Complete T03 with native OpenRouter authentication evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-16 02:12:45 +02:00
parent ec7263dc3f
commit 4a8ea4f591
7 changed files with 551 additions and 2 deletions

View file

@ -0,0 +1,39 @@
{
"status": "failed",
"phase": "verify_attempt_started",
"observed_at": "2026-09-16T00:04:58.620710+00:00",
"actions": [
{
"action": "apply",
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
"exit_code": 0,
"limits": {
"token_ttl": 900,
"token_max_ttl": 1800,
"secret_id_ttl": 900,
"secret_id_num_uses": 1,
"token_num_uses": 8
}
}
],
"health_before": {
"deployment": [
{
"namespace": "activity-core",
"name": "llm-connect",
"ready": 1
}
],
"externalsecret": [
{
"namespace": "activity-core",
"name": "llm-connect-provider-secrets",
"ready": true
}
]
},
"failure_type": "ValueError",
"failure_location": "/home/worsch/railiance-platform/scripts/t03-native-execution.py:25",
"failure_code": "revoked_token_still_usable",
"owner_forwards_closed": true
}

View file

@ -0,0 +1,381 @@
{
"task": "SECRETS-WP-0010-T03",
"status": "passed",
"scope": "Exact pinned read-only OpenRouter key-check recipient; no inference",
"initial_receipt": "2026-09-15-t03-native-execution.json",
"continuation_receipt": "2026-09-16-t03-resume-exec.json",
"reconciliation": "Initial supplemental revocation lookup fell back to admin helper after session token cleared; native verify itself passed. Continuation checked exact applied policy/role and consumed apply/verify state, tested the explicit revoked token (403), then consumed only exec.",
"native_evidence": [
{
"action": "apply",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "",
"detail": {
"approval_status": "pending",
"decision_ref": "CCR-2026-0003"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
"result": "attempt",
"stage": "prod",
"ts": "2026-09-16T00:05:08.084607+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "",
"detail": {},
"hub_delivery_requested": false,
"record_id": "443aeeaf-bae7-479d-a2d1-3d90ccd58594",
"related_record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:08.202043+00:00"
},
{
"action": "apply",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:dc57b3b9614aa15b",
"detail": {
"applied": [
"policy se-prod-openrouter-llm-connect",
"approle se-prod-openrouter-llm-connect -> [se-prod-openrouter-llm-connect]"
],
"approval_consume_idempotent": false,
"approval_consumed": true,
"approval_consumed_at": "2026-09-16T00:05:09+00:00",
"approval_human_control": true,
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
"approval_status": "approved",
"auth_provider": "env",
"authorization_decision_id": "decision:dc57b3b9614aa15b",
"authorization_expires_at": "2026-09-16T00:20:09+00:00",
"decision_id": "decision:dc57b3b9614aa15b",
"decision_ref": "CCR-2026-0003",
"request_digest": "sha256:c5c44adc715385640dffeb3305ff854fc69bd800929f8c31f93a536524089831",
"skipped": [
"kv-mount platform (externally managed; no mutation)"
],
"stance_authorized": true,
"stance_demo_exception": false,
"stance_failure_mode": "fail_closed",
"stance_stage": "prod"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
"result": "applied",
"stage": "prod",
"ts": "2026-09-16T00:05:09.827448+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:dc57b3b9614aa15b",
"detail": {},
"hub_delivery_requested": false,
"record_id": "783c71dc-d848-4511-bb52-a8d2f99f6048",
"related_record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:09.941648+00:00"
},
{
"action": "verify",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "",
"detail": {
"approval_status": "pending",
"decision_ref": "CCR-2026-0003",
"fields": [
"OPENROUTER_API_KEY"
],
"negative_requested": true,
"positive_requested": true
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
"result": "attempt",
"stage": "prod",
"ts": "2026-09-16T00:05:10.134582+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "",
"detail": {},
"hub_delivery_requested": false,
"record_id": "cbca0831-44f3-472a-99c5-e7033f59e450",
"related_record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:10.250783+00:00"
},
{
"action": "verify-check",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {
"field": "OPENROUTER_API_KEY",
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
"reason": "approved consumer can read lane field",
"role": "se-prod-openrouter-llm-connect",
"session": {
"established": true,
"revocation_attempted": true,
"revocation_succeeded": true,
"session_handle": "4c0eb1a18281"
}
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
"result": "positive:pass",
"stage": "prod",
"ts": "2026-09-16T00:05:12.330802+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {},
"hub_delivery_requested": false,
"record_id": "1e8511a0-1b43-4626-a04a-07084c026bd9",
"related_record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:12.450529+00:00"
},
{
"action": "verify-check",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
"reason": "unrelated token denied read"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
