DreamLake

Living dev note. Iterate freely.

One bucket per environment for daemon blobs (exec/, run/, session/, daemon-logs/). Tier-2 archive details in Log storage.

Run it

bash
~/fortyfive/lakeshore-workspace/dev/s3-provision/setup.sh

Creates both lakeshore-blobs-dev and lakeshore-blobs-prod in us-east-1, applies lifecycle + CORS + encryption to each, and creates the shared IAM user lakeshore-controlplane that the controlplane uses to mint presigned URLs. this is idempotent — safe to re-run.

The script outputs a command that you should copy and paste. it contains the secrets. For staging / dev, it looks like the following:

shell
# do NOT run this
heroku config:set \
  AWS_ACCESS_KEY_ID=... \
  AWS_SECRET_ACCESS_KEY=... \
  AWS_REGION=us-east-1 \
  LAKESHORE_BLOBS_BUCKET=lakeshore-blobs-dev \
  --app lakeshore-controlplane-staging

For prod, run:

bash
aws iam create-access-key --user-name lakeshore-controlplane

heroku config:set \
  AWS_ACCESS_KEY_ID=... \
  AWS_SECRET_ACCESS_KEY=... \
  AWS_REGION=us-east-1 \
  LAKESHORE_BLOBS_BUCKET=lakeshore-blobs-prod \
  --app lakeshore-controlplane

(Same key works for both — the IAM policy covers all lakeshore-blobs-*.)

Files in this dir

FileWhat
setup.shOrchestrates everything
lifecycle.jsonPer-prefix retention (exec=30d, session=7d, run=365d, daemon-logs=14d)
cors.jsonBrowser GETs from the dashboard origin
controlplane-policy.jsonIAM policy for the controlplane

Verify

bash
echo hi | aws s3 cp - s3://lakeshore-blobs-dev/exec/2026/05/22/test/out
aws s3 cp s3://lakeshore-blobs-dev/exec/2026/05/22/test/out -
aws s3 rm s3://lakeshore-blobs-dev/exec/2026/05/22/test/out

What I (the agent) can't do

Provision the bucket (no AWS creds at the agent layer). When you've run setup.sh and set Heroku config, I'll wire the controlplane code (@aws-sdk/client-s3 already a dep) to mint presigned URLs per exec and embed them in ExecBody.log.