Skip to content

Commit 87935d6

Browse files
gregoryfosterclaude
andcommitted
#1 fix: CR 12 — Watcher's reader grant ran 2026-10-02 (co-gcs-blob-reader, per the bucket's IAM policy)
watcher#325 has not yet confirmed that identity; the runbook says what to do if Watcher names another. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 parent 3f61a3c commit 87935d6

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

‎docs/DEPLOYMENT.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ Processor runs as one systemd unit, `processor`, on exe.dev VM `co-processor`. C
1515
| Bucket `gs://co-gcs-processor`, UBLA, public access prevention, no lifecycle | GCP | done 2026-10-02, [GCP provisioning](#gcp-provisioning) (spec §2) |
1616
| SA `co-gcs-processor-writer`: `objectCreator` + `objectViewer` on `co-gcs-processor` (**no delete**), `objectViewer` on `co-gcs-blobs` | GCP | done 2026-10-02, [GCP provisioning](#gcp-provisioning) (spec §2) |
1717
| SA key at `/etc/processor/co-gcs-processor-writer.json` (600) | this VM | done 2026-10-02; the writer's preflight reached both buckets |
18-
| Watcher's reader: `objectViewer` on `co-gcs-processor`, bucket level. Proposed for `co-gcs-blob-reader`, the identity Watcher already reads `gs://` blobs with | GCP | watcher#325 (unconfirmed) |
18+
| Watcher's reader: `objectViewer` on `co-gcs-processor`, bucket level, for `co-gcs-blob-reader`, the identity Watcher already reads `gs://` blobs with | GCP | done 2026-10-02 (in the bucket's IAM policy); watcher#325 has not yet confirmed that identity |
1919

2020
### Broker credential handoff (hash-only, broker#75 as of 2026-09-30)
2121

@@ -68,7 +68,8 @@ gcloud storage buckets add-iam-policy-binding gs://co-gcs-blobs \
6868

6969
# 4. Watcher's reader. Proposed: co-gcs-blob-reader, which Watcher already reads
7070
# gs:// blobs with (GCS_BLOB_CREDENTIALS). It gains nothing new, since the text
71-
# is derived from blobs that identity can read. Run once watcher#325 agrees.
71+
# is derived from blobs that identity can read. Run 2026-10-02, ahead of
72+
# watcher#325's answer; if Watcher names another identity, grant that one too.
7273
gcloud storage buckets add-iam-policy-binding gs://co-gcs-processor \
7374
--member="serviceAccount:co-gcs-blob-reader@${PROJECT}.iam.gserviceaccount.com" \
7475
--role=roles/storage.objectViewer

0 commit comments

Comments
 (0)