fix(preprocess): harden S3 and real Compose jobs
This commit is contained in:
@@ -25,3 +25,21 @@ Operational risk: custom S3-compatible endpoints remain part of the deployment t
|
||||
Private endpoint access must be explicitly enabled and should be restricted by container egress
|
||||
policy in production. S3 list consistency semantics are provider-defined; version IDs are preferred
|
||||
over ETags wherever bucket versioning is available.
|
||||
|
||||
## Review correction
|
||||
|
||||
The Compose overlay now uses committed, purpose-built Evidence and DWH workspace files with
|
||||
job-specific dependencies. Its services create their lock roots and mount only the vector secrets
|
||||
they consume. The operational smoke is a real isolated Compose project: real pgvector migrations,
|
||||
a deterministic in-project embeddings endpoint, actual Evidence CLI JSON across initial/unchanged/
|
||||
mutated runs, exact ACTIVE verification, an actual DWH introspection job, and owned cleanup.
|
||||
|
||||
S3 custom endpoints now fail closed unless declared trusted; HTTP and private loopback endpoints
|
||||
need additional independent opt-ins. Boto uses forced path-style addressing. Custom endpoints reject
|
||||
userinfo, query, fragment, and non-root paths. Buckets use strict DNS syntax; listed keys must remain
|
||||
under prefix and within the S3 byte bound; validators must be nonempty/bounded. Because
|
||||
ListObjectsV2 does not provide version IDs, discovery honestly fingerprints the exact ETag and
|
||||
acquisition rejects ETag drift.
|
||||
|
||||
Final correction verification: S3/config focused 20 passed; full harness 721 passed, 5 deselected;
|
||||
real Compose smoke and image build passed; scoped Ruff, shell syntax, and diff checks passed.
|
||||
|
||||
Reference in New Issue
Block a user