Handing an agent an operator session gives it everything you have, for as long as you have it, and every action lands in the audit log as you. scripts/bao-session.sh grant <task> mints a separate token into ~/.claude-bao-token — your ~/.vault-token is untouched and the two revoke independently. 45 minutes, max one hour, display_name claude-<task> so an audited action is attributable to a piece of work. policies/ops-mason-build.hcl is what makes the scope real. It allows the phase-2 survey (sys/mounts, sys/auth, policy list), policy and auth-role creation, KV metadata reads, and short-lived test tokens for positive and negative capability checks. It denies every read of */data/* on platform, operators and secret. That denial is the point: SCOPE.md says ops-mason never touches secret values, and until now that was a promise kept by whoever was driving. An explicit deny outranks any grant, including one added to this policy later by mistake. The one time the line was crossed is recorded in plans/state-hub-forge-derivation-read.md §8; under this policy it would have been refused rather than recorded. sys/mounts/* is deliberately absent — enabling a mount is a railiance-platform act, and a grant that needed it should be recognised as a broader thing rather than folded in here. Also fixes the WSL2 login trap: bao login's browser launch fails under gio, so the script prints the URL plainly instead of appearing to hang. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 3377672@bnt-lap001 Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
8.2 KiB
ops-mason — Agent Instructions
Repo Identity
Purpose: Builder of NetKingdom security infrastructure (AppRoles, policies, KV paths) for ops-warden to route to
Domain: infotech
Repo slug: ops-mason
Topic ID: cee7bedf-2b48-46ef-8601-006474f2ad7a
Workplan prefix: MASON-
State Hub Integration
The Custodian State Hub tracks work across all domains. Interact via HTTP REST — there is no MCP server for Codex agents.
| Context | URL |
|---|---|
| Local workstation | http://127.0.0.1:8000 |
| Remote (railiance01, in-cluster) | http://10.43.68.154:8000 |
| Optional local edge relay | http://127.0.0.1:18080 |
When an operator has enabled the edge relay, set API_BASE to the relay URL. Queueable writes return an explicit queued receipt if the central hub is unreachable. Treat that as pending local evidence, then ask the operator to run statehub outbox status/replay after connectivity returns.
Orient at session start
# Offline brief — works without hub connection
cat .custodian-brief.md
# Active workplans for this domain
curl -s "http://127.0.0.1:8000/workplans/?topic_id=cee7bedf-2b48-46ef-8601-006474f2ad7a&status=active" \
| python3 -m json.tool
# Check inbox
curl -s "http://127.0.0.1:8000/messages/?to_agent=ops-mason&unread_only=true" \
| python3 -m json.tool
Mark a message read:
curl -s -X PATCH "http://127.0.0.1:8000/messages/<id>/read" \
-H "Content-Type: application/json" -d '{}'
Log progress (required at session close)
curl -s -X POST http://127.0.0.1:8000/progress/ \
-H "Content-Type: application/json" \
-d '{
"summary": "what was done",
"event_type": "note",
"author": "codex",
"workplan_id": "<uuid>",
"task_id": "<uuid>"
}'
Omit workplan_id / task_id when not applicable.
Update task status
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
-H "Content-Type: application/json" \
-d '{"status": "progress"}'
# values: wait | todo | progress | done | cancel
Flag a task for human review
curl -s -X PATCH "http://127.0.0.1:8000/tasks/<task_id>" \
-H "Content-Type: application/json" \
-d '{"needs_human": true, "intervention_note": "reason"}'
Session Protocol
Start:
cat .custodian-brief.md— domain goal and open workplans (offline-safe)- Check inbox:
GET /messages/?to_agent=ops-mason&unread_only=true; mark read - Scan workplans:
ls workplans/— notestatus: ready,active, orblockedfiles and open tasks - Check human-needed tasks:
GET /tasks/?needs_human=true
During work:
- Update task statuses in workplan files as tasks progress
- Record significant decisions via
POST /decisions/
Close:
- Update workplan file task statuses to reflect progress
- If finishing a workplan: hand off residuals as live work records first
(intake with
origin: residual+origin_ref: <WP-id>, or a next workplan / decision / engagement). Do not park leftovers only in prose orSCOPE.md. Canon:the-custodian/canon/standards/work-record-types_v0.1.md§ Residuals. - Log:
POST /progress/with a summary of what changed (name handoff ids) - After workplan file changes, run:
Coding agents should run this directly; ask the operator only if the CLI or State Hub API is unavailable. This syncs task status from files into the hub DB.statehub fix-consistency
{CREDENTIAL_ROUTING}
Workplan Convention (ADR-001)
Work items originate as files in this repo — not in the hub. The hub is a read/cache/index layer that rebuilds from files.
