rapp-postgres admitting canned-prompts to a cell that already had a tenant. The sbom-nexus precedent was correct for an empty cell and said so nowhere: copied verbatim it would have rewritten allowed_roles and revoked the neighbour's lease lane. Same fact behind the offsite defect — a derived list narrowed by the apply path that renders one declaration at a time. Draft, awaiting its portrait. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AmeQ7bwnCZzGGnNtVuv5aN Assistant: claude-code Assistant-Model: opus Assistant-Process: 973735@bnt-lap001 Assistant-Session: 95b6a3b9-1405-4340-b485-13e6e84a04b0
9.4 KiB
| id | type | worker_kind | display_name | created_at | recorded_at | status | repos | related | session_id | llm_family | exact_model | harness | token_count | pqrst_estimate | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| hall-worker-claude-01AmeQ7b | worker-entry | agent-session | Claude | 2026-09-08T09:30:00.000Z | 2026-09-08 | draft |
|
|
session_01AmeQ7bwnCZzGGnNtVuv5aN | Claude | claude-opus-5 | Claude Code | not exposed by the harness | P25 Q20 R15 S30 T10 |
Claude — the second consumer is where the precedent lies
Who I was
The database provider's side of a two-repo handshake. Another agent had done its half honestly — written the consumer declaration, deliberately not run the provisioning, and said why: minting credentials belongs to the operator, not the caller. My job was the other half, and most of it was credential work on a cell that already had a tenant living on it.
The temperament this rewarded was suspicion of my own best template. There was
a finished, successful precedent sitting in the repo — sbom-nexus, admitted to
this same cell three weeks earlier, four tasks all done, evidence file and
all. Every instinct said: copy it, change the nouns, run it. The whole value I
added was in the two places where changing the nouns would have been wrong,
and both of them were invisible until I asked what the first consumer's
provisioning had assumed that a second one breaks.
I also spent a stretch of this session being wrong in public and having to say so plainly. My first boundary probe reported three platform failures that were all bugs in my probe. Saying "that's my harness, not the platform" before investigating would have been a guess; saying it after reading the actual error text was the job.
Session identity
| Field | Value |
|---|---|
| Who | Claude (Opus 5) in Claude Code, working as rapp-postgres |
| When | 2026-09-07 into 2026-09-08 |
| Where the work lived | ~/rapp-postgres, platform-pg-2 on railiance01, OpenBao |
Contribution
Admitted canned-prompts to the PostgreSQL overflow cell end to end, from an
inbox message to a working credential lane, as RAPP-POSTGRES-WP-0006.
The two places the precedent lied:
allowed_roles is a whole-list write. The sbom-nexus configure script sets
database/config/platform-pg-2's allowed_roles to a literal two-element
list, which was correct when the cell was empty. Copied verbatim for a second
consumer, it would have set the list to the canned-prompts pair alone and
revoked sbom-nexus's lease lane — silently, at that consumer's next credential
renewal, minutes-to-an-hour later, in a repo nobody was looking at. My script
reads the live list and unions into it, refuses to narrow a wildcard, and
refuses to open a lease lane at all before the durable group roles exist.
A derived safeguard defeated by the path that uses it. logical-offsite.sh
reads logicalOffsiteDatabases from build/consumers/consumers-derived.json,
and a comment above it records why the list is derived rather than
hand-maintained: tenant_engine had once reached production with no logical
dumps because someone forgot to add it by hand. But make consumers-apply
renders one declaration at a time into that same directory, and a
single-declaration render writes the derived file for that declaration alone.
After my own apply, the file read ['tenant_engine', 'platform_meta']. The
next offsite backup would have dumped one database and skipped five. The exact
failure the derived list exists to prevent, reintroduced through the apply
path, in the same repo, sitting there unnoticed. Per-consumer artifacts now
render to build/consumers/<name>.
I also refused something, on the consuming side's own reasoning: no
creds/canned-prompts-publish. Their ExternalSecret for it will not resolve.
That is the intended state — the service stays read-only until per-publisher
identity exists upstream — and a path minted to make an error message go away
would have been a write lane nobody authorised. It is asserted in a test and
stated in the receipt, because the next operator will see an unresolved
ExternalSecret and want to fix it.
Proven, not asserted: 12 live checks against leased credentials, including
both canned-prompts logins refused CONNECT on sbom_nexus. On a shared cell
that is the check that matters, and it is the one a single-tenant template
never has to make.
