Skip to content

docs(cache): dedicated public bucket (don't expose user-builds)#191

Merged
mdheller merged 1 commit into
mainfrom
cache-doc-fix
Jun 22, 2026
Merged

docs(cache): dedicated public bucket (don't expose user-builds)#191
mdheller merged 1 commit into
mainfrom
cache-doc-fix

Conversation

@mdheller

Copy link
Copy Markdown
Contributor

Fixes a dangerous instruction merged in #189: the old setup told you to make gs://sourceos-artifacts-socioprophet public, but that bucket holds private user-builds/. Documents the dedicated gs://sourceos-nix-cache-socioprophet that's now actually provisioned (public-read + CI SA write), keeping user data private. Docs-only.

The artifacts bucket holds private user-builds/, so making it public (as the
old step 2 said) would leak them. Document the dedicated public bucket
gs://sourceos-nix-cache-socioprophet that's actually provisioned, plus the CI
SA write grant. Provisioning is already done (vars/secrets set, keys in
~/.sourceos-keys/); steps kept for rotation.
@mdheller mdheller merged commit 175f0f0 into main Jun 22, 2026
@mdheller mdheller deleted the cache-doc-fix branch June 22, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant