feat: pin bwrap rein runtimes and isolate private state

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-05 20:36:11 +02:00
parent c2886b2f77
commit d69827aaa2
12 changed files with 639 additions and 9 deletions

View file

@ -8,7 +8,7 @@ status: active
owner: codex
topic_slug: owner-mediated-execution
created: "2026-09-04"
updated: "2026-09-04"
updated: "2026-09-05"
state_hub_workstream_id: "b616d1cd-208f-5ecf-a4a0-a028396422c4"
---
@ -112,9 +112,16 @@ destroy the workspace, then update Glas readiness and Activity Core
`ACTIVITY-WP-0032-T05`. Do not trigger the production pilot before readiness
changes.
This task depends on a reviewed Glas profile revision, the owner-fronted
`rein-openweights-openrouter-approle` read, and a deployed sand-boxer owner
service. No credential value belongs in this workplan or State Hub.
This task depends on a reviewed Glas profile revision and its matching
credential/egress/runtime contract. Glas selected the Claude route first in
GLAS-WP-0012; the earlier OpenRouter AppRole dependency applies only to the
separate open-weight profile and does not establish Claude authentication.
2026-09-05: SAND-WP-0015 implements pinned Python runtime mounts and private
namespace state, with a real rein CLI startup proof. Claude workload credential
routing, enforced provider egress, pinning/deploying the Claude executable,
and the real-model acceptance remain open in SAND-WP-0015-T04. No credential
value belongs in this workplan or State Hub.
## Acceptance criteria