2026-09-06 19:57:15 +02:00
---
id: GLAS-WP-0015
type: workplan
title: "Drive owner returns for the first production Glas profile"
domain: infotech
repo: glas-harness
status: active
2026-09-14 15:50:42 +02:00
flavor: implementation
2026-09-06 19:57:15 +02:00
owner: codex
topic_slug: production-dependency-coordination
created: "2026-09-06"
2026-09-09 12:36:15 +02:00
updated: "2026-09-09"
2026-09-06 19:57:16 +02:00
state_hub_workstream_id: "94c02b1f-66ed-588d-bdd7-7158107b85fb"
2026-09-06 19:57:15 +02:00
---
# Production dependency coordination
GLAS-WP-0012 remains the real-profile acceptance workplan. This plan owns only
concrete handoffs and receipt tracking from Glas; it does not duplicate owner
implementation tasks or authorize credential access. User requested driving
the dependencies from this repo after the policy-service production rollout.
## Prepare exact owner requests
```task
id: GLAS-WP-0015-T01
status: done
priority: high
2026-09-06 19:57:16 +02:00
state_hub_task_id: "ddc1a421-079c-52ad-bc0e-591010942205"
2026-09-06 19:57:15 +02:00
```
Reviewed KEY-WP-0013, its existing provisioning packet, AUDIT-WP-0009-T09,
APPROVAL-WP-0002, FLEX-WP-0021, SECRETS-WP-0009 and SAND-WP-0015. Prepared
seven concrete requests in docs/production-dependency-handoffs.md. Includes
live PDP coordinates, custody paths, tenant mismatch, audit startup critical
path, independent image/runtime preparation, and proof project binding mismatch.
## Deliver and track owner handoffs
```task
id: GLAS-WP-0015-T02
2026-09-06 20:23:56 +02:00
status: done
2026-09-06 19:57:15 +02:00
priority: high
2026-09-06 19:57:16 +02:00
state_hub_task_id: "8903d552-4039-5b80-b589-3743f7751e5f"
2026-09-06 19:57:15 +02:00
```
2026-09-06 20:23:56 +02:00
Completed 2026-09-06 after explicit user authorization. Sent one deduplicated
root message to each of the seven owners; State Hub returned 201 and actual
message IDs, recorded in docs/production-handoff-receipts.json. Replies must
use the root message ID as thread_id. The first attempt with a newly invented
thread UUID was rejected before delivery; it was corrected, not counted as sent.
A delivered message is not owner acceptance or implementation evidence.
2026-09-06 19:57:15 +02:00
## Review owner returns against the acceptance gates
```task
id: GLAS-WP-0015-T03
2026-09-06 21:39:10 +02:00
status: progress
2026-09-06 19:57:15 +02:00
priority: high
2026-09-06 19:57:16 +02:00
state_hub_task_id: "68fcc1b4-537b-5f5e-afb5-063c44e5e4db"
2026-09-06 19:57:15 +02:00
```
Track tenant agreement, client custody/identity, audit onboarding, approval
release, native activation and runtime binding against the linked owner tasks.
Check revisions and positive/negative evidence; feed verified returns into
GLAS-WP-0012-T02. Keep unfulfilled owner work live, and do not close this plan
while actionable requests lack an owning record or acknowledged disposition.
2026-09-06 20:23:56 +02:00
2026-09-09 12:36:15 +02:00
2026-09-09 implementation return: the worker now captures a bounded Git bundle
through sandbox owner execution after rein cleanup, then validates and imports
the exact one-commit result under its original baseline, grant and lease after
successful teardown. The actual bwrap/Glas/worker test passed with a deterministic
authoring fixture and response-lost close replay, without duplicate execution.
Native profile USD/turn limits now reach Claude CLI controls and require valid
terminal accounting; missing/exhausted accounting refuses success. Daily/total
reservation, EUR treatment and live provider semantics remain HFACT-WP-0001-T01.
The matching rein/Glas code must be rebuilt and admitted in the protected runtime;
this local proof does not close live G1/G2 or authorize a model request. See the
2026-09-09 runtime-transfer evidence and the owning runtime documentation.
2026-09-06 20:23:56 +02:00
## Delivery receipts
| Owner | Root message / reply thread |
|---|---|
| key-cape | `356f6977-d361-4e3b-83ab-b2c7f4759286` |
| railiance-platform | `1b88b600-7b5d-4e3f-9999-8b8fec54b1ef` |
| audit-core | `85c68e66-46e3-4d30-a72f-4e104e2bbe5c` |
| approval-engine | `1e45cc7f-f1f5-40a8-b3f9-f1f8d78ece5c` |
| secrets-engine | `7ab6d325-11a2-4f94-9736-b17335054e3c` |
| flex-auth | `16172bc0-2935-40fe-8b5b-847132ecb689` |
| sand-boxer | `481b18b6-54ae-44bc-bb31-ffd130d6d8ad` |
2026-09-06 21:39:10 +02:00
## Owner acknowledgements and verified progress
- secrets-engine: `ac6674c7-f737-4437-8287-f39962ed7031` (reviewed and marked read).
- flex-auth: `b3228e3d-d002-4782-95f1-366a6b11475d` (reviewed and marked read).
- approval-engine: `d96200ef-5dd4-4cec-9bf7-abb29e2af780` (reviewed and marked read).
- audit-core: `995a2799-d7a7-477a-b38d-fcef61392067` (reviewed and marked read).
- sand-boxer: `202429d3-8937-433b-9fac-4ea418f04e58` (reviewed and marked read).
- key-cape: `9957e19d-e095-4e9d-9db8-ab0c468ceadd` (reviewed and marked read).
