docs: record credential transport proof and native activation dependency
All checks were successful
ci / validate (push) Successful in 1m25s
All checks were successful
ci / validate (push) Successful in 1m25s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
0c3d8e1a88
commit
73cee37ad8
3 changed files with 46 additions and 0 deletions
|
|
@ -211,3 +211,15 @@ and direct-IP denial, isolated namespace and proxy/workspace cleanup passed.
|
|||
See [egress evidence](../docs/evidence/GLAS-WP-0012-egress-2026-09-05.md).
|
||||
T02 remains waiting on machine auth, protected credential delivery, the pinned
|
||||
Claude executable and the combined production acceptance. Profiles remain blocked.
|
||||
|
||||
## 2026-09-05 credential owner return
|
||||
|
||||
Sand-boxer credential transport is implemented and proved with synthetic
|
||||
provider sandbox 880f749e. Owner config binds exact profile/project/actor and
|
||||
run id; unknown routes refuse, shell API-key fallback is stripped, only the
|
||||
workload child receives the value, and output redaction precedes truncation.
|
||||
Tests: sand-boxer171, secrets-engine226, Glas101 pass. Native data-only read
|
||||
policy/AppRole proposal and activation now live in SECRETS-WP-0009. Its
|
||||
production exec refuses before OpenBao because durable access-engine decision
|
||||
records and scoped service authority remain unavailable. T02 remains waiting
|
||||
on that activation, pinned Claude startup and real provider/task acceptance.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue