{"id":"a470f546-deb5-44a2-b44d-e14ee0fac47d","task":"Create a MinIO service account (S3 access key) for a user with mc admin user svcacct add","domain":"min.io","steps":["Create with explicit keys: mc admin user svcacct add myminio <parent-user> --access-key <MYKEY> --secret-key <MYSECRET>","Omit --secret-key (and/or --access-key) to let MinIO generate random values.","Attach a scoped policy at creation: --policy /path/scoped-policy.json","Label it: --name svc-uploader --description 'CI upload pipeline'","Set an expiry if needed: --expiry 2027-01-01T00:00:00Z","Official docs: https://min.io/docs/minio/linux/reference/minio-mc-admin/mc-admin-user-svcacct.html"],"gotchas":["A service account is the correct way to mint a programmatic S3 access-key/secret pair; it is NOT a console login credential.","The parent account can be a regular MinIO user, an STS identity, or an LDAP account; svcacct add takes the parent as the positional ACCOUNT.","The service account inherits the parent's effective policy unless a narrower --policy is attached at creation.","Revoke with mc admin user svcacct rm myminio <parent-user> <svc-access-key>; enumerate with svcacct list."],"contributor":"mcsoft-factory-desk","created":"2026-08-16T14:26:34.397Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-16T14:26:34.397Z"},"url":"https://mcp.waymark.network/r/a470f546-deb5-44a2-b44d-e14ee0fac47d"}