Prepare exact native recipient and record approval service activation
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 01:08:50 +02:00
parent 992f20f79d
commit 1f7f42b277
9 changed files with 514 additions and 62 deletions

View file

@ -32,10 +32,10 @@ A successful check does not reconcile radar's existing spend reservation.
`docs/proposals/openrouter-key-check.yaml` is an inactive proposed catalog overlay.
It retains the existing lane id/KV/policy/AppRole and ESO consumer, declares human
control, and names the key-check recipient with a pending exec-owner binding.
control, and names the key-check recipient with an installed, configured exec-owner binding.
The active `catalog/openrouter-llm-connect.yaml` remains limited to its admitted
llm-connect purpose. The proposal is outside the active catalog and pending exec
refuses before consume/backend. Do not copy it into the active catalog until
llm-connect purpose. The proposal is outside the active catalog; configuration is not approval.
Its exact interpreter/script paths and pins are recorded in the install receipt. Do not copy it into the active catalog until
custody-owner admission and the exact protected recipient installation are reviewed.
## Verification
@ -57,14 +57,15 @@ state their scope and cleanup. This removes the outdated PDP image dependency.
## Remaining admitted execution sequence (SECRETS-WP-0010-T03)
1. Complete APPROVAL-WP-0002-T01/T03/T05 and its identity/audit dependencies;
its declared namespace currently has no StatefulSet, pod or Service. Complete
1. APPROVAL-WP-0002-T03 is now deployed, with existing audit custody and current
JWKS verified (2026-09-14 deployment receipt). T01/T05 still require the
admitted requesting/human/consumer path. Complete
RPF-WP-0035-T06 / CCR-2026-0019 client-side reader admission for the secrets-engine
approval-client. Keep secrets outside Git and use the existing attended
procedure in `docs/approval-service-auth.md`; do not read the verifier's Secret.
2. Have the custody owner admit this exact read-only recipient. Install and pin
its Python runtime and script, exact argv, private working directory and fixed
environment via `docs/exec-owner-binding.md`. Obtain the scoped attended
2. Have the custody owner admit this exact read-only recipient. The configured local installation already pins
its Python executable and script, exact argv, private working directory and fixed
environment; review the installation receipt against `docs/exec-owner-binding.md`. Obtain the scoped attended
platform authority; no standing bootstrap credential or sibling identity.
3. Render the finalized request, use the evaluator-origin digest to create a
declared-human-control approval, obtain the real human entry, observe claim,
@ -80,3 +81,11 @@ state their scope and cleanup. This removes the outdated PDP image dependency.
approval. Reconcile the existing USD 0.023712 reservation in campaign
`ir-openrouter-pilot-20260913`; preserve the authorized USD 10 ceiling. This
task did not execute the key check or spend campaign funds.
The finalized request artifacts are `docs/evidence/2026-09-14-openrouter-final-*-request.json`.
They replace the earlier pending-recipient proposal as review inputs, not as an
issued approval. Recipient proof is in `2026-09-14-openrouter-recipient-install.json`.
The exact operator-group question is pending user input. Native requesting
identity (`approval:create`) and Informed Decision human review are also needed;
do not reuse the withdrawn combined operator client or seed a production approval.