docs: record credential transport proof and native activation dependency
All checks were successful
ci / validate (push) Successful in 1m25s
All checks were successful
ci / validate (push) Successful in 1m25s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
0c3d8e1a88
commit
73cee37ad8
3 changed files with 46 additions and 0 deletions
|
|
@ -104,3 +104,18 @@ The UI handoff is complete. Do not run the empty initializer again. The next
|
|||
implementation is an exact sandbox-owner machine binding and protected key
|
||||
delivery, followed by enforced provider egress and the bounded real proof.
|
||||
CCR-2026-0016 remains in flight until those acceptance gates pass.
|
||||
|
||||
## Owner transport and native adoption
|
||||
|
||||
Sand-boxer now implements consumer-bound exec-env delivery through a configured
|
||||
credential owner provider, with direct private handoff to the namespace broker.
|
||||
Synthetic proof 880f749e passed child delivery, exact-value output redaction,
|
||||
next-exec absence, wrong-project denial and teardown. No real key was read.
|
||||
|
||||
Secrets-engine catalog `glas-claude-agent-dev-anthropic` now proposes native
|
||||
policy/AppRole `se-prod-glas-claude-agent-dev-anthropic` for the exact KV data
|
||||
path, with metadata access excluded. This supersedes the earlier proposed read
|
||||
policy name; neither policy has been applied by this work. Adoption is tracked
|
||||
in SECRETS-WP-0009. The production exec gate refuses before OpenBao while
|
||||
SECRETS-WP-0007-T04 and SECRETS-WP-0008-T02/T06 remain unresolved.
|
||||
No production profile selects the unactivated route.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue