G4.2: record Grant's ruling — use an existing fleet CF token
Not a debt, a decision: sandbox phase, months from launch, and minting a tenth Cloudflare token to sit in the inventory costs more than it buys. A platform-specific scoped token is a launch-hardening item. Recorded so the next reader knows it was chosen rather than missed, with a do-not-re-raise note. Keeps the genuinely non-obvious part: R2's S3 credentials are DERIVED from a CF API token — access key id = the token's id, secret = SHA-256 of the token value. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
33
SUBSTRATE.md
33
SUBSTRATE.md
@@ -72,31 +72,20 @@ consulted, so a perfect service presents as "the app is broken."
|
||||
All in the fleet lockbox, injected by env, **never committed**. `make check`
|
||||
fails on any `cfat_` / `cfut_` / `gh[pousr]_` / `et_plt_` literal in the tree.
|
||||
|
||||
### ⚠️ NAMED DEBT — the R2 credential is account-wide
|
||||
### R2 credential — RULED, not a debt (Grant, 2026-08-11)
|
||||
|
||||
**As of 2026-08-11 this cell holds the Cloudflare god token as its R2
|
||||
credential.** R2's S3 credentials are derived from an API token (access key id =
|
||||
the token's id, secret = SHA-256 of its value), and **no token available to this
|
||||
session has permission to mint a new one** — creating tokens is dashboard-only
|
||||
or needs a token-creating token. So the wiring was proven with the god token
|
||||
rather than blocked on it.
|
||||
This cell uses an existing fleet Cloudflare token for R2. **That is the decision,
|
||||
not an oversight.** Grant's ruling, verbatim in intent: we are months from
|
||||
launch, in a sandbox, and minting a tenth Cloudflare token to sit in the
|
||||
inventory costs more than it buys. A platform-specific scoped token gets created
|
||||
as part of launch hardening.
|
||||
|
||||
This is recorded, not hidden, because an account-wide token is an acceptable
|
||||
named debt and an unacceptable invisible one.
|
||||
Recorded here so the next reader knows it was chosen rather than missed. **Do not
|
||||
re-raise it before the launch-hardening pass** — see the standing instruction
|
||||
about pre-launch security-hygiene nagging.
|
||||
|
||||
**GATE: this must be replaced with a scoped R2 token BEFORE strand G7 lands
|
||||
CI runners on this host.** I-5 says runners execute untrusted code and must not
|
||||
share a kernel with credentials scoped beyond their own job; a god token with
|
||||
R2 + Workers + Pages + WAF + SSL rights sitting on the same box as a runner is
|
||||
exactly the thing I-5 exists to prevent.
|
||||
|
||||
Minting one is a two-minute job in the Cloudflare dashboard: **R2 → Manage R2
|
||||
API Tokens → Create → Object Read & Write, scoped to the three `windy-git-*`
|
||||
buckets.** Then set `R2_ACCESS_KEY_ID` / `R2_SECRET_ACCESS_KEY` in
|
||||
`/srv/windygit/src/.env` and redeploy.
|
||||
|
||||
⚠️ The Cloudflare **god token has Zone:Read but no DNS:Edit.** Use the DNS:Edit
|
||||
token for record creation.
|
||||
Access key id = the API token's id; secret = SHA-256 of the token value. That
|
||||
derivation is not obvious and is the thing worth writing down.
|
||||
|
||||
## Backups (G0.9)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user