rein-aharness/docs/owner-bootstrap.md
tegwick 565b07716a
Some checks failed
Governed runtime contract / contract (push) Failing after 23s
Bootstrap one metered owner cycle against a pinned standalone runtime
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 22:56:38 +02:00

73 lines
4.1 KiB
Markdown

# One-cycle owner bootstrap
`rein-aharness metered-once --owner-config /absolute/private/owner.json` is the
explicit exec-env child entry point. It prepares the exact admitted pins, consumes
only the deliberately delivered `ANTHROPIC_API_KEY`, removes provider authentication
and base-URL variables before other child processes, and runs at most one claim
cycle. The provider key is held by MessagesOwner outside the sandbox. Missing/mixed
credentials, invalid pins, missing ledgers, blocked profiles, failed readiness and
unclaimed refusals return nonzero. Receipt output excludes raw errors and prompts.
There is no key fetch, alternate provider, key file, OAuth/HOME or daemon fallback.
`--check` validates local pins without a key, queue access or workload dispatch;
it can advance the ledger's clock watermark but never initializes/reset its schema.
Use the standalone candidate interpreter as `python -I -B -m rein_aharness.cli`.
`-I` excludes editable PYTHONPATH/user-site fallbacks; `-B` prevents bytecode writes
from changing the complete artifact digest. The source and namespace rein commands
continue to use their existing entry points. The owner config selects the pinned
runtime through the trusted, ephemeral sandbox binding; it cannot add egress or
provider credentials to the child. Normal `claim-loop` behavior is unchanged.
The mode-0600, regular, owner-owned config has exactly these fields:
```json
{
"version": "1",
"authority_ref": "REPLACE_WITH_ACCEPTED_SPEND_AUTHORITY",
"spend_policy_sha256": "REPLACE_WITH_ACCEPTED_SPEND_POLICY_DIGEST",
"messages_policy": {
"tariff_ref": "REPLACE_WITH_ACCEPTED_PROVIDER_BOUNDS_AND_RATES",
"model": "claude-sonnet-4-6",
"context_tokens": 0,
"max_output_tokens": 0,
"input_microusd_per_token": 0,
"output_microusd_per_token": 0,
"allowed_betas": []
},
"runtime": {
"path": "/absolute/accepted/runtime",
"sha256": "REPLACE_WITH_ACCEPTED_COMPLETE_ARTIFACT_DIGEST"
}
}
```
The placeholders and zero bounds deliberately refuse. The authority reference and
spend digest must match the private existing SpendPolicy. Worker/project, exact
profile/descriptor digests, operational readiness, model, empty-egress bwrap profile
and runtime digest are checked before claim. Runtime, owner state and target checkout
must not overlap. Provision parent and request ledgers as separate reviewed actions.
The normal ACTIVITY_CORE/AGENT_HARNESS worker and state configuration still applies.
This config is not an authorization decision or a custody provenance proof. The
invoking credential engine must already have passed its exact action approval,
consume, scoped backend/readiness and admitted consumer checks. Its reviewed command
must be the fixed one-cycle owner entry point, with the accepted immutable config.
The current `glas-claude-agent-dev-anthropic` catalog describes delivery through the
sandbox helper and does not yet admit this owner holder. SECRETS-WP-0009-T03 and
HFACT-WP-0001-T03/T04 retain that review, existing client/audit/service dependencies,
Railiance placement and live negative tests. No real key is read by local validation.
This initial bootstrap obtains delivery before one claim cycle; an empty queue still
uses that delivery attempt. It intentionally exits after that cycle. Native scheduled
activation must not wrap a persistent claim loop with one reusable provider credential.
Later per-run acquisition for a continuous worker belongs to REINAH-WP-0003-T05/T06
and the same credential owner; it must retain exact action/lease/budget semantics.
`scripts/prove-metered-runtime.py` runs with a built candidate's `python -I -B`.
It verifies all four packages and definitions come from the artifact, exercises this
CLI once against an empty fake HTTP queue with a synthetic exec-env key, and runs the
pinned actual Claude CLI through the protected bwrap mount and metered owner. The
positive fake stream and pre-forward insufficient-capacity refusal are separate
cases. It checks unchanged artifact digest and teardown. Queue/provider/key/profile
are disposable fixtures, never evidence of live admission. The project records the
candidate result in `prj-helixforge-factory/evidence/2026-09-09-owner-bootstrap.json`.