"result": "negative:pass",
"stage": "prod",
"ts": "2026-09-16T00:05:12.456767+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {},
"hub_delivery_requested": false,
"record_id": "3d203e9b-b441-4336-b18a-248cea35dde0",
"related_record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:12.559760+00:00"
},
{
"action": "verify",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {
"approval_consume_idempotent": false,
"approval_consumed": true,
"approval_consumed_at": "2026-09-16T00:05:11+00:00",
"approval_human_control": true,
"approval_id": "273d6882-6253-5dc9-ac54-544f92ef5e56",
"approval_status": "approved",
"auth_provider": "env",
"authorization_decision_id": "decision:b4fca706e4c55b9a",
"authorization_expires_at": "2026-09-16T00:20:11+00:00",
"check_count": 2,
"decision_id": "decision:b4fca706e4c55b9a",
"decision_ref": "CCR-2026-0003",
"fields": [
"OPENROUTER_API_KEY"
],
"negative_requested": true,
"positive_requested": true,
"request_digest": "sha256:a735896e9d208032ea08b073bcc819864b12116bdf60852fcdd2e54dad2e62bf",
"stance_authorized": true,
"stance_demo_exception": false,
"stance_failure_mode": "fail_closed",
"stance_stage": "prod"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
"result": "pass",
"stage": "prod",
"ts": "2026-09-16T00:05:12.565647+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:b4fca706e4c55b9a",
"detail": {},
"hub_delivery_requested": false,
"record_id": "0ddce2fc-b552-4d62-8c24-6c167ff3826d",
"related_record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:05:12.741772+00:00"
},
{
"action": "exec",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "",
"detail": {
"approval_status": "pending",
"command": "/usr/bin/python3.12",
"decision_ref": "CCR-2026-0003",
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
"field": "OPENROUTER_API_KEY",
"mode": "exec-env",
"session": {}
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
"result": "attempt",
"stage": "prod",
"ts": "2026-09-16T00:08:28.639246+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "",
"detail": {},
"hub_delivery_requested": false,
"record_id": "b14a7442-c26b-4368-a4a0-fc39cd902143",
"related_record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:08:28.752134+00:00"
},
{
"action": "exec",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"completeness_claimed": false,
"decision_id": "decision:82cec64febcf635f",
"detail": {
"approval_consume_idempotent": false,
"approval_consumed": true,
"approval_consumed_at": "2026-09-16T00:08:32+00:00",
"approval_human_control": true,
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
"approval_status": "approved",
"auth_provider": "env",
"authorization_decision_id": "decision:82cec64febcf635f",
"authorization_expires_at": "2026-09-16T00:23:31+00:00",
"command": "/usr/bin/python3.12",
"decision_id": "decision:82cec64febcf635f",
"decision_ref": "CCR-2026-0003",
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
"field": "OPENROUTER_API_KEY",
"mode": "exec-env",
"request_digest": "sha256:4082d2ccad78097a8be34ff0b0221ed2c4b6407fdbaf36e4a583927ae9acc820",
"session": {
"established": true,
"revocation_attempted": true,
"revocation_succeeded": true,
"session_handle": "6b9b4927b6ba"
},
"stance_authorized": true,
"stance_demo_exception": false,
"stance_failure_mode": "fail_closed",
"stance_stage": "prod"
},
"evidence_kind": "attributive",
"evidence_rule": "default-attributive",
"hub_delivery_requested": true,
"record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
"result": "exit-0",
"stage": "prod",
"ts": "2026-09-16T00:08:30.937892+00:00"
},
{
"action": "evidence-delivery",
"actor": "worsch",
"catalog_id": "openrouter-llm-connect",
"decision_id": "decision:82cec64febcf635f",
"detail": {},
"hub_delivery_requested": false,
"record_id": "6b1208b7-32fd-4245-b73b-d35968e3a960",
"related_record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
"result": "delivered",
"stage": "prod",
"ts": "2026-09-16T00:08:31.048605+00:00"
}
],
"clock_acceptance": {
"scope": "production authority acceptance",
"host": "railiance01",
"client": "Linux/WSL via SSH loopback",
"os_clocks_changed": false,
"samples": [
{
"width_ms": 132.40261,
"railiance_minus_local_midpoint_ms": 1334.507298,
"independent_host_cross_check": true
},
{
"width_ms": 127.548741,
"railiance_minus_local_midpoint_ms": 1391.968235,
"independent_host_cross_check": true
},
{
"width_ms": 126.412228,
"railiance_minus_local_midpoint_ms": 1445.070823,
"independent_host_cross_check": true
}
],
"wrong_kid_refused": true,
"epoch": "b1164ccb-a4c2-4cc8-adf8-1d5597de697b",
"kid": "railiance01-clock-20260915-v1",
"public_key_sha256": "bd583446b5ed61d086806b2a0c5aaf33a875b751e45599e75335d1f415be609a",
"trust_lifetime_seconds": 900
},
"residual_handoffs": [
"INFD-IN-0005",
"SECRETS-WP-0006-T05",
"SECRETS-WP-0006-T06",
"SECRETS-WP-0007-T04",
"SECRETS-WP-0007-T07",
"IR-WP-0005",
"IR-WP-0006"
],
"approval_state": "All three native claims inspected as consumed after completion",
"inference_performed": false,
"provider_key_rotated": false
}

