Scaleway Setup Guide
How to connect a Scaleway project to AuditBadger with a dedicated read-only IAM application API key. Takes about 10
minutes.
1. Create the IAM application
1. In the Scaleway console, open IAM → Applications.
2. Create an application named auditbadger-compliance-reader.
Do not use a personal (user-owned) API key — application keys are not tied to a human account and survive offboarding.
2. Create the read-only policy
Open IAM → Policies, create a policy named auditbadger-compliance-read-only attached to the application, with two rule
groups:
- Organization scope:
- OrganizationReadOnly
- ProjectReadOnly
- IAMReadOnly (lets AuditBadger verify the key stays read-only)
- AuditTrailReadOnly (optional — only if you want Audit Trail evidence)
- Project scope, limited to the project(s) you want monitored:
- InstancesReadOnly
- BlockStorageReadOnly
- ObjectStorageBucketsRead
- RelationalDatabasesReadOnly
- SecretManagerReadOnly
- Project scope, optional — grant only the products you actually use:
- KubernetesReadOnly (cluster posture; AuditBadger never downloads kubeconfig files)
- LoadBalancersReadOnly (TLS and certificate posture)
- ContainerRegistryReadOnly (namespace visibility; images are never pulled)
- VPCReadOnly and PrivateNetworksReadOnly (network segmentation inventory)
Never grant FullAccess, Manager, Write, or Delete permission sets — AuditBadger detects them and blocks automated
collection until they are removed. AllProductsReadOnly works but grants more read access than needed; AuditBadger will
show a warning.
3. Generate the API key
1. Open IAM → API keys → Generate API key.
2. Select the auditbadger-compliance-reader application as the bearer.
3. Prefer no expiration so evidence collection is not interrupted; rotate the key manually instead. If you do set an
expiration, AuditBadger shows the date and warns before the key expires.
4. Copy the access key and the secret key — Scaleway shows the secret key only once.
4. Connect in AuditBadger
1. Go to Account Settings → Integrations → Scaleway.
2. Fill in: label (e.g. "production"), organization ID, project ID, access key, secret key, and default region.
3. Save. AuditBadger validates the connection in the background, checks each product API, and verifies the read-only
permission posture.
4. Once healthy, install evidence sources on your compliance controls (individually from a control, or in bulk via
"Install evidence sources").
Key rotation
1. Generate a new API key for the same IAM application in Scaleway.
2. On the integration page, open Configuration, paste the new access key and secret key, and save. Evidence sources and
collected evidence are kept.
3. After AuditBadger re-validates, delete the old API key in Scaleway.
Troubleshooting
- "Write-capable permissions detected" - the key's policy grants a write/full-access permission set. Replace the
policy with the read-only sets above; collection stays blocked until fixed.
- "Unrecognized permission set" - Scaleway added a permission set AuditBadger doesn't know yet. Collection is blocked
as a precaution; contact support.
- "Permission verification incomplete" - the key lacks IAMReadOnly, so AuditBadger cannot verify the policy.
Collection still works, but the read-only posture is unverified.
- A product shows "Permission denied" - the project-scope rule is missing that product's read-only permission set, or
the policy is scoped to a different project.
- Audit Trail source shows "setup required" - enable "Collect Audit Trail evidence" in the integration settings and
grant AuditTrailReadOnly.