flex-auth/docs/openrouter-native-access.md
tegwick 41f359f2dc
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Build and Publish Container Image / build-and-push (push) Successful in 1m8s
Resolve OpenRouter native contract and promote secrets-engine PDP
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:54:56 +02:00

3.7 KiB

OpenRouter native access contract — 2026-09-14

FLEX-WP-0026 answers intelligence-radar message a4a4f455-bacd-4172-a45c-2c375a58db12 and ops-warden question a90672e4-4f5f-4ab8-ac43-455f4da351a7 (WARDEN-WP-0039-T03).

The existing caller binding admits representation of a protected system. It contains no delegated credential-read contract for ops-warden to represent railiance-platform. The resolution for this use case is the native secrets-engine lifecycle path. Do not widen ops-warden's binding, rename the credential owner, or treat its planner's autonomous verdict as runtime admission.

The native CheckRequest addresses catalog:openrouter-llm-connect, type secret-catalog-lane, system secrets-engine, tenant tenant:platform, subject secrets-engine / service. This is the lifecycle resource actually enforced by secrets-engine, not a relabelled railiance-platform credential read. OpenBao custody remains railiance-platform's; llm-connect remains the existing workload owner. Radar is a proposed delivery recipient, not a PDP caller or lifecycle subject.

context.catalog_target carries the actual non-secret mount/path, owner repo, fields, consumers, delivery/auth specification and workload delivery. Exec also carries the existing exact recipient digest. The evaluator binds this submitted context through FLEX-DEC-2026-012; it does not independently admit an arbitrary KV path. The consumer must join the issuer's exact-action approval to approval_binding_digest and CAS-consume before OpenBao. A changed path or owner can produce a new policy allow, but cannot reuse the old approval. Claim validity and declared human control remain the issuer/consumer responsibilities.

Dedicated pin correction

Helm release flex-auth-secrets-engine, revision 4, now uses the existing CI-published source dd8dd517438b876fdadf27770e3f7e7f55ea69cf image sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd. The old September 6 image lacked the consumer's current replay contract. Policy stays secrets-engine.catalog-lane.lifecycle / v2; caller enforcement and the existing ServiceAccount binding remain in force. The policy rules did not change. Loopback forwarding to the named pod authenticates the responder through the Kubernetes API; plain workstation Service DNS remains unsupported.

Validation: full Go race suite, image policy validation (28 tests / 32 fixtures), Helm lint and server dry-run, then 11 live checks. Correct native caller succeeds; missing/wrong callers, foreign system, wrong tenant and recipient-as-subject refuse. Submitted context and approval digest pairing survive the real evaluator; changed path/mount/owner produces a different approval binding. All other PDP Deployment specs were compared before/after and are identical. Ten-minute caller tokens stayed in memory; the temporary named-pod forward was stopped.

Receipt: docs/evidence/2026-09-14-openrouter-live-pdp.json. It is evaluation-only with a synthetic claim, not real approval or OpenBao evidence. If this pin cannot serve the current contract, stop native execution; rolling back to the prior image restores the replay incompatibility and cannot unblock credential delivery.

Live handoff

SECRETS-WP-0010-T03 holds the unresolved native admission and delivery work, linked to SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06. Approval Engine has no StatefulSet, pod or Service in its declared namespace at inspection. Its production identity/audit and client-reader gates must be completed before native apply. No credential read, AppRole/policy write, ESO change or model spend was performed here. WARDEN-WP-0039-T03 and IR-WP-0004-T02 remain waiting on the native verification; publishing this contract does not retire the proxy.