2026-09-14 00:54:55 +02:00
|
|
|
---
|
|
|
|
|
id: SECRETS-WP-0010
|
|
|
|
|
type: workplan
|
|
|
|
|
title: "Native OpenRouter access for intelligence-radar"
|
|
|
|
|
domain: infotech
|
|
|
|
|
repo: secrets-engine
|
2026-09-14 03:21:48 +02:00
|
|
|
status: active
|
2026-09-14 00:54:55 +02:00
|
|
|
owner: codex
|
|
|
|
|
topic_slug: netkingdom
|
|
|
|
|
created: "2026-09-14"
|
|
|
|
|
updated: "2026-09-14"
|
|
|
|
|
related_workplans:
|
|
|
|
|
- IR-WP-0004
|
|
|
|
|
- FLEX-WP-0026
|
|
|
|
|
- SECRETS-WP-0007
|
|
|
|
|
- SECRETS-WP-0006
|
2026-09-14 00:57:12 +02:00
|
|
|
state_hub_workstream_id: "e1e68392-e7c4-50ab-91e4-4793e3591cac"
|
2026-09-14 00:54:55 +02:00
|
|
|
---
|
|
|
|
|
|
|
|
|
|
Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f.
|
|
|
|
|
Implementation and execution procedure: `docs/openrouter-native-access.md`.
|
|
|
|
|
|
|
|
|
|
## Bind approval to actual native custody and delivery inputs
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: SECRETS-WP-0010-T01
|
|
|
|
|
status: done
|
|
|
|
|
priority: high
|
2026-09-14 00:57:12 +02:00
|
|
|
state_hub_task_id: "b315d0bd-63c5-530d-afde-b82973cee3a9"
|
2026-09-14 00:54:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Implemented context.catalog_target and complete plan limits. Changed paths,
|
|
|
|
|
mounts, owners and token limits refuse replay before consume/backend against
|
|
|
|
|
real local components. Existing exec-owner and human-control contracts retained.
|
|
|
|
|
410 repository tests and 26 component checks passed. Receipts in docs/evidence.
|
|
|
|
|
|
|
|
|
|
## Prepare value-safe first recipient and exact native plan
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: SECRETS-WP-0010-T02
|
|
|
|
|
status: done
|
|
|
|
|
priority: high
|
2026-09-14 00:57:12 +02:00
|
|
|
state_hub_task_id: "564496a4-2ea9-51e5-9573-84003d955666"
|
2026-09-14 00:54:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Implemented the fixed read-only OpenRouter key-check script and synthetic tests.
|
|
|
|
|
Inactive proposed overlay declares human control and a pending exact recipient;
|
|
|
|
|
active llm-connect catalog admission is not broadened. Non-secret apply request
|
|
|
|
|
and bounded plan are review artifacts, not runtime grants.
|
|
|
|
|
|
|
|
|
|
## Admit and verify real native delivery
|
|
|
|
|
|
|
|
|
|
```task
|
|
|
|
|
id: SECRETS-WP-0010-T03
|
2026-09-14 03:21:48 +02:00
|
|
|
status: progress
|
2026-09-14 00:54:55 +02:00
|
|
|
priority: high
|
2026-09-14 00:57:12 +02:00
|
|
|
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"
|
2026-09-14 00:54:55 +02:00
|
|
|
```
|
|
|
|
|
|
|
|
|
|
Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4,
|
|
|
|
|
11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05
|
|
|
|
|
(identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader
|
|
|
|
|
admission, exact installed recipient admission, real human approval/consume and
|
|
|
|
|
scoped attended platform authority. No Approval Engine StatefulSet/pod/Service
|
|
|
|
|
was present in its declared namespace at the 2026-09-14 inspection.
|
|
|
|
|
|
|
|
|
|
Then execute `docs/openrouter-native-access.md` steps: bounded native apply,
|
|
|
|
|
positive/negative checks, ESO/app health, value-safe key check and session revoke.
|
|
|
|
|
SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan
|
|
|
|
|
must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and
|
|
|
|
|
IR-WP-0004-T02 waiting until the native route passes. Trials require a separately
|
|
|
|
|
bound recipient and the existing campaign/budget reconciliation.
|
2026-09-14 01:08:50 +02:00
|
|
|
|
|
|
|
|
### T03 continuation — 2026-09-14
|
|
|
|
|
|
|
|
|
|
User explicitly requested execution of T03. Completed the independently runnable
|
|
|
|
|
prerequisites: Approval Engine is now deployed and restart/backup/restore verified
|
|
|
|
|
(APPROVAL-WP-0002-T03 done). Existing audit sender custody/ESO and KeyCape
|
|
|
|
|
consumer registration were already complete; neither was reprovisioned. Live
|
|
|
|
|
JWKS/readiness/anonymous and invalid-bearer refusal plus durable heartbeat/outbox
|
|
|
|
|
checks pass. See `docs/evidence/2026-09-14-approval-engine-deployment.json`.
