Renew T03 requests using Railiance time and bind native execution
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
codex 2026-09-16 01:08:56 +02:00
parent 3bd3a2e87b
commit 5b3041cfb5
7 changed files with 219 additions and 14 deletions

View file

@ -0,0 +1,25 @@
# T03 continuation after Railiance Clock deployment
The original requests expired unconsumed. Replacement request IDs and immutable
memo version 2 are recorded in the creation receipt and Secrets Engine workplan.
The exact apply/verify/exec action requests and checker pins are unchanged.
Run the requester and execution worker with
`/home/worsch/secrets-engine/.venv/bin/python`; this environment includes Clock,
JSON Schema, JWT, and YAML dependencies. The requester requires
`--clock-trust-file` and validates full token validity against that interval.
The native execution worker requires `SECRETS_ENGINE_CLOCK_TRUST_FILE`.
Refresh the boot-bound admission via the independently verified Clock public key
and SSH owner epoch readback immediately before attended execution. An expired
trust file fails closed; never extend it or use workstation wall-time fallback.
Use `http://127.0.0.1:18200` for the admitted OpenBao relay and the existing
`operator-browser` PATH helper on WSL when no browser launcher is installed.
The outer lane remains secrets-engine-approval-client-login; its reviewed
`t03-attended-delivery.py` invokes the separate contained platform-admin lane.
Both retain their own self-revocation and private runtime cleanup.
Human review: https://decisions.coulomb.social/review?memo_id=SECRETS-WP-0010-T03-apply
(and identifiers ending -verify and -exec). Version 2 is required. The requester
has no approval or consume scope; no human entries are copied from version 1.
No execution may begin before the new approvals pass native claim/PDP checks.

View file

@ -0,0 +1,147 @@
{
"observed_at": "2026-09-15T22:28:23.009075+00:00",
"status": "created",
"phase": "three_unapproved_requests_created",
"requests": [
{
"memo_id": "SECRETS-WP-0010-T03-apply",
"memo_version": 2,
"action": "apply",
"approval": {
"binding": {
"action": "apply",
"actor": "secrets-engine",
"digest": "sha256:03cc5b37437f14e86b686ce4054f976556334eff3fa260b03e8014ed3d9217e5",
"human_control": true,
"pdp_digest": "sha256:933427642c58c54f65dd4781b8e4c8e2f358eb96497ae35870fff4bd593d2b84",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "IR-WP-0004 read-only OpenRouter key authentication check; no inference",
"target": {
"attributes": {
"auth_targets": [
"se-prod-openrouter-llm-connect"
],
"fields": [],
"policy_targets": [
"se-prod-openrouter-llm-connect"
],
"stage": "prod"
},
"id": "catalog:openrouter-llm-connect",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-15T22:28:26+00:00",
"entries": [],
"id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-15T22:28:26+00:00",
"validity": {
"expires_at": "2026-09-16T22:28:26.260445+00:00",
"not_before": "2026-09-15T22:28:26.260445+00:00"
}
}
},
{
"memo_id": "SECRETS-WP-0010-T03-verify",
"memo_version": 2,
"action": "verify",
"approval": {
"binding": {
"action": "verify",
"actor": "secrets-engine",
"digest": "sha256:72d9267d038c17107c880ffc9009793ce9c70defbddfe2219628854b811a04b2",
"human_control": true,
"pdp_digest": "sha256:9e36cdbf3890cc5a7e550fd57191f9c0f2a6b2180909aac302aa3b999e7e6b25",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "IR-WP-0004 read-only OpenRouter key authentication check; no inference",
"target": {
"attributes": {
"auth_targets": [
"se-prod-openrouter-llm-connect"
],
"fields": [
"OPENROUTER_API_KEY"
],
"policy_targets": [
"se-prod-openrouter-llm-connect"
],
"stage": "prod"
},
"id": "catalog:openrouter-llm-connect",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-15T22:28:26+00:00",
"entries": [],
"id": "273d6882-6253-5dc9-ac54-544f92ef5e56",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-15T22:28:26+00:00",
"validity": {
"expires_at": "2026-09-16T22:28:26.464110+00:00",
"not_before": "2026-09-15T22:28:26.464110+00:00"
}
}
},
{
"memo_id": "SECRETS-WP-0010-T03-exec",
"memo_version": 2,
"action": "exec",
"approval": {
"binding": {
"action": "exec",
"actor": "secrets-engine",
"digest": "sha256:f2cf0fb53b740900756ccde5587c3578fcff44beef2f1edab17b9a198a4033d8",
"human_control": true,
"pdp_digest": "sha256:9f17812750fc8962b0fc58fc09df136850c9935a864fafa998a1c030dfb75bd9",
"pdp_path": true,
"principal": "secrets-engine",
"purpose": "IR-WP-0004 read-only OpenRouter key authentication check; no inference",
"target": {
"attributes": {
"auth_targets": [
"se-prod-openrouter-llm-connect"
],
"fields": [
"OPENROUTER_API_KEY"
],
"policy_targets": [
"se-prod-openrouter-llm-connect"
],
"stage": "prod"
},
"id": "catalog:openrouter-llm-connect",
"system": "secrets-engine",
"type": "secret-catalog-lane"
}
},
"created_at": "2026-09-15T22:28:26+00:00",
"entries": [],
"id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
"required_count": 1,
"status": "requested",
"superseded_by": null,
"updated_at": "2026-09-15T22:28:26+00:00",
"validity": {
"expires_at": "2026-09-16T22:28:26.786252+00:00",
"not_before": "2026-09-15T22:28:26.786252+00:00"
}
}
}
],
"credential_values_emitted": false,
"signature_verified": true,
"excess_scopes_refused": true,
"wrong_secret_refused": true,
"reader_scope_verified": true,
"human_entries_created": false,
"approvals_consumed": false
}