File location: workplans/MASON-NNNN-<slug>.md
Archived location: finished workplans may move to
workplans/archived/YYMMDD-MASON-NNNN-<slug>.md. The YYMMDD prefix is
the completion/archive date; the frontmatter id does not change.
Ad Hoc Tasks: small opportunistic fixes discovered during a session use
workplans/ADHOC-YYYY-MM-DD.md with task ids ADHOC-YYYY-MM-DD-T01, etc. Use
this only for low-risk work completed directly; create a normal workplan for
anything needing analysis, design, approval, dependencies, or multiple phases.
Frontmatter:
---
id: MASON-NNNN
type: workplan
title: "..."
domain: infotech
repo: ops-mason
status: proposed | ready | active | blocked | backlog | finished | archived
owner: codex
topic_slug: ...
created: "YYYY-MM-DD"
updated: "YYYY-MM-DD"
state_hub_workstream_id: "<uuid>" # fix-consistency — do not edit (legacy field name; workplan UUID)
---
Use proposed for a new draft, ready after review against current repo
state, and finished after implementation. stalled and needs_review are
derived health labels, not frontmatter statuses.
Terminology: workplan is the fleet term; workstream appears only in legacy
API/MCP/frontmatter bridges until STATE-WP-0069 retires them — see
the-custodian/canon/standards/workplan-terminology-fleet_v0.1.md.
Task block format (one per ## section):
## Task Title
` ` `task
id: MASON-NNNN-T01
status: wait | todo | progress | done | cancel
priority: high | medium | low
state_hub_task_id: "<uuid>" # written by fix-consistency — do not edit
` ` `
Task description text.
Status progression: todo → progress → done; use wait for waiting/blocked work and cancel for stopped work.
Residuals when finishing: actionable leftovers become live work records
before status: finished — usually an intake (origin: residual,
origin_ref: MASON-NNNN) or a spawned workplan. Residual is a role,
not a kind. Fleet list lives on State Hub, not in SCOPE.md.
To create a new workplan:
- Write the file following the format above
- Run
statehub fix-consistencylocally; ask the operator only if the CLI or State Hub API is unavailable.
OpenBao Access — how to grant a session, and what it authorises
ops-mason builds in OpenBao, so it needs a session. Do not hand it your own operator session: that gives everything you have, for as long as you have it, and every action lands in the audit log as you.
./scripts/bao-session.sh status # what session exists, if any
./scripts/bao-session.sh login # refresh YOUR operator session (OIDC)
./scripts/bao-session.sh grant <task> # mint a scoped token for Claude
./scripts/bao-session.sh revoke # end it immediately
grant mints a separate token into ~/.claude-bao-token — your own
~/.vault-token is untouched, and the two revoke independently. The agent uses
it as BAO_TOKEN=$(cat ~/.claude-bao-token) bao <cmd>.
What the grant authorises
Policy ops-mason-build (policies/ops-mason-build.hcl), 45 minutes, max one
hour, named claude-<task>:
| Allowed | Denied |
|---|---|
read sys/mounts, sys/auth, policy list — the phase-2 survey |
every read of */data/* on platform, operators, secret |
create/update policies under sys/policies/acl/* |
enabling or tuning mounts (sys/mounts/*) — a railiance-platform act |
create/update auth/kubernetes/role/*, auth/approle/role/* |
anything not listed |
| read KV metadata — versions and timestamps, enough to confirm a delivery landed | KV values |
| mint and revoke short-lived test tokens, check capabilities |
The denial is the point. SCOPE.md says ops-mason never touches secret values;
this makes OpenBao enforce it rather than leaving it to whoever is driving. An
explicit deny outranks any grant, including one added to this policy later by
mistake.
Choosing the task name
grant <task> sets display_name=claude-<task>, so the audit log attributes an
action to a piece of work rather than to a person. Use the workplan task where
there is one — grant MASON-WP-0003-T02 — otherwise something a reader would
recognise later.
When a broader grant is genuinely needed
Enabling a mount, reading a value, or touching another subsystem's paths is out
of ops-mason-build on purpose. Do not widen the policy to get past a refusal.
Either the act belongs to another repo, or it needs its own named policy and its
own decision — the way operators/ did.