Skip to content

seaweedfs-buckets

One OpenTofu root, terraform/40_seaweedfs-buckets, that declares SeaweedFS S3 buckets and lands their credentials in OpenBao where exactly one Kubernetes namespace can read them.

Two providers, no third-party ones: hashicorp/aws talks to the S3 and IAM APIs that SeaweedFS serves on a single port, and hashicorp/vault writes the resulting keys into OpenBao. The server side of that endpoint is s3-01.

Buckets are owned here and nowhere else; Nix on s3-01 carries no bucket names. See The declaration.