# One machine running an object store that other machines use. # # The same shape as `a-provider`, against a different kind of provision, and that is the whole # reason it exists: novox/hq 04-ISSUES and the work breakdown's Phase 1.1 ask whether a module can # be given a bucket the way it is given a database. The provisioning model is name-agnostic — the # control plane special-cases neither — so what is unproven is not the mesh's half but the last # step, where something on the machine turns a delivered secret into a key that works. # # It also proves the half a database does not: **a consumer must not be able to reach another # consumer's bucket.** One store holds everybody's, where one PostgreSQL server holds separate # databases, so isolation here is a policy somebody wrote rather than a boundary the product has. scenario: an-object-store segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } egress: true inbound: allow place: all: [runtime]