Complete T03 with native OpenRouter authentication evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-16 02:12:45 +02:00
parent ec7263dc3f
commit 4a8ea4f591
7 changed files with 551 additions and 2 deletions

View file

@ -0,0 +1,39 @@
{
"status": "failed",
"phase": "verify_attempt_started",
"observed_at": "2026-09-16T00:04:58.620710+00:00",
"actions": [
{
"action": "apply",
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
"exit_code": 0,
"limits": {
"token_ttl": 900,
"token_max_ttl": 1800,
"secret_id_ttl": 900,
"secret_id_num_uses": 1,
"token_num_uses": 8
}
}
],
"health_before": {
"deployment": [
{
"namespace": "activity-core",
"name": "llm-connect",
"ready": 1
}
],
"externalsecret": [
{
"namespace": "activity-core",
"name": "llm-connect-provider-secrets",
"ready": true
}
]
},
"failure_type": "ValueError",
"failure_location": "/home/worsch/railiance-platform/scripts/t03-native-execution.py:25",
"failure_code": "revoked_token_still_usable",
"owner_forwards_closed": true
}

View file

@ -0,0 +1,381 @@
{
"task": "SECRETS-WP-0010-T03",
"status": "passed",
"scope": "Exact pinned read-only OpenRouter key-check recipient; no inference",
"initial_receipt": "2026-09-15-t03-native-execution.json",
"continuation_receipt": "2026-09-16-t03-resume-exec.json",
"reconciliation": "Initial supplemental revocation lookup fell back to admin helper after session token cleared; native verify itself passed. Continuation checked exact applied policy/role and consumed apply/verify state, tested the explicit revoked token (403), then consumed only exec.",
"native_evidence": [
{
"action": "apply",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "",
"detail": {
"approval_status": "pending",
"decision_ref": "CCR-2026-0003"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
"result": "attempt",
"stage": "prod",
"ts": "2026-09-16T00:05:08.084607+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "",
"detail": {},
"hub_delivery_requested": false,
"record_id": "443aeeaf-bae7-479d-a2d1-3d90ccd58594",
"related_record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:08.202043+00:00"
},
{
"action": "apply",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:dc57b3b9614aa15b",
"detail": {
"applied": [
"policy se-prod-openrouter-llm-connect",
"approle se-prod-openrouter-llm-connect -> [se-prod-openrouter-llm-connect]"
],
"approval_consume_idempotent": false,
"approval_consumed": true,
"approval_consumed_at": "2026-09-16T00:05:09+00:00",
"approval_human_control": true,
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
"approval_status": "approved",
"auth_provider": "env",
"authorization_decision_id": "decision:dc57b3b9614aa15b",
"authorization_expires_at": "2026-09-16T00:20:09+00:00",
"decision_id": "decision:dc57b3b9614aa15b",
"decision_ref": "CCR-2026-0003",
"request_digest": "sha256:c5c44adc715385640dffeb3305ff854fc69bd800929f8c31f93a536524089831",
"skipped": [
"kv-mount platform (externally managed; no mutation)"
],
"stance_authorized": true,
"stance_demo_exception": false,
"stance_failure_mode": "fail_closed",
"stance_stage": "prod"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
"result": "applied",
"stage": "prod",
"ts": "2026-09-16T00:05:09.827448+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:dc57b3b9614aa15b",
"detail": {},
"hub_delivery_requested": false,
"record_id": "783c71dc-d848-4511-bb52-a8d2f99f6048",
"related_record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:09.941648+00:00"
},
{
"action": "verify",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "",
"detail": {
"approval_status": "pending",
"decision_ref": "CCR-2026-0003",
"fields": [
"OPENROUTER_API_KEY"
],
"negative_requested": true,
"positive_requested": true
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
"result": "attempt",
"stage": "prod",
"ts": "2026-09-16T00:05:10.134582+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "",
"detail": {},
"hub_delivery_requested": false,
"record_id": "cbca0831-44f3-472a-99c5-e7033f59e450",
"related_record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:10.250783+00:00"
},
{
"action": "verify-check",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {
"field": "OPENROUTER_API_KEY",
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
"reason": "approved consumer can read lane field",
"role": "se-prod-openrouter-llm-connect",
"session": {
"established": true,
"revocation_attempted": true,
"revocation_succeeded": true,
"session_handle": "4c0eb1a18281"
}
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
"result": "positive:pass",
"stage": "prod",
"ts": "2026-09-16T00:05:12.330802+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {},
"hub_delivery_requested": false,
"record_id": "1e8511a0-1b43-4626-a04a-07084c026bd9",
"related_record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:12.450529+00:00"
},
{
