Selection flow
- Choose an external, customer-managed service reachable by both web and worker.
- Provision separate
quarantine,records, andephemerallocations. - Confirm identity, TLS/private CA, encryption, versioning, retention, legal hold, audit logging, egress, backup, and restore requirements.
- Compare the exact product profile with
scripts/storage/certification-matrix.json. - Run live qualification against the exact product/version from the workload network.
- Sign and retain sanitized evidence with the release record.
Current matrix interpretation
Current ODF/Ceph live evidence is blocked on customer credentials. It is
configured and qualification-ready, not certified. Update customer-facing
status only after the release validator accepts signed exact-version evidence.
Evidence levels
- Unit proves local adapter behavior in controlled code tests.
- Emulator proves SDK and contract compatibility with an emulator’s subset.
- Live proves the required operations against a named product and exact version in the intended network, trust, identity, and policy context.
requiredCertification is live. Product family names such as “S3
compatible,” “Ceph,” or “Azure Blob” are insufficient without an exact target
version and evidence digest.
Emulator compatibility is not live certification.
Validate the matrix
scripts/storage/certification-evidence.template.json. Never add
credentials, tokens, connection strings, private keys, object contents,
customer object names, or signed URLs to evidence.
Configuration examples
For production, prefer a mode-0400 or 0600 mounted
STORAGE_CONFIG_FILE. This shape is illustrative:
Requalification triggers
Re-run live evidence after changing any of:- CaseBender release or storage SDK;
- provider, ODF, Ceph, account, or API version;
- bucket/container security, versioning, retention, or immutability;
- identity, role, credential, endpoint, private CA, or egress policy;
- scanner/promotion boundary; or
- backup, migration, and restore tooling.