Triage the older secrets-engine inbox: record platform waits and railiance-clock
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s

railiance-platform e82bb289 recorded against SECRETS-WP-0006-T05 (explicit wait
on T04 serving; CCR-2026-0003 is provenance only). 29cccf8a recorded against
SECRETS-WP-0008-T06, including the open tenant:coulomb vs tenant:platform
question for the service JWT, left for an owner session. railiance-clock's
review request opened as SECRETS-IN-0003. The intelligence-radar messages are
superseded by SECRETS-WP-0010-T03 (done 2026-09-16) and answered by pointer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 07:37:53 +02:00
parent 8a48cb05df
commit 377ec06d69
3 changed files with 54 additions and 1 deletions

View file

@ -199,6 +199,16 @@ priority: high
state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542"
```
Inbox triage 2026-09-21. railiance-platform `e82bb289` (2026-09-09) answered
the openrouter-llm-connect first-lane request with an explicit **wait on T04
serving**: no approval object path and no scoped attended authority yet, because
the canonical `action=apply` ActionAuthorization does not exist and llm-connect
has not confirmed ESO health. It accepts the apply shape and rollback
containment in principle, confirms CCR-2026-0003 is provenance and not
executable authorization for a native AppRole, and will name the approval path
and attended window together once T04 serves and llm-connect confirms. Keep
`forgejo-admin-api-token` last. Nothing changes here; T05 stays `wait`.
Progress 2026-09-03. Re-rendered guarded plans on the post-hardening engine.
Every admitted lane is still `kv-mount-check` + exact-path read policy +
bounded AppRole. First live candidate is `openrouter-llm-connect` (narrowest

View file

@ -339,7 +339,22 @@ does not read `BAO_TOKEN` on failure. `--bootstrap-token-file` is a named
break-glass provider with `auth_break_glass` evidence.
The platform-owned OpenBao JWT mount/role is still unpublished, so auto keeps
bootstrap/env and this task remains `wait`. Companion §7 / statute §3.4: an
bootstrap/env and this task remains `wait`.
Inbox triage 2026-09-21. railiance-platform `29cccf8a` (2026-09-09): status,
not a contract. Their side is RPF-WP-0035-T02 (design
`docs/credential-lane-designs/secrets-engine-service-jwt.md`), still `wait`.
Designed: role/audience `secrets-engine-openbao`, subject
`service:secrets-engine`, token policy `secrets-engine-login-self`, five-minute
budget, login-only. KeyCape issuer `https://kc.coulomb.social` and its JWKS are
now confirmed live, so the remaining blocker is this registration's issued
claims, consumer readiness, an approved source and attended apply authority.
**Open question for secrets-engine, not answered in the triage session:** the
JWT design says `tenant:coulomb`, while the approval chain resolved to
`tenant:platform` (decision `5ed3fb35`) and approval-engine compares tenant by
exact string. Which tenant the OpenBao service identity carries is a design
decision for an owner session; platform will correct its design before the
role exists once told. A service login grants no lane mutation authority. Companion §7 / statute §3.4: an
agent holds no long-lived credential of its own. Authority is per task,
time-bounded, and attributable to the principal it acts for.