fix(evidence): close S3 and smoke safety gaps
This commit is contained in:
@@ -72,7 +72,9 @@ docker compose -f compose.yaml -f deploy/compose.local-vector.yaml \
|
||||
S3 Evidence uses the optional `tht[s3]` dependency and canonical `s3://bucket/key` provenance.
|
||||
AWS endpoints are used when no custom URL is supplied. Every custom endpoint is an explicit egress
|
||||
trust-boundary opt-in and uses path-style addressing; private and HTTP endpoints require additional
|
||||
independent opt-ins. Store access key, secret key, and session token as secret references in
|
||||
independent opt-ins. Literal non-global IPv4/IPv6 addresses are classified locally; hostnames are
|
||||
not DNS-pinned, so trusted custom-endpoint deployments must enforce their destination with network
|
||||
egress policy. Store access key, secret key, and session token as secret references in
|
||||
deployment configuration—never in Compose environment values or source URIs. Discovery and reads
|
||||
are bounded by configured page, object, and byte limits.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user