Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
159 lines
6.7 KiB
YAML
159 lines
6.7 KiB
YAML
id: CCR-2026-0016
|
|
kind: credential-change-request
|
|
schema_version: 1
|
|
request_type: workload-kv-read
|
|
title: Glas local Claude workload Anthropic API key
|
|
status: in_flight
|
|
created: '2026-09-05'
|
|
updated: '2026-09-05'
|
|
in_flight:
|
|
missing_fields:
|
|
- openbao.policy_file
|
|
- openbao.auth
|
|
blocking_reason: Custody version 2 confirmed. Sand-boxer exec-env transport is proved
|
|
with synthetic values. Native activation is SECRETS-WP-0009; durable production
|
|
authorization/consume and scoped engine service authority are unavailable. Workspace
|
|
scope/budget and real provider authentication remain unverified.
|
|
owner: railiance-platform
|
|
requester:
|
|
agent: codex
|
|
reason: User selected a dedicated Anthropic workload API key for GLAS-WP-0012 and
|
|
SAND-WP-0015. Establish custody and owner delivery before the real local Claude
|
|
proof.
|
|
review:
|
|
required: true
|
|
required_approvers:
|
|
- platform-operator
|
|
- sand-boxer-owner
|
|
comments:
|
|
- at: '2026-09-05'
|
|
reviewer: user via chat
|
|
decision: authentication_model_selected
|
|
comment: User requested establishment of an Anthropic workload API key. This records
|
|
the chosen authentication model; final machine bindings are not yet known.
|
|
- at: '2026-09-05'
|
|
reviewer: user via chat
|
|
decision: empty_seed_authorized
|
|
comment: User authorized preparing the existing proposed location with an empty
|
|
version; user will create a version containing the secret through the OpenBao
|
|
UI. No runtime grant authorized by this seed.
|
|
target:
|
|
domain: infotech
|
|
tenant: glas-harness
|
|
workload: sand-boxer-claude-agent-dev
|
|
environment: production
|
|
purpose: Dedicated Claude Code inference for the Glas local agent-dev profile, delivered
|
|
by the sandbox owner.
|
|
openbao:
|
|
mount: platform
|
|
kv_path: platform/workloads/glas-harness/claude-agent-dev
|
|
fields:
|
|
- ANTHROPIC_API_KEY
|
|
metadata_read: false
|
|
policy_name: se-prod-glas-claude-agent-dev-anthropic
|
|
access_frontdoor:
|
|
type: sandbox-owner
|
|
catalog_id: glas-claude-agent-dev-anthropic
|
|
selector: Glas local Claude Anthropic workload API key
|
|
readiness: pending-review
|
|
resolvable: false
|
|
delivery:
|
|
surface: owner-exec
|
|
target: Sand-boxer delivers ANTHROPIC_API_KEY only to the selected Claude workload;
|
|
neither the Glas caller nor the runtime receives an OpenBao token.
|
|
risk:
|
|
classification: high
|
|
notes:
|
|
- KV path exists with live version 2. Catalog selector is still proposed and no
|
|
runtime read grant has been activated.
|
|
- Provider credential can incur API charges; use a dedicated workspace and user-selected
|
|
budget.
|
|
- Use a workspace-scoped service account key; organization administration is outside
|
|
the workload grant.
|
|
- OpenBao token expiration does not expire the provider key. Provider revocation
|
|
is required for compromise.
|
|
- Owner environment injection can expose the key to descendants within that workload;
|
|
it is not per-process secrecy against workload code.
|
|
verification:
|
|
positive:
|
|
- Confirm provider organization, workspace, service account, key identifier and
|
|
expiration using metadata only.
|
|
- Exact authenticated sandbox owner can read only the intended data entry and deliver
|
|
the field without logging it.
|
|
- Bounded real Claude proof succeeds through enforced provider egress and removes
|
|
private state on teardown.