Six owners acknowledged; platform custody reply remains outstanding.
Verified sand-boxer 23d0c2b source profile and exact project binding. No
production readiness follows from the unpinned Claude executable.
Flex-auth v1 failed to enforce tenant. Deployed the owner v2 correction from
CI main-d98323b at digest
sha256:db1c4f7e621c7ea119489a321d7db0e05da09afc17be5f69d873b2b3c7f60cfc,
Helm revision 2. Six live fixtures pass including wrong_tenant denial; other
consumer Deployment specs unchanged. Receipt file:
docs/evidence/GLAS-WP-0015-policy-v2-2026-09-06.json. Do not roll back to the
known over-permissive v1; if v2 cannot operate, stop this consumer release.
2026-09-06 21:48:12 +02:00
Operator tenant choice was pending at rollout and is resolved below. Follow-ups request live tracking of the
2026-09-06 21:39:10 +02:00
workstation caller path, independent Claude packaging, audit T03 then T09,
and correct v2 adoption. T03 remains progress until owner prerequisites are
verified; no real credential or model run has occurred.
2026-09-06 21:48:12 +02:00
## Accepted tenant choice — 2026-09-06
Operator approved exact `tenant:platform` , the platform management,
administration and services tenant (landlord zone). Recorded in
`docs/platform-tenant-decision.md` and State Hub; delivery receipts in
`docs/platform-tenant-decision-receipts.json` . The two proposed service clients,
approval store and lifecycle request must agree exactly. No alias or implicit
cross-tenant authorization. Existing owner threads receive the approved change;
T03 remains progress pending implementation evidence and other dependencies.
2026-09-06 23:37:38 +02:00
## Later owner review and production progress — 2026-09-06
Reviewed and marked read the five replies below; cross-checked the owner source
revisions. Tenant source alignment accepted at KeyCape 7a6666d and approval
6d18f62; no live tenant-registration claim. Audit evidence-kind prerequisite
complete at 15e5436; exact sender scope/redaction confirmation requested.
- approval-engine: `cfff917f-d6e1-4f5e-a396-e0e43ebb97e6`
- secrets-engine: `b9c4641b-3227-47a2-84de-a696a219fd8e`
- flex-auth: `e272f234-7ba2-458b-a6df-9c2664e4ad76`
- audit-core: `4ae48d3d-a6fd-4f26-aaa7-c5f55a93ab75`
- key-cape: `893e17a1-ac96-465c-ad22-af88204275cd`
Published approval-engine d7a9fe5 candidate 0.1.0 and verified the registry
index digest 73333f5ceb55e48192e3095cb2e2a741cdc6ff0be2f18128301072b4a6b6eb9d.
Both owner deployment image references pinned; client dry-run passes. Production
service remains undeployed until KeyCape and audit credential admission.
FLEX-WP-0023 now owns the workstation path. Created the exact bound caller SA
without role bindings and with automount disabled. Ten-minute audience-scoped
TokenRequest identity passed warn adoption with zero warnings. Helm revision 3
now enforces caller authentication; positive request passes, missing token and
wrong audience return 401, wrong principal returns 403. Real expiry proof passed (expired 401, then fresh 200); see docs/evidence/GLAS-WP-0015-caller-auth-2026-09-06.json for outcomes.
Other three consumer Deployment specs unchanged. Caller provenance/signatures
remain live owner work (FLEX-WP-0023-T04 / FLEX-WP-0024).
Five follow-ups delivered, receipts in
`docs/production-owner-review-followups-2026-09-06.json` . GLAS-WP-0012 remains
blocked on credential custody/adoption, approval deployment and Claude runtime
pin/startup. No Anthropic key read or real model run. Profiles remain two blocked
and one unverified; no readiness promotion.
Also reviewed and marked read approval scan follow-up
`89e21fcb-fbf8-43c0-9138-5da7f4dc0d67` ; its publication blocker was resolved in
this session. The published pin is committed in approval-engine `b51d174` .
Independently ran approval-engine tests/test_auth.py: 23 passed. Glas fetched
origin with no ahead/behind drift before edits; the readiness catalog validated.
Final caller proof completed: FLEX-WP-0023-T01/T02/T03 done, including actual
issued-token expiry and fresh-token recovery. Temporary forward removed and
proof process exited. Final owner receipt deliveries recorded in
`docs/production-caller-access-receipts-2026-09-06.json` . This establishes the
operator path; consumer adoption and native action authorization remain open.
2026-09-06 23:52:48 +02:00
## Pinned Claude startup progress — 2026-09-06
Advanced sand-boxer SAND-WP-0015-T05 independently of custody: runtime builder
now copies only an explicitly digest-pinned native Claude executable. Selected
installed Claude 2.1.263, binary digest
26d020351e8112f4006790f3cfce43b4c9df0c1bb1d0e542364d64151b81d5ba;
complete candidate runtime digest
5cf9a16c5d77a16bdb2cb5b3df06ea655356bc2d44741791e3fedfee20d7e922.
Sandbox f8821ec2 passed actual Claude --version, rein CLI/import, read-only
runtime, private HOME/state persistence, source absence, clean tree and teardown
with owner proxy environment present. Lint and all 175 sand-boxer tests pass.
Evidence: docs/evidence/GLAS-WP-0015-claude-startup-2026-09-06.json.
This resolves candidate binary pin/startup, not protected runtime deployment,
Claude provider-request compatibility, credential delivery or a real model run.
The candidate is in /tmp; no production profile readiness changed. Existing
credential and acceptance tasks remain open. No new owner replies at session start.