"action": "verify-check",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
"reason": "unrelated token denied read"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
"result": "negative:pass",
"stage": "prod",
"ts": "2026-09-16T00:05:12.456767+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {},
"hub_delivery_requested": false,
"record_id": "3d203e9b-b441-4336-b18a-248cea35dde0",
"related_record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:12.559760+00:00"
},
{
"action": "verify",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {
"approval_consume_idempotent": false,
"approval_consumed": true,
"approval_consumed_at": "2026-09-16T00:05:11+00:00",
"approval_human_control": true,
"approval_id": "273d6882-6253-5dc9-ac54-544f92ef5e56",
"approval_status": "approved",
"auth_provider": "env",
"authorization_decision_id": "decision:b4fca706e4c55b9a",
"authorization_expires_at": "2026-09-16T00:20:11+00:00",
"check_count": 2,
"decision_id": "decision:b4fca706e4c55b9a",
"decision_ref": "CCR-2026-0003",
"fields": [
"OPENROUTER_API_KEY"
],
"negative_requested": true,
"positive_requested": true,
"request_digest": "sha256:a735896e9d208032ea08b073bcc819864b12116bdf60852fcdd2e54dad2e62bf",
"stance_authorized": true,
"stance_demo_exception": false,
"stance_failure_mode": "fail_closed",
"stance_stage": "prod"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
"result": "pass",
"stage": "prod",
"ts": "2026-09-16T00:05:12.565647+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {},
"hub_delivery_requested": false,
"record_id": "0ddce2fc-b552-4d62-8c24-6c167ff3826d",
"related_record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:12.741772+00:00"
},
{
"action": "exec",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "",
"detail": {
"approval_status": "pending",
"command": "/usr/bin/python3.12",
"decision_ref": "CCR-2026-0003",
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
"field": "OPENROUTER_API_KEY",
"mode": "exec-env",
"session": {}
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
"result": "attempt",
"stage": "prod",
"ts": "2026-09-16T00:08:28.639246+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "",
"detail": {},
"hub_delivery_requested": false,
"record_id": "b14a7442-c26b-4368-a4a0-fc39cd902143",
"related_record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:08:28.752134+00:00"
},
{
"action": "exec",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:82cec64febcf635f",
"detail": {
"approval_consume_idempotent": false,
"approval_consumed": true,
"approval_consumed_at": "2026-09-16T00:08:32+00:00",
"approval_human_control": true,
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
"approval_status": "approved",
"auth_provider": "env",
"authorization_decision_id": "decision:82cec64febcf635f",
"authorization_expires_at": "2026-09-16T00:23:31+00:00",
"command": "/usr/bin/python3.12",
"decision_id": "decision:82cec64febcf635f",
"decision_ref": "CCR-2026-0003",
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
"field": "OPENROUTER_API_KEY",
"mode": "exec-env",
"request_digest": "sha256:4082d2ccad78097a8be34ff0b0221ed2c4b6407fdbaf36e4a583927ae9acc820",
"session": {
"established": true,
"revocation_attempted": true,
"revocation_succeeded": true,
"session_handle": "6b9b4927b6ba"
},
"stance_authorized": true,
"stance_demo_exception": false,
"stance_failure_mode": "fail_closed",
"stance_stage": "prod"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
"result": "exit-0",
"stage": "prod",
"ts": "2026-09-16T00:08:30.937892+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:82cec64febcf635f",
"detail": {},
"hub_delivery_requested": false,
"record_id": "6b1208b7-32fd-4245-b73b-d35968e3a960",
"related_record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:08:31.048605+00:00"
}
],
"clock_acceptance": {
"scope": "production authority acceptance",
"host": "railiance01",
"client": "Linux/WSL via SSH loopback",
"os_clocks_changed": false,
"samples": [
{
"width_ms": 132.40261,
"railiance_minus_local_midpoint_ms": 1334.507298,
"independent_host_cross_check": true
},
{
"width_ms": 127.548741,
"railiance_minus_local_midpoint_ms": 1391.968235,
"independent_host_cross_check": true
},
{
"width_ms": 126.412228,
"railiance_minus_local_midpoint_ms": 1445.070823,
"independent_host_cross_check": true
}
],
"wrong_kid_refused": true,
"epoch": "b1164ccb-a4c2-4cc8-adf8-1d5597de697b",
"kid": "railiance01-clock-20260915-v1",
"public_key_sha256": "bd583446b5ed61d086806b2a0c5aaf33a875b751e45599e75335d1f415be609a",
"trust_lifetime_seconds": 900
},
"residual_handoffs": [
"INFD-IN-0005",
"SECRETS-WP-0006-T05",
"SECRETS-WP-0006-T06",
"SECRETS-WP-0007-T04",
"SECRETS-WP-0007-T07",
"IR-WP-0005",
"IR-WP-0006"
],
"approval_state": "All three native claims inspected as consumed after completion",
"inference_performed": false,
"provider_key_rotated": false
}

