Storage Tiering Service · View 29 of 31 · 7 · Assurance
Decisions
- SPIRE attests the pod and issues a JWT-SVID. RGW's STS trusts SPIRE's OIDC discovery endpoint and exchanges the SVID for credentials bound to one role: PutObject on one tier, or DeleteObject on one tier.
- Roles are per tier and per operation. There is no role that can both write to cold and delete from warm, so no single token can complete a movement end to end.
- OpenBao holds tenant keys for RGW server-side encryption. The mover never sees a key, only a key id.
Proof-phase checks
- RGW AssumeRoleWithWebIdentity accepting SPIRE-issued JWT-SVIDs with the expected audience and subject claims.
- RGW SSE-KMS against OpenBao's transit engine at mover write rates, and behaviour when OpenBao is briefly unreachable: writes should fail, not fall back to unencrypted.
Numbers
- SVID lifetime 5 minutes, STS credentials 15 minutes, renewed at two thirds of lifetime.