A tiny FastAPI + boto3 app that exists for one reason: to prove, end to
end, that c2a daari secrets bind actually wires an S3-shaped Secret
into a running pod's environment. It's a sibling demo to
pg-hello-py, covering the S3 credential shape instead
of Postgres.
GET /— friendly HTML landing page, links to/bucket-checkGET /bucket-check— creates an S3 client usingAWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY/AWS_REGIONfrom the environment, lists up to 10 keys inS3_BUCKET_NAME, and returns:- success:
{"ok": true, "bucket": "...", "region": "...", "keyCount": N, "keys": [...]} - failure:
{"ok": false, "error": "..."}with HTTP 500
- success:
The app fails fast at startup (SystemExit(1) with a clear stderr
message) if any of the four required env vars is missing. That's
deliberate — a silently-missing binding is exactly the failure mode this
app exists to catch, so we'd rather crash loudly on boot than serve
requests against vars that were never set.
Paketo auto-detects the Procfile (web: uvicorn app:app --host 0.0.0.0 --port $PORT) — no server.py/Node concerns, this is a pure Python
buildpack app.
c2aCLI installed and authenticated (c2a login)- An active project set (
c2a project use <name>— check withc2a project show) - A reachable S3 bucket (any disposable dev bucket works) with an IAM user/role you're willing to paste credentials for into a Daari Secret
-
Confirm your active project:
c2a project show
-
Create the Daari Secret holding the S3 credentials:
c2a daari secrets create s3-hello-creds \ --from-literal AWS_ACCESS_KEY_ID=<key-id> \ --from-literal AWS_SECRET_ACCESS_KEY=<secret> \ --from-literal AWS_REGION=<region> \ --from-literal S3_BUCKET_NAME=<bucket>
Note the
k8sNameprinted in the output (in parentheses) — that's whatdaari secrets bindtakes as its second argument, not the display name you typed. -
Deploy the app from this directory's git remote (or any fork/mirror of it):
c2a app create s3-hello-py -g <git-url-for-this-repo-or-a-fork>
-
Bind the secret to the app:
c2a daari secrets bind s3-hello-py <k8sName-from-step-2>
This writes the
s3-hello-py-service-bindingSecret'sC2A_SYSTEM_ENVJSON (the platform's runtime binding contract — variables / secrets / bindings all serialized together) and additive-patches the ksvc'senvFromto reference it. The platform init step unpacks that JSON into plain env vars beforeapp.pystarts, so this app never parsesC2A_SYSTEM_ENVitself — it just readsAWS_ACCESS_KEY_IDetc. fromos.environas shown above. -
Wait for the new revision to become Ready, then verify:
c2a app show s3-hello-py -f url curl "$(c2a app show s3-hello-py -f url)/bucket-check"Expect
{"ok":true,"bucket":"...","region":"...","keyCount":N,"keys":[...]}.
c2a daari secrets create uses the CLI's active project's namespace
with no override flag and no warning. If you're not sure which project is
active, secrets can land in the wrong namespace and go undetected until a
bind silently fails to find them. Always run c2a project show first.
Unlike pg-hello-py, this demo has no e2e.sh. Standing up a real S3
bucket + IAM credentials isn't something we want to automate against in
CI-style runs; see NOTE.md for details. Use the manual
walkthrough above.