|
|
|
|
|
|
|
|
|
|
Installed the read-only checker in the owner-private versioned local directory,
|
|
|
|
|
using pinned `/usr/bin/python3.12 -I -B <script>`, fixed environment and private
|
|
|
|
|
runtime cwd. `docs/proposals/openrouter-key-check.yaml` now has a configured
|
|
|
|
|
recipient; it remains outside the active catalog and does not admit key use.
|
|
|
|
|
Runtime trust is the system-owned Python standard library plus pinned executable
|
|
|
|
|
and script. The install receipt and finalized apply/verify/exec request JSONs are
|
|
|
|
|
under docs/evidence. No provider request or credential read was made.
|
|
|
|
|
|
2026-09-14 01:30:23 +02:00
|
|
|
Operator input received, 2026-09-14: the user explicitly selected
|
|
|
|
|
`net-kingdom-admins` for CCR-2026-0019. The platform source now records that
|
|
|
|
|
binding and the approved metadata apply. The guarded applier requires role
|
|
|
|
|
`secrets-engine-approval-client-workload-kv-read`; its dry run passes.
|
|
|
|
|
Attended apply/readback passed: exact group, policy and 900-second TTL verified.
|
|
|
|
|
Warden completed its contained session successfully. Platform receipt:
|
|
|
|
|
`docs/evidence/2026-09-14-ccr0019-operator-binding.json`. Native scoped delivery
|
|
|
|
|
proof remains pending; no credential was read and the front door stays disabled.
|
2026-09-14 01:08:50 +02:00
|
|
|
A separately admitted approval:create requester and real human approver flow
|
|
|
|
|
also remain necessary: the withdrawn approval-engine-operator convenience client
|
|
|
|
|
must not be restored or used to create and approve its own requests. Informed
|
|
|
|
|
Decision's native review flow and requester admission are dependencies, not
|
|
|
|
|
replaced by a service token or a seeded live approval. T03 remains open until
|
|
|
|
|
real approval/consume, attended OpenBao apply, key check, positive/negative
|
|
|
|
|
native delivery and revocation are evidenced.
|
2026-09-14 01:46:47 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
### Native reader acceptance — 2026-09-14
|
|
|
|
|
|
|
|
|
|
The scoped Warden login lane `secrets-engine-approval-client-login` now routes
|
|
|
|
|
to the applied OIDC reader and the platform's silent preflight. The installed
|
|
|
|
|
Warden package still carries an older catalog; use the explicit source catalog
|
|
|
|
|
`WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml`
|
|
|
|
|
until its next normal installation refresh. This lane authenticates the reader;
|
|
|
|
|
it is not a raw secret fetch or retained-file delivery interface.
|
|
|
|
|
|
|
|
|
|
Live effective-policy and capability checks passed: only exact data/metadata
|
|
|
|
|
read, no sibling secret, parent listing, write or control-plane authority.
|
|
|
|
|
A second contained session read existing version 1 into an operator-owned 0600
|
|
|
|
|
file in a private 0700 runtime tmpfs directory. The native consumer exchanged
|
|
|
|
|
separate read and consume scopes; Approval Engine verified the read token before
|
|
|
|
|
returning 404 for a fresh nonexistent approval, and refused the consume-only
|
|
|
|
|
token's read request with 403. No approval was created, bound or consumed.
|
|
|
|
|
Both Warden sessions exited 0 after self-revocation/helper cleanup; temporary
|
|
|
|
|
credential file and directory were removed. Four refusal/path/redirect tests
|
|
|
|
|
pass. Receipts are in platform `docs/evidence/2026-09-14-ccr0019-{reader-preflight,delivery-check}.json`.
|
|
|
|
|
|
|
|
|
|
Remaining: an actual nonmember login refusal, real approval claim/consume,
|
|
|
|
|
separate narrow requester admission and deployed Informed Decision review with
|
|
|
|
|
an explicitly admitted human mandate. The reader group alone grants no review
|
|
|
|
|
mandate. T03 and CCR delivery activation remain open; no OpenRouter key was read.
|
2026-09-14 02:47:32 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
### T03 scoped review deployment — 2026-09-14
|
|
|
|
|
|
|
|
|
|
The operator explicitly admitted `net-kingdom-admins` as the human review group
|
|
|
|
|
for only the T03 apply, verify and read-only key-check records, separately from
|
|
|
|
|
its credential-reader membership. The review service is live and ready at
|
|
|
|
|
https://decisions.coulomb.social with verified KeyCape groups, fresh MFA and a
|
|
|
|
|
dedicated caller-bound Flex Auth policy. Its mandate does not grant consumption.
