Skip to main content
← Back to list
01Issue
FeatureOpenExtensionsPublic
AssigneesNone

Relationships

#2339 s3-datastore: per-datastore AWS profile, so a serve audit store can use different credentials from the main datastore

Opened by randybias · 9/22/2026

Problem

design/enablers/serve-audit.md recommends a dedicated audit bucket: "audit data should not live alongside application data, so it cannot be tampered with by someone who has access to the main datastore." That separation only holds if the audit store uses different credentials from the main datastore — otherwise one key reaches both buckets.

It cannot be configured today. @swamp/s3-datastore takes credentials only from the default AWS credential chain (its config has bucket, prefix, region, endpoint, forcePathStyle — no credential or profile field), and serve builds each audit store through the same datastore provider (src/cli/commands/serve.ts, RemoteAuditStore), inside one process with one credential chain. So the audit store necessarily runs as the same S3 identity as the datastore. With properly separated bucket users (datastore user denied the audit bucket, audit user denied the datastore) the audit store simply gets 403.

Proposed solution

An optional profile field on the S3 (and GCS) datastore config, passed to the SDK's credential provider (fromIni({ profile }) / fromProcess({ profile })), so each datastore and each audit store target can name its own profile in ~/.aws/config. Credentials stay out of .swamp.yaml and serve.yaml; only a profile name is configured.

audit:
  stores:
    - target: security-audit
      type: "@swamp/s3-datastore"
      config:
        bucket: my-audit-bucket
        profile: swamp-audit        # new

Alternatives considered

  • Granting the datastore identity write access to the audit bucket: works, but defeats the separation the design doc recommends.
  • ${{ vault.get(...) }} credential fields in the config: would also work, but a profile keeps secrets entirely out of swamp config and composes with credential_process, which is how we source keys from a vault today.

Upstream repository: https://github.com/systeminit/swamp-extensions

Environment

  • Extension: @swamp/s3-datastore@2026.09.22.1
  • swamp: 20260922.011324.0-sha.2e949db5
  • OS: linux (x86_64)
  • Deno: 2.9.7
  • Shell: /bin/bash
02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/22/2026, 9:17:03 AM

No activity in this phase yet.

03Sludge Pulse

Sign in to post a ripple.