Skip to content

Unattended workflow guide #34

Description

@alukach

Alongside.

Do
One page, with short snippets per client environment (server or VM, Kubernetes, GitHub Actions): how to get credentials, how they refresh, how long they last, and what failure looks like when refresh is skipped.

Supersede, not just add
docs/using-source/data-upload.md, "Option 3: Long-standing or automated access", is 200 lines of "create an IAM role, then send us the ARN". It is the current human-in-the-loop answer to exactly this problem and becomes wrong when service accounts ship. data-proxy.md ("Authenticated Access with the Source CLI") and the credential sections earlier in data-upload.md describe acquisition too.

Include
Tools with their own credential handling — GDAL /vsis3, DuckDB httpfs, rclone — capture environment variables at process start, so a transfer longer than the credential lifetime fails mid-flight. That is the failure users will actually hit.

Watch
The sidebar is hand-enumerated in sidebars.ts; a new page must be added there or it will not appear.

Depends on source-cooperative/data.source.coop#223, source-cooperative/source.coop#548 and source-cooperative/data.source.coop#229.


Part of source-cooperative/source.coop#491.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions