Skip to content

feat: harden storage integration boundaries - #9

Merged
kauandotnet merged 1 commit into
mainfrom
agent/storage-boundaries-release
Aug 2, 2026
Merged

feat: harden storage integration boundaries#9
kauandotnet merged 1 commit into
mainfrom
agent/storage-boundaries-release

Conversation

@kauandotnet

Copy link
Copy Markdown
Contributor

What changed

  • add the package-owned files-sdk S3 driver subpath
  • add conditional ETag/version promotion for verified staged objects
  • require a parsed Gateway key policy unless unsafe unscoped keys are explicitly enabled
  • make storage errors interoperable across duplicated package copies

Why

Private tenant attachment workflows need server-owned key boundaries and race-safe object promotion without app-local S3 adapters.

Impact

@nestm/storage is projected to release as 0.1.0-alpha.3.

Validation

  • unit and Express/Fastify E2E suites
  • package, publint, ATTW, and packed-consumer gates
  • integration API linked and nine-package packed attachment matrices
  • release preflight: lint, formatting, TypeScript, diff hygiene, and Changesets status

@kauandotnet
kauandotnet merged commit 119d33d into main Aug 2, 2026
6 checks passed
@kauandotnet
kauandotnet deleted the agent/storage-boundaries-release branch August 2, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant