Parent
#35
What to build
Slice 2c of the transformation architecture: data renders, so its share of the tree is produced by the core and replaces the hand-written placeholder tree. What 2b resolved now reaches the rendered objects, and backups land with the decisions taken for them (deploy audit rows 22 and 23, SC-41 row 19):
- Grants. A new
vso adapter renders a VaultAuth per Process holding a grant and a VaultStaticSecret per synced grant, in the Application's own directory (vso.yaml), each destination excluded from Flagger's configuration tracking. A new vault-policy adapter renders one policy and one Kubernetes auth role per Process identity, at apps/vso-secrets/policies/<namespace>/<process>.{policy,role}.json, estate-scoped and listed by no kustomization (rendered, not applied).
- Env and file delivery. A secret reference renders as a
secretKeyRef to the grant's synced Secret; a file grant mounts it.
- Assets. An Asset renders as an immutable
ConfigMap under its content-hashed name, mounted at its mountAt.
- Sidecars. A sidecar renders as a container beside the Process, under the platform's posture.
- Writable paths. Each renders as an
emptyDir at the platform's ephemeral size.
- Backups.
- A backed-up volume renders a backup
CronJob at its class's schedule, running the engine's method image, which prunes to retain copies. No separate sweep job.
- Each runs as a derived per-Process backup identity,
<process>-backup. Only that identity holds the off-cluster credential, never the serving Process.
- Each volume derives a
<claim>-backup claim of the same size, the on-cluster copy.
- A claim whose class derives a backup, and its backup claim, are never pruned.
retain counts copies kept, as chapter 10 says.
Acceptance criteria
Blocked by
None: slice 2b (#189) is merged.
Parent
#35
What to build
Slice 2c of the transformation architecture:
datarenders, so its share of the tree is produced by the core and replaces the hand-written placeholder tree. What 2b resolved now reaches the rendered objects, and backups land with the decisions taken for them (deploy audit rows 22 and 23, SC-41 row 19):vsoadapter renders aVaultAuthper Process holding a grant and aVaultStaticSecretper synced grant, in the Application's own directory (vso.yaml), each destination excluded from Flagger's configuration tracking. A newvault-policyadapter renders one policy and one Kubernetes auth role per Process identity, atapps/vso-secrets/policies/<namespace>/<process>.{policy,role}.json, estate-scoped and listed by no kustomization (rendered, not applied).secretKeyRefto the grant's synced Secret; a file grant mounts it.ConfigMapunder its content-hashed name, mounted at itsmountAt.emptyDirat the platform's ephemeral size.CronJobat its class's schedule, running the engine's method image, which prunes toretaincopies. No separate sweep job.<process>-backup. Only that identity holds the off-cluster credential, never the serving Process.<claim>-backupclaim of the same size, the on-cluster copy.retaincounts copies kept, as chapter 10 says.Acceptance criteria
data's rendered share equals its committed golden tree byte for byte, every file attributed to one adapter.vso,vault-policyand backup spellings are stated in chapter 30 and proven at the adapter seam.dataobject.Blocked by
None: slice 2b (#189) is merged.