id: CCR-2026-0016 kind: credential-change-request schema_version: 1 request_type: workload-kv-read title: Glas local Claude workload Anthropic API key status: in_flight created: '2026-09-05' updated: '2026-09-05' in_flight: missing_fields: - openbao.policy_file - openbao.auth blocking_reason: Custody version 2 confirmed. Sand-boxer exec-env transport is proved with synthetic values. Native activation is SECRETS-WP-0009; durable production authorization/consume and scoped engine service authority are unavailable. Workspace scope/budget and real provider authentication remain unverified. owner: railiance-platform requester: agent: codex reason: User selected a dedicated Anthropic workload API key for GLAS-WP-0012 and SAND-WP-0015. Establish custody and owner delivery before the real local Claude proof. review: required: true required_approvers: - platform-operator - sand-boxer-owner comments: - at: '2026-09-05' reviewer: user via chat decision: authentication_model_selected comment: User requested establishment of an Anthropic workload API key. This records the chosen authentication model; final machine bindings are not yet known. - at: '2026-09-05' reviewer: user via chat decision: empty_seed_authorized comment: User authorized preparing the existing proposed location with an empty version; user will create a version containing the secret through the OpenBao UI. No runtime grant authorized by this seed. target: domain: infotech tenant: glas-harness workload: sand-boxer-claude-agent-dev environment: production purpose: Dedicated Claude Code inference for the Glas local agent-dev profile, delivered by the sandbox owner. openbao: mount: platform kv_path: platform/workloads/glas-harness/claude-agent-dev fields: - ANTHROPIC_API_KEY metadata_read: false policy_name: se-prod-glas-claude-agent-dev-anthropic access_frontdoor: type: sandbox-owner catalog_id: glas-claude-agent-dev-anthropic selector: Glas local Claude Anthropic workload API key readiness: pending-review resolvable: false delivery: surface: owner-exec target: Sand-boxer delivers ANTHROPIC_API_KEY only to the selected Claude workload; neither the Glas caller nor the runtime receives an OpenBao token. risk: classification: high notes: - KV path exists with live version 2. Catalog selector is still proposed and no runtime read grant has been activated. - Provider credential can incur API charges; use a dedicated workspace and user-selected budget. - Use a workspace-scoped service account key; organization administration is outside the workload grant. - OpenBao token expiration does not expire the provider key. Provider revocation is required for compromise. - Owner environment injection can expose the key to descendants within that workload; it is not per-process secrecy against workload code. verification: positive: - Confirm provider organization, workspace, service account, key identifier and expiration using metadata only. - Exact authenticated sandbox owner can read only the intended data entry and deliver the field without logging it. - Bounded real Claude proof succeeds through enforced provider egress and removes private state on teardown. negative: - Wrong owner identity, sibling KV path, metadata read, parent listing and workload writes are denied. - Generic coding-agent identity cannot retrieve the credential directly. - No credential or OpenBao token appears in execution replies, artifacts, source tree or State Hub. - A revoked predecessor provider key fails authentication after controlled rotation. activation_conditions: - User confirms Anthropic organization and workspace budget; provider service account and key are created through attended Console custody. - Confirm actual sandbox host service identity and auth binding; review exact read policy and separate protected custody writer before apply. - Seed KV with compare-and-set zero through attended custody; never enter values in chat or command arguments. - Positive and negative access, owner delivery and provider authentication evidence pass before route activation. evidence: - at: '2026-09-05' actor: codex kind: empty_seed result: passed details: - Empty ANTHROPIC_API_KEY version 1 created with CAS zero; user will create version 2 in UI. - Request id 50cafc25-8d24-c1d6-5be8-1ade049e088b. - Provider metadata recorded; metadata-only recovery completed after empty response parsing fix; contained sessions revoked. - No secret data read or real key handled; runtime lane remains inactive. - at: '2026-09-05' actor: codex kind: custody_metadata_verification result: passed details: - User reports secret saved in UI. Metadata confirms live version 2 created 2026-09-05T19:12:40.442796563Z, neither deleted nor destroyed. - Metadata request id d0b60424-a749-c72f-593b-ced6172dd183; contained session revoked. - No value read; field content and provider authentication not verified. Runtime lane remains inactive. - at: '2026-09-05' actor: codex kind: synthetic_owner_transport result: passed details: - Sand-boxer sandbox880f749e proved synthetic exec-env delivery, output redaction, subsequent-exec absence, wrong-project denial and teardown. - 'No real credential was read. Native production exec refused before OpenBao: durable access-engine decision record unavailable.' - SECRETS-WP-0009 owns native activation; this CCR remains custody provenance, not native apply authorization. lifecycle: deactivate: Disable the owner route and provider key; revoke outstanding OpenBao reader tokens. Preserve KV history under platform retention rules. rotate: Create a replacement provider key, write with expected-version CAS, stop old runs, verify new delivery and inference, then revoke the predecessor at Anthropic and prove its denial. compromised: Disable the provider key immediately, stop affected runs and owner route, revoke Bao leases, replace forward through protected custody and record non-secret incident evidence. state_hub: workplan_id: GLAS-WP-0012 task_id: GLAS-WP-0012-T02 provider_metadata: organization_id: e1a8f305-9e64-4639-a7fd-af48e34f37c7 key_name: claude_key_bernd.worsch expires_at: '2027-01-31T21:00:00Z' source: user supplied; provider identity and workspace scope not independently verified native_delivery: owner: secrets-engine catalog_id: glas-claude-agent-dev-anthropic workplan: SECRETS-WP-0009 policy_name: se-prod-glas-claude-agent-dev-anthropic role_name: se-prod-glas-claude-agent-dev-anthropic status: proposed-not-applied custody_only_ccr: true