glas-harness/workplans/GLAS-WP-0015-production-dependency-coordination.md
tegwick 74a6071e84
All checks were successful
ci / validate (push) Successful in 1m35s
Record enforced caller proof and published approval release
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
2026-09-06 23:37:38 +02:00

7.4 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
GLAS-WP-0015 workplan Drive owner returns for the first production Glas profile infotech glas-harness active codex production-dependency-coordination 2026-09-06 2026-09-06 94c02b1f-66ed-588d-bdd7-7158107b85fb

Production dependency coordination

GLAS-WP-0012 remains the real-profile acceptance workplan. This plan owns only concrete handoffs and receipt tracking from Glas; it does not duplicate owner implementation tasks or authorize credential access. User requested driving the dependencies from this repo after the policy-service production rollout.

Prepare exact owner requests

id: GLAS-WP-0015-T01
status: done
priority: high
state_hub_task_id: "ddc1a421-079c-52ad-bc0e-591010942205"

Reviewed KEY-WP-0013, its existing provisioning packet, AUDIT-WP-0009-T09, APPROVAL-WP-0002, FLEX-WP-0021, SECRETS-WP-0009 and SAND-WP-0015. Prepared seven concrete requests in docs/production-dependency-handoffs.md. Includes live PDP coordinates, custody paths, tenant mismatch, audit startup critical path, independent image/runtime preparation, and proof project binding mismatch.

Deliver and track owner handoffs

id: GLAS-WP-0015-T02
status: done
priority: high
state_hub_task_id: "8903d552-4039-5b80-b589-3743f7751e5f"

Completed 2026-09-06 after explicit user authorization. Sent one deduplicated root message to each of the seven owners; State Hub returned 201 and actual message IDs, recorded in docs/production-handoff-receipts.json. Replies must use the root message ID as thread_id. The first attempt with a newly invented thread UUID was rejected before delivery; it was corrected, not counted as sent. A delivered message is not owner acceptance or implementation evidence.

Review owner returns against the acceptance gates

id: GLAS-WP-0015-T03
status: progress
priority: high
state_hub_task_id: "68fcc1b4-537b-5f5e-afb5-063c44e5e4db"

Track tenant agreement, client custody/identity, audit onboarding, approval release, native activation and runtime binding against the linked owner tasks. Check revisions and positive/negative evidence; feed verified returns into GLAS-WP-0012-T02. Keep unfulfilled owner work live, and do not close this plan while actionable requests lack an owning record or acknowledged disposition.

Delivery receipts

Owner Root message / reply thread
key-cape 356f6977-d361-4e3b-83ab-b2c7f4759286
railiance-platform 1b88b600-7b5d-4e3f-9999-8b8fec54b1ef
audit-core 85c68e66-46e3-4d30-a72f-4e104e2bbe5c
approval-engine 1e45cc7f-f1f5-40a8-b3f9-f1f8d78ece5c
secrets-engine 7ab6d325-11a2-4f94-9736-b17335054e3c
flex-auth 16172bc0-2935-40fe-8b5b-847132ecb689
sand-boxer 481b18b6-54ae-44bc-bb31-ffd130d6d8ad

Owner acknowledgements and verified progress

  • secrets-engine: ac6674c7-f737-4437-8287-f39962ed7031 (reviewed and marked read).
  • flex-auth: b3228e3d-d002-4782-95f1-366a6b11475d (reviewed and marked read).
  • approval-engine: d96200ef-5dd4-4cec-9bf7-abb29e2af780 (reviewed and marked read).
  • audit-core: 995a2799-d7a7-477a-b38d-fcef61392067 (reviewed and marked read).
  • sand-boxer: 202429d3-8937-433b-9fac-4ea418f04e58 (reviewed and marked read).
  • key-cape: 9957e19d-e095-4e9d-9db8-ab0c468ceadd (reviewed and marked read).

Six owners acknowledged; platform custody reply remains outstanding. Verified sand-boxer 23d0c2b source profile and exact project binding. No production readiness follows from the unpinned Claude executable.

