Architecture
Every deployment defines three profiles:quarantinereceives user-controlled uploads;recordsholds scanner-approved durable data and generated exports; andephemeralholds canaries and short-lived objects.
@cbr/storage boundary implements canonical adapters s3, gcs,
azure, and local. Runtime operations include health, upload, download,
exists, list, metadata, copy, delete, retention, and legal hold. Runtime never
creates or configures buckets/containers and never generates signed URLs.
User uploads are written behind a durable upload intent, read back and
SHA-256-verified, scanned by external clamd, and copied to records only
after a clean verdict. Durable mutation, migration, and reconciliation workers
retry idempotently and expose dead-letter/integrity telemetry.
Start here
Support Policy
Current machine-readable support and qualification status
Select a Provider
Compare live certification requirements and evidence levels
Security Baseline
Quarantine, scanning, integrity, encryption, WORM, and secret controls
Backup and Restore
Protect PostgreSQL and exact object versions as one set
Migration Runbook
Copy-first cutover, ledger verification, source retention, and rollback
Health and Troubleshooting
Readiness categories, canary, scanner, CA, permissions, and dead letters
Provider guidance
OpenShift ODF/Ceph RGW
External OBC or standalone RGW with private CA and restricted egress
AWS S3
Existing buckets and workload identity
Google Cloud Storage
Existing buckets and Workload Identity
Azure Blob
Existing containers and Managed Identity
S3-Compatible Products
Exact-product/version live certification policy
Local and MinIO
Development-only local storage and legacy MinIO migration