Repository navigation
V0.5
s3gc v0.5
This release adds a safer Kubernetes Job workflow, flexible S3 authentication, and important correctness fixes for orphan
collection and deletion.
Highlights
-
Added Kubernetes Job phases for collect, dry-run, approved delete, and verify.
-
Added development-only dev-automation phase for end-to-end fixture testing.
-
Added S3 authentication modes:
- static credentials, including session tokens
- aws boto3 credential chain / AWS SSO profiles
- iam workload identity for IRSA, EC2 instance profiles, and ECS task roles
-
Published public multi-architecture images to ghcr.io/altinity/s3gc.
-
Added GCS compatibility: GCS endpoints automatically use per-object deletion because batch deletion is unsupported.
-
CI now runs offline tests, renders the Kubernetes Job, and validates it with strict Kubeconform schemas.
Fixes
- Fixed boolean environment parsing.
- Fixed --age for objects older than 24 hours.
- --usecollected now fails clearly when the auxiliary table is missing or empty.
- Added per-delete checkpointing and cumulative deletion totals.
- Added clearer S3 listing-permission errors and broader secret redaction.
Breaking change
S3GC_S3USEIAM / --s3useiam was removed. Use:
S3GC_S3AUTH=iam
Use S3AUTH=static|aws|iam in Kubernetes rendering configuration.
Operational notes
- Use a per-replica ClickHouse Service consistently across all phases.
- Always follow:
collect → dry-run → explicit approval → delete → verify
- Use digest-pinned images and a dedicated ClickHouse user with the documented minimum grants.