railiance-platform/docs/credential-lane-designs/t03-renewed-execution.md

29 lines
1.7 KiB
Markdown
Raw Normal View History

# T03 continuation after Railiance Clock deployment
The 2026-09-16 requests were consumed. The next cycle uses three new approval
IDs and immutable memo version 3. The creation receipt is
`docs/evidence/2026-09-27-t03-approval-requests.json`; execution receipts are
`secrets-engine/docs/evidence/2026-09-27-t03-native-execution.json` and
`docs/evidence/2026-09-27-t03-attended-delivery.json`. The exact
apply/verify/exec action requests and checker pins are unchanged.
Run the requester and execution worker with
`/home/worsch/secrets-engine/.venv/bin/python`; this environment includes Clock,
JSON Schema, JWT, and YAML dependencies. The requester requires
`--clock-trust-file` and validates full token validity against that interval.
The native execution worker requires `SECRETS_ENGINE_CLOCK_TRUST_FILE`.
Refresh the boot-bound admission via the independently verified Clock public key
and SSH owner epoch readback immediately before attended execution. An expired
trust file fails closed; never extend it or use workstation wall-time fallback.
Use `http://127.0.0.1:18200` for the admitted OpenBao relay and the existing
`operator-browser` PATH helper on WSL when no browser launcher is installed.
The outer lane remains secrets-engine-approval-client-login; its reviewed
`t03-attended-delivery.py` invokes the separate contained platform-admin lane.
Both retain their own self-revocation and private runtime cleanup.
Human review: https://decisions.coulomb.social/review?memo_id=SECRETS-WP-0010-T03-apply
(and identifiers ending -verify and -exec). Version 3 is required. The requester
has no approval or consume scope; no human entries are copied from version 2.
No execution may begin before the new approvals pass native claim/PDP checks.