Skip to content

feat: delegate application S3 resources - #8

Merged
glitchedmob merged 4 commits into
mainfrom
feat/delegate-kaneo-aws-resources
Sep 2, 2026
Merged

feat: delegate application S3 resources#8
glitchedmob merged 4 commits into
mainfrom
feat/delegate-kaneo-aws-resources

Conversation

@glitchedmob

@glitchedmob glitchedmob commented Sep 2, 2026

Copy link
Copy Markdown
Member

Establishes a reusable control-plane/data-plane boundary for application-owned S3 storage managed by infra-app-config.

  • Allows infra-app-config to create and configure arbitrary S3 buckets without object-data access.
  • Protects the shared Terraform state bucket from application bucket management and workload access.
  • Allows infra-app-config to create arbitrarily named, repository-owned IAM roles without assuming or passing them.
  • Requires every application role to use a boundary limited to approved S3 operations from SGF Devs K3s service-account identities.
  • Lets each application role policy select its own bucket without future infra-aws-core changes.

@glitchedmob glitchedmob changed the title feat: delegate Kaneo AWS resources feat: delegate app configuration AWS resources Sep 2, 2026
@glitchedmob glitchedmob changed the title feat: delegate app configuration AWS resources feat: delegate application S3 resources Sep 2, 2026
@glitchedmob
glitchedmob merged commit fa8ed03 into main Sep 2, 2026
3 checks passed
@glitchedmob
glitchedmob deleted the feat/delegate-kaneo-aws-resources branch September 2, 2026 10:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant