Record approved metered requester extension and six native creates
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
codex 2026-09-27 21:08:43 +02:00
parent b15ab5774f
commit 2f4485a4b6
5 changed files with 353 additions and 9 deletions

View file

@ -5,7 +5,7 @@ request_type: workload-kv-read
title: T03 create-only requester attended operator reader title: T03 create-only requester attended operator reader
status: applied status: applied
created: '2026-09-14' created: '2026-09-14'
updated: '2026-09-14' updated: '2026-09-27'
requester: requester:
agent: codex agent: codex
reason: User instructed completion of SECRETS-WP-0010-T03 and explicitly confirmed reason: User instructed completion of SECRETS-WP-0010-T03 and explicitly confirmed
@ -26,13 +26,22 @@ review:
approval, consume, provider-key access or model-spending scope. Separate reader approval, consume, provider-key access or model-spending scope. Separate reader
and verifier remain exact to this new path; no old credential or registration and verifier remain exact to this new path; no old credential or registration
is widened. is widened.
- at: '2026-09-27'
reviewer: operator in attended Codex session
decision: approved
comment: Exact six-request extension approved. Packet SHA-256
22e640428e3a7ae8fc2363cf193db98381cd94e4be7ab009bc6703658d6fc544;
scripts/create-metered-approval-requests.sh creates only apply/verify/exec
requests for glas-claude-agent-dev-anthropic and activity-core-metered-worker-token.
No approve, consume, workload credential retrieval or execution authority.
Receipt docs/evidence/2026-09-27-metered-requester-mandate.json.
target: target:
domain: financials domain: financials
tenant: platform tenant: platform
workload: secrets-engine workload: secrets-engine
environment: production environment: production
purpose: T03 create-only requester attended operator reader; execute only the three purpose: Create only the three fixed T03 request records or the six metered
fixed T03 request records. records frozen by the explicitly approved 2026-09-27 packet; no arbitrary requests.
openbao: openbao:
mount: platform mount: platform
kv_path: platform/workloads/secrets-engine/approval-requester kv_path: platform/workloads/secrets-engine/approval-requester

View file

@ -0,0 +1,325 @@
{
"observed_at": "2026-09-27T18:38:15.656671+00:00",
"status": "created",
"phase": "six_unapproved_requests_created",
"requests": [
{
"memo_id": "metered-20260927-provider-apply",
"memo_version": 1,
"action": "apply",
"catalog": "glas-claude-agent-dev-anthropic",
"approval": {
"binding": {
"action": "apply",
"actor": "secrets-engine",
"digest": "sha256:a36b88244c26b1ffcd765cbadc201ff79260c7bcbd71d20d1584c3c0a3b1c3de",
"human_control": true,
"pdp_digest": "sha256:ad563454ecebe247b34e7b7dd3c06dd851d686624a00f782636a688b1f9069b9",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "Owner-admitted glas-harness agt run through the reviewed local profile; no caller-facing key fetch",
"target": {
"attributes": {
"auth_targets": [
"se-prod-glas-claude-agent-dev-anthropic"
],
"fields": [],
"policy_targets": [
"se-prod-glas-claude-agent-dev-anthropic"
],
"stage": "prod"
},
"id": "catalog:glas-claude-agent-dev-anthropic",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-27T18:38:25+00:00",
"entries": [],
"id": "0c05bd0a-f81f-451d-840c-5565628e2edc",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-27T18:38:25+00:00",
"validity": {
"expires_at": "2026-09-28T18:20:00+00:00",
"not_before": "2026-09-27T18:38:24.734893+00:00"
}
}
},
{
"memo_id": "metered-20260927-provider-verify",
"memo_version": 1,
"action": "verify",
"catalog": "glas-claude-agent-dev-anthropic",
"approval": {
"binding": {
"action": "verify",
"actor": "secrets-engine",
"digest": "sha256:98636335ccd36286c02fe018f296fd7d4dfd091ee89d27fe1b629e3db00cf121",
"human_control": true,
"pdp_digest": "sha256:0e45d156c8a2b31789fa6f9431c260ee411d8546c3aeaf50d3ac56d5c4b39139",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "Owner-admitted glas-harness agt run through the reviewed local profile; no caller-facing key fetch",
"target": {
"attributes": {
"auth_targets": [
"se-prod-glas-claude-agent-dev-anthropic"
],
"fields": [
"ANTHROPIC_API_KEY"
],
"policy_targets": [
"se-prod-glas-claude-agent-dev-anthropic"
],
"stage": "prod"
},
"id": "catalog:glas-claude-agent-dev-anthropic",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-27T18:38:26+00:00",
"entries": [],
"id": "47f118a3-a86c-43ad-969d-42e09a0f45bb",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-27T18:38:26+00:00",
"validity": {
"expires_at": "2026-09-28T18:20:00+00:00",
"not_before": "2026-09-27T18:38:25.790058+00:00"
}
}
},
{
"memo_id": "metered-20260927-provider-exec",
"memo_version": 1,
"action": "exec",
"catalog": "glas-claude-agent-dev-anthropic",
"approval": {
"binding": {
"action": "exec",
"actor": "secrets-engine",
"digest": "sha256:8b31dd5911552b901b1f807a8cd6348d09547f3dbb2a52e3b42ad9fd948a2b01",
"human_control": true,
"pdp_digest": "sha256:62686f744536db70a48e17f416be6c32203c48d7d1bb3dbda85afb3f0e3ea0f3",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "Owner-admitted glas-harness agt run through the reviewed local profile; no caller-facing key fetch",
"target": {
"attributes": {
"auth_targets": [
"se-prod-glas-claude-agent-dev-anthropic"
],
"fields": [
"ANTHROPIC_API_KEY"
],
"policy_targets": [
"se-prod-glas-claude-agent-dev-anthropic"
],
"stage": "prod"
},
"id": "catalog:glas-claude-agent-dev-anthropic",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-27T18:38:28+00:00",
"entries": [],
"id": "7b32443a-a817-400c-a130-01b9ef04c8ee",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-27T18:38:28+00:00",
"validity": {
"expires_at": "2026-09-28T18:20:00+00:00",
"not_before": "2026-09-27T18:38:27.518711+00:00"
}
}
},
{
"memo_id": "metered-20260927-worker-apply",
"memo_version": 1,
"action": "apply",
"catalog": "activity-core-metered-worker-token",
"approval": {
"binding": {
"action": "apply",
"actor": "secrets-engine",
"digest": "sha256:412b79fb537d4444e52e3358820b6ea204fa17173a4420ab6372c52d010ee018",
"human_control": false,
"pdp_digest": "sha256:f8cffb9005b5d267d14ec1a216a785716ad3d611422c94ab52d6d66d3b259d95",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "Claim the admitted hfact-metered ops_run as rein-aharness-metered@railiance01 inside the catalog-bound Glas metered owner",
"target": {
"attributes": {
"auth_targets": [
"se-prod-activity-core-metered-worker-token"
],
"fields": [],
"policy_targets": [
"se-prod-activity-core-metered-worker-token"
],
"stage": "prod"
},
"id": "catalog:activity-core-metered-worker-token",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-27T18:38:29+00:00",
"entries": [],
"id": "2ce76d7f-01c3-4b63-8476-8d1230679769",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-27T18:38:29+00:00",
"validity": {
"expires_at": "2026-09-28T18:20:00+00:00",
"not_before": "2026-09-27T18:38:29.092610+00:00"
}
}
},
{
"memo_id": "metered-20260927-worker-verify",
"memo_version": 1,
"action": "verify",
"catalog": "activity-core-metered-worker-token",
"approval": {
"binding": {
"action": "verify",
"actor": "secrets-engine",
"digest": "sha256:bce6e2091ed076ec0040804d24c822078ac1eda18cd62703801fc9da77898303",
"human_control": false,
"pdp_digest": "sha256:d53ce35084b40ccf92f2e0062185d721ba726323f5b6324ba5884d4fbe2c23c4",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "Claim the admitted hfact-metered ops_run as rein-aharness-metered@railiance01 inside the catalog-bound Glas metered owner",
"target": {
"attributes": {
"auth_targets": [
"se-prod-activity-core-metered-worker-token"
],
"fields": [
"token"
],
"policy_targets": [
"se-prod-activity-core-metered-worker-token"
],
"stage": "prod"
},
"id": "catalog:activity-core-metered-worker-token",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-27T18:38:30+00:00",
"entries": [],
"id": "c2af4bcf-15b4-4305-aac1-acc7e4dcb099",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-27T18:38:30+00:00",
"validity": {
"expires_at": "2026-09-28T18:20:00+00:00",
"not_before": "2026-09-27T18:38:30.369203+00:00"
}
}
},
{
"memo_id": "metered-20260927-worker-exec",
"memo_version": 1,
"action": "exec",
"catalog": "activity-core-metered-worker-token",
"approval": {
"binding": {
"action": "exec",
"actor": "secrets-engine",
"digest": "sha256:ae261c9271a21b626be354646054f493d0951f69aecdbde3cfce3ac0c5667e8f",
"human_control": false,
"pdp_digest": "sha256:93b12e31b0323a21ae310fced3add0b887658e64530f2e4bc65130ebbd6d9a3d",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "Claim the admitted hfact-metered ops_run as rein-aharness-metered@railiance01 inside the catalog-bound Glas metered owner",
"target": {
"attributes": {
"auth_targets": [
"se-prod-activity-core-metered-worker-token"
],
"fields": [
"token"
],
"policy_targets": [
"se-prod-activity-core-metered-worker-token"
],
"stage": "prod"
},
"id": "catalog:activity-core-metered-worker-token",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-27T18:38:31+00:00",
"entries": [],
"id": "dc22666a-d5d7-46bc-9490-ebe9fe09dc38",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-27T18:38:31+00:00",
"validity": {
"expires_at": "2026-09-28T18:20:00+00:00",
"not_before": "2026-09-27T18:38:31.300944+00:00"
}
}
}
],
"credential_values_emitted": false,
"packet_sha256": "22e640428e3a7ae8fc2363cf193db98381cd94e4be7ab009bc6703658d6fc544",
"signature_verified": true,
"excess_scopes_refused": true,
"wrong_secret_refused": true,
"reader_scope_verified": true,
"planned_requests": [
{
"memo_id": "metered-20260927-provider-apply",
"approval_id": "0c05bd0a-f81f-451d-840c-5565628e2edc",
"action": "apply",
"catalog": "glas-claude-agent-dev-anthropic"
},
{
"memo_id": "metered-20260927-provider-verify",
"approval_id": "47f118a3-a86c-43ad-969d-42e09a0f45bb",
"action": "verify",
"catalog": "glas-claude-agent-dev-anthropic"
},
{
"memo_id": "metered-20260927-provider-exec",
"approval_id": "7b32443a-a817-400c-a130-01b9ef04c8ee",
"action": "exec",
"catalog": "glas-claude-agent-dev-anthropic"
},
{
"memo_id": "metered-20260927-worker-apply",
"approval_id": "2ce76d7f-01c3-4b63-8476-8d1230679769",
"action": "apply",
"catalog": "activity-core-metered-worker-token"
},
{
"memo_id": "metered-20260927-worker-verify",
"approval_id": "c2af4bcf-15b4-4305-aac1-acc7e4dcb099",
"action": "verify",
"catalog": "activity-core-metered-worker-token"
},
{
"memo_id": "metered-20260927-worker-exec",
"approval_id": "dc22666a-d5d7-46bc-9490-ebe9fe09dc38",
"action": "exec",
"catalog": "activity-core-metered-worker-token"
}
],
"human_entries_created": false,
"approvals_consumed": false
}

View file

@ -0,0 +1,6 @@
{
"status": "operator-approved",
"packet_sha256": "22e640428e3a7ae8fc2363cf193db98381cd94e4be7ab009bc6703658d6fc544",
"scope": "create-only-six-metered-requests",
"source": "explicit user approval in attended Codex session"
}

View file

@ -1,8 +1,8 @@
# Exact metered requester extension — awaiting operator approval # Exact metered requester extension — operator approved
Existing work: RPF-WP-0035-T06, SECRETS-WP-0009-T03, REINAH-WP-0003-T06. Existing work: RPF-WP-0035-T06, SECRETS-WP-0009-T03, REINAH-WP-0003-T06.
This proposal does not change CCR-2026-0025's admitted scope until the operator The operator explicitly approved this exact packet on 2026-09-27; the mandate
explicitly approves it. No additional task or workplan is created. and six successful native creates are retained in docs/evidence/. No additional task or workplan is created.
Reviewed command: scripts/create-metered-approval-requests.sh, invoking the Reviewed command: scripts/create-metered-approval-requests.sh, invoking the
adjacent Python script with --clock-trust-file and --mandate. The command freezes adjacent Python script with --clock-trust-file and --mandate. The command freezes
@ -20,9 +20,13 @@ credential. It writes non-secret native receipts and refuses to overwrite a
partial receipt or retry an uncertain create. Planned IDs persist before POST. partial receipt or retry an uncertain create. Planned IDs persist before POST.
Four requester tests plus two existing token-time tests pass. Dry-run lists Four requester tests plus two existing token-time tests pass. Dry-run lists
exactly six records. Actual creation still requires explicit operator mandate, exactly six records. Creation completed under the explicit operator mandate,
fresh admitted Railiance Clock interval and attended reader execution. Native a fresh admitted Railiance Clock interval and attended reader execution. Native
review and consume/backend admission remain after creation. The current human review and consume/backend admission remain after creation. The current human
review HTTP adapter admits human-control records only: companion ordinary review HTTP adapter admits human-control records only: companion ordinary
approval needs its own supported approver path; do not relabel it human-control approval needs its own supported approver path; do not relabel it human-control
or use the retired combined operator client to bypass that boundary. or use the retired combined operator client to bypass that boundary.
Six native requests were created with no human entries or consume. The attended
reader closed. Informed Decision exact-ID ordinary human review is implemented
for the three companion IDs; it preserves their native ordinary control type.

View file

@ -1,3 +1,3 @@
#!/bin/sh #!/bin/sh
# Credential-bearing child output remains inside the attended owner boundary. # Credential-bearing child output remains inside the attended owner boundary.
exec /home/worsch/informed-decision/.venv/bin/python -B /home/worsch/railiance-platform/scripts/create-metered-approval-requests.py "$@" >/dev/null 2>&1 exec /home/worsch/secrets-engine/.venv/bin/python -B /home/worsch/railiance-platform/scripts/create-metered-approval-requests.py "$@" >/dev/null 2>&1