feat: deliver owner-bound credentials into bwrap commands
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-06 00:25:07 +02:00
parent 0196f083c4
commit 17d4160b6e
10 changed files with 505 additions and 6 deletions

View file

@ -84,11 +84,11 @@ continues to carry exact consumer identity and value-free route references.
Bwrap refuses `network.default: allow` and setup secret references. Network
egress is opt-in through the owner allowlist described in bwrap-egress.md;
empty-egress profiles retain loopback-only networking. There is still no
credential-delivery mechanism. Returning a
empty-egress profiles retain loopback-only networking. Credential exec delivery is now opt-in through the owner route contract
in bwrap-credentials.md; no production route is active. Returning a
declared egress list as evidence would not make that list enforced or usable.
Exec credential route references continue to be labels, not credential values
or delivery grants.
Exec credential route references contain no values. Nonempty references now
require an owner-configured, consumer-bound provider; references alone grant nothing.
On 2026-09-05, `warden route find anthropic --json` and `warden route find
claude-code --json` returned no matching workload routes. The generic OpenBao