View file

@ -0,0 +1,59 @@
{
"status": "passed",
"phase": "all_actions_completed",
"observed_at": "2026-09-16T00:08:21.161761+00:00",
"actions": [
{
"action": "exec",
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
"exit_code": 0,
"key_check": {
"http_status": 200,
"result": "authenticated"
}
}
],
"health_before": {
"deployment": [
{
"namespace": "activity-core",
"name": "llm-connect",
"ready": 1
}
],
"externalsecret": [
{
"namespace": "activity-core",
"name": "llm-connect-provider-secrets",
"ready": true
}
]
},
"prior_receipt": "2026-09-15-t03-native-execution.json",
"completed_actions_not_replayed": [
"apply",
"verify"
],
"supplemental_cleanup": {
"unrelated_path_denied": true,
"session_revocation_verified": true,
"revoked_token_lookup_status": 403
},
"health_after": {
"deployment": [
{
"namespace": "activity-core",
"name": "llm-connect",
"ready": 1
}
],
"externalsecret": [
{
"namespace": "activity-core",
"name": "llm-connect-provider-secrets",
"ready": true
}
]
},
"owner_forwards_closed": true
}

View file

@ -91,3 +91,15 @@ records the live binding. Attended apply/readback passed; scoped credential
delivery verification remains pending. Native requesting
identity (`approval:create`) and Informed Decision human review are also needed;
do not reuse the withdrawn combined operator client or seed a production approval.
## Native acceptance completed — 2026-09-16
The sequence above has now passed for the exact pinned key-check recipient.
See `docs/evidence/2026-09-16-t03-completion.json` for native positive/negative
verification, three distinct consumed human approvals, OpenRouter HTTP 200,
revocation HTTP 403, application/ESO health and Railiance Clock admission.
The first supplemental revocation probe failed due to admin-helper fallback;
the retained continuation fixes that check without replaying apply or verify.
Future executions require new approvals. Trials and billing readiness remain
owned by IR-WP-0005/0006; general proxy retirement remains SECRETS-WP-0006-T06.