Bind credential exec to exact owner inputs and approval digest
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-10 09:29:38 +02:00
parent 9eb07fd8fc
commit 42b48aa54f
13 changed files with 626 additions and 7 deletions

View file

@ -5,6 +5,13 @@ railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-00
KV custody is already confirmed at version 2. Do not provision or rotate it as
part of native read-lane adoption.
2026-09-10: the factory continuation uses a metered MessagesOwner outside the
sandbox. Its exact runtime is installed and synthetically proved on Railiance.
The catalog now blocks exec with an explicit pending recipient binding until the
native holder and immutable configuration are admitted. See
[exec owner binding](exec-owner-binding.md). The older transport description
below records the original child-key route; it cannot admit the metered holder.
The generated plan checks existing mount `platform`, creates policy and AppRole
`se-prod-glas-claude-agent-dev-anthropic`, and grants read only on
`platform/data/workloads/glas-harness/claude-agent-dev`. Field ANTHROPIC_API_KEY
@ -37,7 +44,7 @@ catalog and service-jwt selection. No real value was requested.
Activation depends on SECRETS-WP-0007-T04 (exact production actions) and
SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require
canonical ActionAuthorization for each protected action, successful consume,
canonical validated DecisionEnvelope for each protected action, successful consume,
and exact scoped backend authority. This draft cannot authorize itself; an
operator browser token or unsafe-demo flag is not a runtime substitute.