) => return Err(BlobError::NotFound),
Err(e) => return Err(BlobError::Io(e.to_string())),
}
self.store
.delete(&path)
.await
.map_err(|e| BlobError::Io(e.to_string()))
}
}