|
|
negative:
|
|
- Wrong owner identity, sibling KV path, metadata read, parent listing and workload
|
|
writes are denied.
|
|
- Generic coding-agent identity cannot retrieve the credential directly.
|
|
- No credential or OpenBao token appears in execution replies, artifacts, source
|
|
tree or State Hub.
|
|
- A revoked predecessor provider key fails authentication after controlled rotation.
|
|
activation_conditions:
|
|
- User confirms Anthropic organization and workspace budget; provider service account
|
|
and key are created through attended Console custody.
|
|
- Confirm actual sandbox host service identity and auth binding; review exact read
|
|
policy and separate protected custody writer before apply.
|
|
- Seed KV with compare-and-set zero through attended custody; never enter values
|
|
in chat or command arguments.
|
|
- Positive and negative access, owner delivery and provider authentication evidence
|
|
pass before route activation.
|
|
evidence:
|
|
- at: '2026-09-05'
|
|
actor: codex
|
|
kind: empty_seed
|
|
result: passed
|
|
details:
|
|
- Empty ANTHROPIC_API_KEY version 1 created with CAS zero; user will create version
|
|
2 in UI.
|
|
- Request id 50cafc25-8d24-c1d6-5be8-1ade049e088b.
|
|
- Provider metadata recorded; metadata-only recovery completed after empty response
|
|
parsing fix; contained sessions revoked.
|
|
- No secret data read or real key handled; runtime lane remains inactive.
|
|
- at: '2026-09-05'
|
|
actor: codex
|
|
kind: custody_metadata_verification
|
|
result: passed
|
|
details:
|
|
- User reports secret saved in UI. Metadata confirms live version 2 created 2026-09-05T19:12:40.442796563Z,
|
|
neither deleted nor destroyed.
|
|
- Metadata request id d0b60424-a749-c72f-593b-ced6172dd183; contained session
|
|
revoked.
|
|
- No value read; field content and provider authentication not verified. Runtime
|
|
lane remains inactive.
|
|
- at: '2026-09-05'
|
|
actor: codex
|
|
kind: synthetic_owner_transport
|
|
result: passed
|
|
details:
|
|
- Sand-boxer sandbox880f749e proved synthetic exec-env delivery, output redaction,
|
|
subsequent-exec absence, wrong-project denial and teardown.
|
|
- 'No real credential was read. Native production exec refused before OpenBao:
|
|
durable access-engine decision record unavailable.'
|
|
- SECRETS-WP-0009 owns native activation; this CCR remains custody provenance,
|
|
not native apply authorization.
|
|
lifecycle:
|
|
deactivate: Disable the owner route and provider key; revoke outstanding OpenBao
|
|
reader tokens. Preserve KV history under platform retention rules.
|
|
rotate: Create a replacement provider key, write with expected-version CAS, stop
|
|
old runs, verify new delivery and inference, then revoke the predecessor at Anthropic
|
|
and prove its denial.
|
|
compromised: Disable the provider key immediately, stop affected runs and owner
|
|
route, revoke Bao leases, replace forward through protected custody and record
|
|
non-secret incident evidence.
|
|
state_hub:
|
|
workplan_id: GLAS-WP-0012
|
|
task_id: GLAS-WP-0012-T02
|
|
provider_metadata:
|
|
organization_id: e1a8f305-9e64-4639-a7fd-af48e34f37c7
|
|
key_name: claude_key_bernd.worsch
|
|
expires_at: '2027-01-31T21:00:00Z'
|
|
source: user supplied; provider identity and workspace scope not independently verified
|
|
native_delivery:
|
|
owner: secrets-engine
|
|
catalog_id: glas-claude-agent-dev-anthropic
|
|
workplan: SECRETS-WP-0009
|
|
policy_name: se-prod-glas-claude-agent-dev-anthropic
|
|
role_name: se-prod-glas-claude-agent-dev-anthropic
|
|
status: proposed-not-applied
|
|
custody_only_ccr: true
|