Scaleway Brezel real-infrastructure evidence
Qualification boundary
This evidence records the bounded InferCrane private-computer production workflow completed on 2026-09-21. It qualifies only the named Scaleway host, public edge, dedicated Brezel project, immutable CPU environments, connector, and InferCrane integration below. It is not a general Brezel, Scaleway, multi-host, GPU, or hostile-multitenancy qualification.
The scoped service token is stored only on the host in a
0600 file. Its
value was not read, copied into the repository, sent to the browser, or
included in this evidence.
Directly observed public boundary
On 2026-09-21, a fresh request tohttps://sandbox.infercrane.com/readyz returned HTTP 200 with
{"status":"ready"} over HTTP/2 through Caddy. The response included HSTS,
Cache-Control: no-store, a deny-all content security policy,
X-Content-Type-Options: nosniff, and frame denial.
An unauthenticated request to /v1/capabilities returned HTTP 401. This is
the expected production boundary: readiness is public, while capabilities
require the dedicated server-side service credential and are consumed through
InferCrane.
Operator-qualified workflow
The production workflow was run through InferCrane rather than directly from a customer browser to Brezel. It passed:- Create InferCrane metadata and a durable Brezel workspace.
- Create a computer from an approved immutable environment.
- Stream command output and receive the terminal execution event.
- Write and read a file through the InferCrane proxy.
- Create and use a re-brokered HTTP preview.
- Read sanitized execution receipt evidence.
- Pause and resume while retaining workspace data.
- Reach the approved InferCrane model through the immutable connector.
- Record content-free usage events.
- Delete the computer and confirm cleanup.