The access server is stateless process deployment over Group 0 and the chunk layer. Complete the KV and chunk checks first. Use distinct listen addresses for every access process; keep credentials in the local secret store or process environment, never in Group 0.
S3 access
The local S3 process uses CROWDB_S3_LISTEN, CROWDB_MANAGEMENT_SEEDS, CROWDB_S3_TENANT, CROWDB_S3_REGION and CROWDB_S3_MASTER_KEY. Supply a generated private master key through your local secret mechanism. Set CROWDB_S3_TRUSTED_NETWORK only for an isolated development network. The CLI mini-cluster is a separate local evaluation workflow; its restart state contains process inputs and Group 0 seeds, without a local topology copy.
For an isolated loopback development host, save a generated 64-character hexadecimal master key as CROWDB_S3_MASTER_KEY in a private /srv/crowdb/access/private.env file (mode 0600). Keep this file out of source control. From the CROWDB checkout, launch the matching build after sourcing that file:
set -a
. /srv/crowdb/access/private.env
set +a
CROWDB_MANAGEMENT_SEEDS=http://127.0.0.1:10000 \
CROWDB_S3_LISTEN=127.0.0.1:16000 \
CROWDB_S3_TENANT=local CROWDB_S3_REGION=us-east-1 \
CROWDB_S3_TRUSTED_NETWORK=true \
pixi run -- target/release/crowdb-access-serverUse a service manager with the same private environment and executable for a persistent process; the command above occupies the terminal. Require its ready endpoint before issuing S3 requests:
curl -f http://127.0.0.1:16000/_crowdb/health/readyReplace port 16000 with CROWDB_S3_LISTEN. A successful HTTP health check alone does not prove durable storage: also verify live Group 0 service registrations and an object write/read on disposable data. The S3 object guide describes those requests.
Iceberg access
The single-node Docker quick start is the verified evaluation path for the Iceberg catalog and FileIO. It is independent of this bare-metal process setup. Use the Iceberg guide for client requests and limitations. Multi-machine bare-metal Iceberg deployment and recovery are not yet production-ready.
Operations boundary
If Group 0 is unavailable, do not substitute a local launch registry, an old console file or a cached monitor view for access topology. Keep access-server secrets out of ordinary logs and rotate them through the local secret mechanism. Use disposable data for this development deployment.