Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
61 lines
3.7 KiB
Markdown
61 lines
3.7 KiB
Markdown
# OpenRouter native access contract — 2026-09-14
|
|
|
|
FLEX-WP-0026 answers intelligence-radar message
|
|
`a4a4f455-bacd-4172-a45c-2c375a58db12` and ops-warden question
|
|
`a90672e4-4f5f-4ab8-ac43-455f4da351a7` (WARDEN-WP-0039-T03).
|
|
|
|
The existing caller binding admits representation of a protected system. It
|
|
contains no delegated credential-read contract for ops-warden to represent
|
|
railiance-platform. The resolution for this use case is the native
|
|
secrets-engine lifecycle path. Do not widen ops-warden's binding, rename the
|
|
credential owner, or treat its planner's `autonomous` verdict as runtime admission.
|
|
|
|
The native CheckRequest addresses `catalog:openrouter-llm-connect`, type
|
|
`secret-catalog-lane`, system `secrets-engine`, tenant `tenant:platform`, subject
|
|
`secrets-engine` / `service`. This is the lifecycle resource actually enforced by
|
|
secrets-engine, not a relabelled railiance-platform credential read. OpenBao
|
|
custody remains railiance-platform's; llm-connect remains the existing workload
|
|
owner. Radar is a proposed delivery recipient, not a PDP caller or lifecycle subject.
|
|
|
|
`context.catalog_target` carries the actual non-secret mount/path, owner repo,
|
|
fields, consumers, delivery/auth specification and workload delivery. Exec also
|
|
carries the existing exact recipient digest. The evaluator binds this submitted
|
|
context through FLEX-DEC-2026-012; it does not independently admit an arbitrary
|
|
KV path. The consumer must join the issuer's exact-action approval to
|
|
`approval_binding_digest` and CAS-consume before OpenBao. A changed path or owner
|
|
can produce a new policy allow, but cannot reuse the old approval. Claim validity
|
|
and declared human control remain the issuer/consumer responsibilities.
|
|
|
|
## Dedicated pin correction
|
|
|
|
Helm release `flex-auth-secrets-engine`, revision 4, now uses the existing
|
|
CI-published source `dd8dd517438b876fdadf27770e3f7e7f55ea69cf` image
|
|
`sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd`.
|
|
The old September 6 image lacked the consumer's current replay contract.
|
|
Policy stays `secrets-engine.catalog-lane.lifecycle` / `v2`; caller enforcement
|
|
and the existing ServiceAccount binding remain in force. The policy rules did
|
|
not change. Loopback forwarding to the named pod authenticates the responder
|
|
through the Kubernetes API; plain workstation Service DNS remains unsupported.
|
|
|
|
Validation: full Go race suite, image policy validation (28 tests / 32 fixtures),
|
|
Helm lint and server dry-run, then 11 live checks. Correct native caller succeeds;
|
|
missing/wrong callers, foreign system, wrong tenant and recipient-as-subject
|
|
refuse. Submitted context and approval digest pairing survive the real evaluator;
|
|
changed path/mount/owner produces a different approval binding. All other PDP
|
|
Deployment specs were compared before/after and are identical. Ten-minute
|
|
caller tokens stayed in memory; the temporary named-pod forward was stopped.
|
|
|
|
Receipt: `docs/evidence/2026-09-14-openrouter-live-pdp.json`. It is evaluation-only
|
|
with a synthetic claim, not real approval or OpenBao evidence. If this pin cannot
|
|
serve the current contract, stop native execution; rolling back to the prior
|
|
image restores the replay incompatibility and cannot unblock credential delivery.
|
|
|
|
## Live handoff
|
|
|
|
SECRETS-WP-0010-T03 holds the unresolved native admission and delivery work,
|
|
linked to SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06. Approval Engine
|
|
has no StatefulSet, pod or Service in its declared namespace at inspection.
|
|
Its production identity/audit and client-reader gates must be completed before
|
|
native apply. No credential read, AppRole/policy write, ESO change or model spend
|
|
was performed here. WARDEN-WP-0039-T03 and IR-WP-0004-T02 remain waiting on the
|
|
native verification; publishing this contract does not retire the proxy.
|