railiance-platform/docs/credential-lane-designs/t03-renewed-execution.md
codex 53825190ca
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Point the OpenRouter cycle at memo version 3.
Fresh receipts use the new approval IDs. A matching live policy and AppRole
skips apply without claiming that approval. A difference fails closed.

Assistant: grok
Assistant-Session: 01a0e2a1-8058-7553-9999-b7d106c17047
2026-09-27 15:33:09 +02:00

1.7 KiB

T03 continuation after Railiance Clock deployment

The 2026-09-16 requests were consumed. The next cycle uses three new approval IDs and immutable memo version 3. The creation receipt is docs/evidence/2026-09-27-t03-approval-requests.json; execution receipts are secrets-engine/docs/evidence/2026-09-27-t03-native-execution.json and docs/evidence/2026-09-27-t03-attended-delivery.json. The exact apply/verify/exec action requests and checker pins are unchanged.

Run the requester and execution worker with /home/worsch/secrets-engine/.venv/bin/python; this environment includes Clock, JSON Schema, JWT, and YAML dependencies. The requester requires --clock-trust-file and validates full token validity against that interval. The native execution worker requires SECRETS_ENGINE_CLOCK_TRUST_FILE. Refresh the boot-bound admission via the independently verified Clock public key and SSH owner epoch readback immediately before attended execution. An expired trust file fails closed; never extend it or use workstation wall-time fallback.

Use http://127.0.0.1:18200 for the admitted OpenBao relay and the existing operator-browser PATH helper on WSL when no browser launcher is installed. The outer lane remains secrets-engine-approval-client-login; its reviewed t03-attended-delivery.py invokes the separate contained platform-admin lane. Both retain their own self-revocation and private runtime cleanup.

Human review: https://decisions.coulomb.social/review?memo_id=SECRETS-WP-0010-T03-apply (and identifiers ending -verify and -exec). Version 3 is required. The requester has no approval or consume scope; no human entries are copied from version 2. No execution may begin before the new approvals pass native claim/PDP checks.