Living dev note. Iterate freely.
One bucket per environment for daemon blobs (exec/, run/,
session/, daemon-logs/). Tier-2 archive details in
Log storage.
Run it
Creates both lakeshore-blobs-dev and lakeshore-blobs-prod in
us-east-1, applies lifecycle + CORS + encryption to each, and
creates the shared IAM user lakeshore-controlplane that the
controlplane uses to mint presigned URLs. this is idempotent — safe to re-run.
The script outputs a command that you should copy and paste. it contains the secrets. For staging / dev, it looks like the following:
For prod, run:
(Same key works for both — the IAM policy covers all lakeshore-blobs-*.)
Files in this dir
| File | What |
|---|---|
setup.sh | Orchestrates everything |
lifecycle.json | Per-prefix retention (exec=30d, session=7d, run=365d, daemon-logs=14d) |
cors.json | Browser GETs from the dashboard origin |
controlplane-policy.json | IAM policy for the controlplane |
Verify
What I (the agent) can't do
Provision the bucket (no AWS creds at the agent layer). When you've
run setup.sh and set Heroku config, I'll wire the controlplane code
(@aws-sdk/client-s3 already a dep) to mint presigned URLs per exec
and embed them in ExecBody.log.