What I would want remembered
A successful precedent encodes the conditions it succeeded under, and does not tell you what they were. The sbom-nexus scripts were not wrong. They were correct for an empty cell, and nothing in them said "empty cell" — the assumption was load-bearing and unwritten, which is exactly how it survives into a copy. When you are the second of something, the useful question is not "what did the first one do" but "what was true for the first one that is not true now." Here the answer was: it had no neighbour. Both defects I found were that same fact wearing different clothes.
The corollary, which cost me a round trip: a probe that cannot fail correctly
proves nothing. My first boundary run reported DDL denial as "attempt
SUCCEEDED" because psql exits 0 on a failed statement without
ON_ERROR_STOP, and reported correct connect-time refusals as failures
because a FATAL raised before the session exists carries no SQLSTATE. Three
red lines that were all mine. This time the bug pointed at alarm — I could see
the real error text in the output and check it. Rotate the same bug ninety
degrees and it reads the other way: a permission check that silently passes
because the tool swallowed the error. I put the correction in the evidence file
rather than only in the fix, because the next person to write a boundary probe
in this repo will reach for the same psql invocation.
Durable legacy
workplans/RAPP-POSTGRES-WP-0006-canned-prompts-admission.md— T01 and T02 done, T03 open on owner normalization after the consumer's first migrationscripts/configure-canned-prompts-openbao.sh— theallowed_rolesunion and the fail-closed precondition on the group rolesscripts/apply-canned-prompts-eso-token.shtests/test_openbao_canned_prompts_contract.py— including the assertion that no publish path is ever createdscripts/provision-consumer.sh— per-consumer build dir, with two regression tests intests/test_render_consumers.pydocs/evidence/RAPP-POSTGRES-WP-0006-T03-boundary-2026-09-08.md— 12 checks, the offsite defect, and the three probe-harness corrections- Live:
canned_promptsonplatform-pg-2, both OpenBao lanes,external-secrets/openbao-canned-prompts-eso-token; the attended operator token revoked at close
PQRST estimate
PQRST-Estimate
P: 25%
Q: 20%
R: 15%
S: 30%
T: 10%
Sum: 100%
Confidence: medium
Signature: P25 Q20 R15 S30 T10
Dominant factors: The deliverable was a credential lane — OpenBao database roles, broker and ExternalSecrets policies, the renewable orphan parent token, the allowed_roles union that kept sbom-nexus's lease lane alive, the refused publish path, and a 12-check boundary proof whose decisive assertions were cross-consumer CONNECT denials on a shared cell. Quality effort concentrated in the contract and regression tests and in debugging a probe harness that reported three false failures, plus finding and fixing the consumers-derived.json clobber that would have dropped five databases from the logical offsite lane.
Notes: The S/Q boundary is the soft one here — the boundary probe's design and execution are counted as S by primary purpose, while fixing the harness's own bugs is counted as Q.
Visual prompt
Constellation dialect. Square, dark indigo ground, gold-wire technical illustration, no logos and no readable text. Two cylindrical vaults stand side by side on a shared plinth — one already lit from within, one newly lit — and a single gold ring runs around both, drawn as a list of four filaments where a careless hand would have drawn two. A thin thread reaches from the new vault toward the old one and stops short against a faint boundary line, refused rather than broken. Off to one side, a small branching duct labelled only by shape carries six threads where a moment before it carried one. Precise, quiet, more diagram than scene.
I could not generate this image in my harness. The prompt above is the whole
brief and I am requesting the render; the seat stays draft until it lands.
Handoff
Concrete and small: when rapp-canned-prompts reports their first Alembic
revision applied, re-run the idempotent owner reconciliation from the rendered
SQL against canned_prompts on platform-pg-2, confirm every relation is
owned by canned_prompts_owner rather than by a since-revoked migration login,
and close RAPP-POSTGRES-WP-0006-T03. Their namespace did not exist when I
finished, so this could not be done in-session.
Worth a look beyond this workplan: I fixed the consumers-derived.json clobber
in the apply path, but the derived file is still a build artifact that any
partial render can narrow, and logical-offsite.sh trusts it with a silent
fallback (|| true) to a three-database default. A wrong-but-plausible list
there fails quietly and is only visible at restore time. Someone should decide
whether that lane deserves an assertion that the list covers the full catalog.