/** * Offload object-store dispatch — one lister, two backends. * * The read side of the offload loop (retriever probe, offload-delivery * verifier, doctor) has always shelled out to `aws s3api`. An env-config * destination of `type: "azure_blob"` therefore surfaced as an AWS CLI * failure, with a remedy telling the operator to fix IAM on a bucket that * does not exist. That is the defect this module closes: callers name the * store by its destination type and get the matching CLI, the matching URI * in every message, and a remedy phrased in that store's own vocabulary. * * Convention mirrors the AWS side deliberately: `execFile` on the vendor CLI * with a JSON output flag, a bounded `maxBuffer`, and a bounded timeout. No * SDK is added — `@azure/storage-blob` is not a dependency of this package, * and the probe/verifier/doctor paths already assume a CLI on PATH. * * Azure authentication follows the accessor's own order of preference. The * first call runs `--auth-mode login`, which uses whatever the `az` CLI is * already signed in as: an interactive login, an AKS workload identity, or a * service principal from `az login --service-principal`. When that call fails * and the environment carries an explicit storage credential * (`AZURE_STORAGE_CONNECTION_STRING`, `AZURE_STORAGE_KEY`, * `AZURE_STORAGE_SAS_TOKEN`), the call is retried once with it. An * environment holding only an account key therefore still works, and a signed * in operator is never forced to export one. * * Write support is out of scope here: the offload WRITE path for Azure Blob * does not exist (`offload-recipes.ts` emits S3 sinks only). This module is * the read side. */ /** The offload destination types this module can read. */ export type ObjectStoreKind = 's3' | 'azure_blob'; /** * Where offloaded objects live. `container` is the S3 bucket name or the * Azure Blob container name; `storageAccount` names the Azure account that * holds the container and is required when `kind` is `azure_blob`. */ export interface ObjectStoreTarget { kind: ObjectStoreKind; container: string; storageAccount?: string; } /** One listed object. Field names match the S3 shape the callers already read. */ export interface StoreObjectMeta { Key: string; Size?: number; LastModified?: string; } /** * Build a target from an env-config offload destination. `gcs` and `file` * destinations have no lister here and return undefined, so a caller can skip * rather than read them through the wrong CLI. */ export declare function objectStoreTargetFrom(dest: { type?: string; bucket?: string; storage_account?: string; } | undefined, fallbackContainer?: string): ObjectStoreTarget | undefined; /** The address an operator can paste into their own CLI. */ export declare function storeUri(target: ObjectStoreTarget, prefix?: string): string; /** The CLI the caller would run by hand to see the same listing. */ export declare function storeListCommand(target: ObjectStoreTarget, prefix?: string): string; /** * The remedy for a failed read, in the store's own vocabulary. The Azure * branch names data-plane blob roles, never IAM: an Azure operator has no IAM * to grant, and an IAM remedy sends them looking for a control that does not * exist on their account. */ export declare function storeReadAccessRemedy(target: ObjectStoreTarget): string; /** List objects under `prefix`. Throws on a store-level error (missing container, denied read). */ export declare function listStoreObjects(target: ObjectStoreTarget, prefix: string): Promise; /** Fetch one object's body as text. */ export declare function getStoreObject(target: ObjectStoreTarget, key: string): Promise;