Flex-auth v1 failed to enforce tenant. Deployed the owner v2 correction from CI main-d98323b at digest sha256:db1c4f7e621c7ea119489a321d7db0e05da09afc17be5f69d873b2b3c7f60cfc, Helm revision 2. Six live fixtures pass including wrong_tenant denial; other consumer Deployment specs unchanged. Receipt file: docs/evidence/GLAS-WP-0015-policy-v2-2026-09-06.json. Do not roll back to the known over-permissive v1; if v2 cannot operate, stop this consumer release.

Operator tenant choice was pending at rollout and is resolved below. Follow-ups request live tracking of the workstation caller path, independent Claude packaging, audit T03 then T09, and correct v2 adoption. T03 remains progress until owner prerequisites are verified; no real credential or model run has occurred.

Accepted tenant choice — 2026-09-06

Operator approved exact tenant:platform, the platform management, administration and services tenant (landlord zone). Recorded in docs/platform-tenant-decision.md and State Hub; delivery receipts in docs/platform-tenant-decision-receipts.json. The two proposed service clients, approval store and lifecycle request must agree exactly. No alias or implicit cross-tenant authorization. Existing owner threads receive the approved change; T03 remains progress pending implementation evidence and other dependencies.

Later owner review and production progress — 2026-09-06

Reviewed and marked read the five replies below; cross-checked the owner source revisions. Tenant source alignment accepted at KeyCape 7a6666d and approval 6d18f62; no live tenant-registration claim. Audit evidence-kind prerequisite complete at 15e5436; exact sender scope/redaction confirmation requested.

  • approval-engine: cfff917f-d6e1-4f5e-a396-e0e43ebb97e6
  • secrets-engine: b9c4641b-3227-47a2-84de-a696a219fd8e
  • flex-auth: e272f234-7ba2-458b-a6df-9c2664e4ad76
  • audit-core: 4ae48d3d-a6fd-4f26-aaa7-c5f55a93ab75
  • key-cape: 893e17a1-ac96-465c-ad22-af88204275cd

Published approval-engine d7a9fe5 candidate 0.1.0 and verified the registry index digest 73333f5ceb55e48192e3095cb2e2a741cdc6ff0be2f18128301072b4a6b6eb9d. Both owner deployment image references pinned; client dry-run passes. Production service remains undeployed until KeyCape and audit credential admission.

FLEX-WP-0023 now owns the workstation path. Created the exact bound caller SA without role bindings and with automount disabled. Ten-minute audience-scoped TokenRequest identity passed warn adoption with zero warnings. Helm revision 3 now enforces caller authentication; positive request passes, missing token and wrong audience return 401, wrong principal returns 403. Real expiry proof passed (expired 401, then fresh 200); see docs/evidence/GLAS-WP-0015-caller-auth-2026-09-06.json for outcomes. Other three consumer Deployment specs unchanged. Caller provenance/signatures remain live owner work (FLEX-WP-0023-T04 / FLEX-WP-0024).

Five follow-ups delivered, receipts in docs/production-owner-review-followups-2026-09-06.json. GLAS-WP-0012 remains blocked on credential custody/adoption, approval deployment and Claude runtime pin/startup. No Anthropic key read or real model run. Profiles remain two blocked and one unverified; no readiness promotion.

Also reviewed and marked read approval scan follow-up 89e21fcb-fbf8-43c0-9138-5da7f4dc0d67; its publication blocker was resolved in this session. The published pin is committed in approval-engine b51d174. Independently ran approval-engine tests/test_auth.py: 23 passed. Glas fetched origin with no ahead/behind drift before edits; the readiness catalog validated.

Final caller proof completed: FLEX-WP-0023-T01/T02/T03 done, including actual issued-token expiry and fresh-token recovery. Temporary forward removed and proof process exited. Final owner receipt deliveries recorded in docs/production-caller-access-receipts-2026-09-06.json. This establishes the operator path; consumer adoption and native action authorization remain open.