A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)
mssql disables the login, mongodb takes the user's roles, minio revokes the key and keeps the bucket, mailu disables the mailbox, gitea prohibits the login instead of purging the user and their repositories, umami keeps the website. Each provider's create already enables what this locks.
This commit is contained in:
@@ -47,15 +47,10 @@ runProvisioner("s3-bucket", {
|
||||
async remove(p: { as: string; derived: Readonly<Record<string, unknown>> }): Promise<void> {
|
||||
const bucket = bucketNamed(p.derived);
|
||||
|
||||
// Revoking the key is what cuts the consumer's access. The bucket is emptied-then-dropped only if
|
||||
// empty; a bucket that still holds objects is left for an operator rather than erroring on every
|
||||
// reconcile tick — access is already gone, and silently deleting a consumer's data would be worse.
|
||||
// Revoking the key is what cuts the consumer's access, and the bucket is kept, empty or not
|
||||
// (novox/hq issue 241: a withdrawal never destroys a consumer's data — on 2026-10-04 a misread grants file withdrew every consumer at once). A bucket is removed by a person, never by this loop.
|
||||
try { await minio.removeAccessKey(p.as); } catch { /* already gone */ }
|
||||
try {
|
||||
await minio.removeBucket(bucket);
|
||||
} catch (err) {
|
||||
console.error(`[minio] bucket ${bucket} not removed (likely non-empty), access revoked: ${err}`);
|
||||
}
|
||||
console.error(`[minio] ${p.as} withdrawn: access key revoked, bucket ${bucket} kept`);
|
||||
|
||||
await announce("bucket.removed", { bucket, accessKey: p.as });
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user