Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
3.7 KiB
OpenRouter native access contract — 2026-09-14
FLEX-WP-0026 answers intelligence-radar message
a4a4f455-bacd-4172-a45c-2c375a58db12 and ops-warden question
a90672e4-4f5f-4ab8-ac43-455f4da351a7 (WARDEN-WP-0039-T03).
The existing caller binding admits representation of a protected system. It
contains no delegated credential-read contract for ops-warden to represent
railiance-platform. The resolution for this use case is the native
secrets-engine lifecycle path. Do not widen ops-warden's binding, rename the
credential owner, or treat its planner's autonomous verdict as runtime admission.
The native CheckRequest addresses catalog:openrouter-llm-connect, type
secret-catalog-lane, system secrets-engine, tenant tenant:platform, subject
secrets-engine / service. This is the lifecycle resource actually enforced by
secrets-engine, not a relabelled railiance-platform credential read. OpenBao
custody remains railiance-platform's; llm-connect remains the existing workload
owner. Radar is a proposed delivery recipient, not a PDP caller or lifecycle subject.
context.catalog_target carries the actual non-secret mount/path, owner repo,
fields, consumers, delivery/auth specification and workload delivery. Exec also
carries the existing exact recipient digest. The evaluator binds this submitted
context through FLEX-DEC-2026-012; it does not independently admit an arbitrary
KV path. The consumer must join the issuer's exact-action approval to
approval_binding_digest and CAS-consume before OpenBao. A changed path or owner
can produce a new policy allow, but cannot reuse the old approval. Claim validity
and declared human control remain the issuer/consumer responsibilities.
Dedicated pin correction
Helm release flex-auth-secrets-engine, revision 4, now uses the existing
CI-published source dd8dd517438b876fdadf27770e3f7e7f55ea69cf image
sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd.
The old September 6 image lacked the consumer's current replay contract.
Policy stays secrets-engine.catalog-lane.lifecycle / v2; caller enforcement
and the existing ServiceAccount binding remain in force. The policy rules did
not change. Loopback forwarding to the named pod authenticates the responder
through the Kubernetes API; plain workstation Service DNS remains unsupported.
Validation: full Go race suite, image policy validation (28 tests / 32 fixtures), Helm lint and server dry-run, then 11 live checks. Correct native caller succeeds; missing/wrong callers, foreign system, wrong tenant and recipient-as-subject refuse. Submitted context and approval digest pairing survive the real evaluator; changed path/mount/owner produces a different approval binding. All other PDP Deployment specs were compared before/after and are identical. Ten-minute caller tokens stayed in memory; the temporary named-pod forward was stopped.
Receipt: docs/evidence/2026-09-14-openrouter-live-pdp.json. It is evaluation-only
with a synthetic claim, not real approval or OpenBao evidence. If this pin cannot
serve the current contract, stop native execution; rolling back to the prior
image restores the replay incompatibility and cannot unblock credential delivery.
Live handoff
SECRETS-WP-0010-T03 holds the unresolved native admission and delivery work, linked to SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06. Approval Engine has no StatefulSet, pod or Service in its declared namespace at inspection. Its production identity/audit and client-reader gates must be completed before native apply. No credential read, AppRole/policy write, ESO change or model spend was performed here. WARDEN-WP-0039-T03 and IR-WP-0004-T02 remain waiting on the native verification; publishing this contract does not retire the proxy.