Skip to content

DL-063

Agent session transcripts persist to S3 for v1 via an ENDPOINT-AGNOSTIC backend (COMPASS_S3_ENDPOINT, generic Bun.S3Client, no S3-server-specific calls), reached under default-deny egress via an allowlisted endpoint — the S3 client path is exercised from v1, never a swap-later local-fs abstraction. Solo/self-host backend is a local-filesystem Garage (≥ v2.3.0) per Runner host, granting a full-bucket credential (cross-agent read/tamper accepted only within the single-trust-domain MVP); real/multi-user deployments MUST NOT use the Garage full-bucket credential — they use Cloudflare R2 with prefix-scoped tokens, which is a CONFIG change not a new build (endpoint-agnostic). Docs advisory + hardening follow-up (“R2 + prefix-scoped tokens for real deployments”) stated; no bucket-per-agent, no Runner signing proxy

Status: Superseded by DL-084 (Matt, 2026-07-31)

Record: ../../agent/compass-agent-session-persistence/design.md#appendix–superseded-by-the-reversal-2026-07-31-the-agent-direct-s3-model