64 lines
2.3 KiB
YAML
64 lines
2.3 KiB
YAML
|
|
id: activity-core-metered-worker-token
|
||
|
|
kind: kv
|
||
|
|
org: coulomb
|
||
|
|
repo: activity-core
|
||
|
|
stage: prod
|
||
|
|
description: Activity Core queue token for rein-aharness-metered@railiance01,
|
||
|
|
delivered only as a companion of the Glas metered owner. Custody and issuance
|
||
|
|
are activity-core's (ACTIVITY-WP-0039); secrets-engine only reads.
|
||
|
|
mount: platform
|
||
|
|
path: workloads/activity-core/ops-run-workers/rein-aharness-metered-railiance01
|
||
|
|
mount_management: existing
|
||
|
|
fields:
|
||
|
|
- token
|
||
|
|
consumers:
|
||
|
|
- name: rein-aharness-metered-railiance01
|
||
|
|
auth: approle
|
||
|
|
claim: catalog:activity-core-metered-worker-token
|
||
|
|
purpose: Claim the admitted hfact-metered ops_run as rein-aharness-metered@railiance01
|
||
|
|
inside the catalog-bound Glas metered owner
|
||
|
|
workload_delivery: []
|
||
|
|
delivery_config:
|
||
|
|
companion_of:
|
||
|
|
- glas-claude-agent-dev-anthropic
|
||
|
|
delivery_modes:
|
||
|
|
- exec-env
|
||
|
|
delivery_auth:
|
||
|
|
method: approle
|
||
|
|
management: engine
|
||
|
|
policy_name: se-prod-activity-core-metered-worker-token
|
||
|
|
role_name: se-prod-activity-core-metered-worker-token
|
||
|
|
metadata_read: false
|
||
|
|
token_ttl: 5m
|
||
|
|
token_max_ttl: 15m
|
||
|
|
secret_id_ttl: 5m
|
||
|
|
secret_id_num_uses: 1
|
||
|
|
token_num_uses: 8
|
||
|
|
approval:
|
||
|
|
model: decision
|
||
|
|
decision_ref: ACTIVITY-WP-0039
|
||
|
|
notes: Ordinary lane approval, no human control (operator decision 2026-09-23,
|
||
|
|
SECRETS-WP-0011). Native apply and exec still need per-lane claim, PDP decision
|
||
|
|
and consume. This entry is not authorization.
|
||
|
|
verification:
|
||
|
|
positive: Exact scoped AppRole reads only token, delivered as ACTIVITY_CORE_WORKER_TOKEN
|
||
|
|
into the bound Glas metered owner.
|
||
|
|
negative: The claim-loop worker path, sibling KV, metadata, listing and writes denied;
|
||
|
|
the Glas lane AppRole cannot read this path.
|
||
|
|
risk:
|
||
|
|
classification: standard
|
||
|
|
notes: Lets the holder claim, heartbeat and close ops_runs as the metered identity
|
||
|
|
only. No provider spend by itself.
|
||
|
|
rotation:
|
||
|
|
owner: activity-core
|
||
|
|
expectation: Mint a new value at the same path via ACTIVITY-WP-0039 procedure; ESO
|
||
|
|
resyncs actcore-runtime-secret; next exec reads the new value.
|
||
|
|
ttl: owner-defined
|
||
|
|
deactivation:
|
||
|
|
owner: activity-core
|
||
|
|
expectation: Remove the identity from ACTIVITY_CORE_WORKERS and the path; revoke
|
||
|
|
the se-prod AppRole and policy.
|
||
|
|
audit:
|
||
|
|
evidence: Lane id, companion primary, actor, exact path, field name, timestamps,
|
||
|
|
and pass/fail only
|