|
|
|
|
|
|
|
|
|
|
The new `secrets-engine-requester` client has subject `secrets-engine`, tenant
|
|
|
|
|
`tenant:platform`, role `secrets-engine-requester`, and only `approval:create`.
|
|
|
|
|
CCR-2026-0024 and CCR-2026-0025 provide distinct verifier and attended reader
|
|
|
|
|
custody. Native signature, subject, scope and TTL checks passed; excess scopes
|
|
|
|
|
and a wrong secret were refused. Existing consumer identity is unchanged.
|
|
|
|
|
Three real requested approvals were created with human control, required count
|
|
|
|
|
one, and zero entries. Platform evidence is
|
|
|
|
|
`docs/evidence/2026-09-14-t03-native-approval-requests.json`.
|
|
|
|
|
|
|
|
|
|
Review image: sha256:8f55bcecf37a8d65f96e073510b1ffb4636c0a91d75e1ee7d582ad4bce8b953a.
|
|
|
|
|
Policy image: sha256:c9f028b49dfcede930a9cc48757ec8371ecc71d20b1bfee2733e55298dffcc7c.
|
|
|
|
|
Review tests: 339 passed, 39 optional integration tests skipped; 11 container
|
|
|
|
|
checks and HIGH/CRITICAL image scan passed. Policy checks: 57 local and 6 native
|
|
|
|
|
caller checks passed, using synthetic subjects, not human binding evidence.
|
|
|
|
|
Approval Engine CPU request was reduced from 25m to 10m after observing 1m use;
|
|
|
|
|
review requests 20m and its PDP 5m. Limits are unchanged. Native services ready.
|
|
|
|
|
|
|
|
|
|
Remaining T03 gate: the operator's exact signed-in account is needed to address
|
|
|
|
|
three prepared immutable memos, followed by real acknowledgements and acceptance
|
|
|
|
|
in Informed Decision. No human entry or consume has been generated by an agent.
|
|
|
|
|
Then execute claim -> validated PDP Check -> CAS consume separately for apply,
|
|
|
|
|
verify and exec using scoped attended authority, and capture native denial,
|
|
|
|
|
revocation, workload health and key-check evidence. No OpenRouter credential has
|
|
|
|
|
been read and no inference or spend was performed. T03 remains waiting; this
|
|
|
|
|
entry supersedes earlier statements that requester or group admission is missing.
|
2026-09-14 02:54:54 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
### Live browser registration correction — 2026-09-14
|
|
|
|
|
|
|
|
|
|
The user's login exposed `invalid_profile_usage: unknown client_id`: the public
|
|
|
|
|
`informed-decision-approver` registration existed in the source example but was
|
|
|
|
|
absent from live KeyCape. Applied exactly the existing admitted registration,
|
|
|
|
|
with UID/resourceVersion guards and byte-preserving insertion; unrelated clients,
|
|
|
|
|
configuration, signing key and pinned image were preserved. KeyCape is ready.
|
|
|
|
|
The actual review-site `/auth/start` now redirects through KeyCape to
|
|
|
|
|
`auth.coulomb.social`. Wrong redirect, consume scope and absent PKCE are refused.
|
|
|
|
|
Receipt: key-cape/docs/evidence/2026-09-14-informed-decision-browser-registration.json.
|
|
|
|
|
Repeatable contained helper: key-cape/tools/register-informed-decision.py
|
|
|
|
|
(default preflight; --apply mutates only a missing exact registration).
|
|
|
|
|
Human callback/MFA/token proof and T03 approval entries remain pending. The
|
|
|
|
|
previous ready check established service health, not browser login acceptance.
|
2026-09-14 03:21:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
### Human approval and execution preparation — 2026-09-14
|
|
|
|
|
|
|
|
|
|
The three native Approval Engine records are approved by the actual signed-in
|
|
|
|
|
human uid=platform-root,ou=people,dc=netkingdom,dc=local, with one human entry each
|
|
|
|
|
and no consumption at inspection. The exact action/memo IDs remain unchanged.
|
|
|
|
|
Execution preflight found and corrected two CLI gaps: missing explicit policy/
|
|
|
|
|
role targets, and an unnecessary hub/fixture lookup after an already validated
|
|
|
|
|
native claim/PDP join. Real claim validation and mandatory CAS remain in place;
|
|
|
|
|
unserved legacy review paths are unchanged. 414 regression tests passed, including
|
|
|
|
|
frozen approved-request comparisons and consume-refusal/backend isolation.
|
|
|
|
|
The attended owner procedure is in platform scripts/t03-native-execution.py and
|
|
|
|
|
t03-attended-delivery.py. It uses the exact scoped client reader, contained
|
|
|
|
|
platform administration, named/pinned native pods, private runtime storage, and
|
|
|
|
|
native CLI handlers. No approval has yet been consumed by this preparation.
|