View file

@ -0,0 +1,59 @@
{
"status": "passed",
"phase": "all_actions_completed",
"observed_at": "2026-09-16T00:08:21.161761+00:00",
"actions": [
{
"action": "exec",
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
"exit_code": 0,
"key_check": {
"http_status": 200,
"result": "authenticated"
}
}
],
"health_before": {
"deployment": [
{
"namespace": "activity-core",
"name": "llm-connect",
"ready": 1
}
],
"externalsecret": [
{
"namespace": "activity-core",
"name": "llm-connect-provider-secrets",
"ready": true
}
]
},
"prior_receipt": "2026-09-15-t03-native-execution.json",
"completed_actions_not_replayed": [
"apply",
"verify"
],
"supplemental_cleanup": {
"unrelated_path_denied": true,
"session_revocation_verified": true,
"revoked_token_lookup_status": 403
},
"health_after": {
"deployment": [
{
"namespace": "activity-core",
"name": "llm-connect",
"ready": 1
}
],
"externalsecret": [
{
"namespace": "activity-core",
"name": "llm-connect-provider-secrets",
"ready": true
}
]
},
"owner_forwards_closed": true
}

View file

@ -91,3 +91,15 @@ records the live binding. Attended apply/readback passed; scoped credential
delivery verification remains pending. Native requesting delivery verification remains pending. Native requesting
identity (`approval:create`) and Informed Decision human review are also needed; identity (`approval:create`) and Informed Decision human review are also needed;
do not reuse the withdrawn combined operator client or seed a production approval. do not reuse the withdrawn combined operator client or seed a production approval.
## Native acceptance completed — 2026-09-16
The sequence above has now passed for the exact pinned key-check recipient.
See `docs/evidence/2026-09-16-t03-completion.json` for native positive/negative
verification, three distinct consumed human approvals, OpenRouter HTTP 200,
revocation HTTP 403, application/ESO health and Railiance Clock admission.
The first supplemental revocation probe failed due to admin-helper fallback;
the retained continuation fixes that check without replaying apply or verify.
Future executions require new approvals. Trials and billing readiness remain
owned by IR-WP-0005/0006; general proxy retirement remains SECRETS-WP-0006-T06.

View file

@ -313,3 +313,18 @@ unchanged.
verification. verification.
- The two generic/non-owned routes are not mislabeled as secrets-engine lanes. - The two generic/non-owned routes are not mislabeled as secrets-engine lanes.
- No secret material is recorded in repository or coordination evidence. - No secret material is recorded in repository or coordination evidence.
### Native OpenRouter handoff from SECRETS-WP-0010 — 2026-09-16
SECRETS-WP-0010-T03 completed the exact read-only key-check recipient: native
apply and verify, distinct human-approved CAS consumption for all three actions,
OpenRouter GET /api/v1/key HTTP 200, unrelated identity/path denials, explicit
revoked-token HTTP 403, and unchanged llm-connect/ESO health. Evidence:
`docs/evidence/2026-09-16-t03-completion.json`. No inference was performed.
This supplies one lane's evidence; this workplan retains its existing broader
live adoption tasks. SECRETS-WP-0006-T05/T06 own other-lane acceptance and
routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readiness.
Do not reuse the consumed approvals or treat the temporary key-check overlay as
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.

View file

@ -772,3 +772,18 @@ not transfer custody or authorization ownership into this repository.
native verification/cutover path; remaining lanes have explicit external native verification/cutover path; remaining lanes have explicit external
blockers rather than engine-safety blockers. blockers rather than engine-safety blockers.
- Service-mode design remains deferred until these guarantees are demonstrated. - Service-mode design remains deferred until these guarantees are demonstrated.
### Native OpenRouter handoff from SECRETS-WP-0010 — 2026-09-16
SECRETS-WP-0010-T03 completed the exact read-only key-check recipient: native
apply and verify, distinct human-approved CAS consumption for all three actions,
OpenRouter GET /api/v1/key HTTP 200, unrelated identity/path denials, explicit
revoked-token HTTP 403, and unchanged llm-connect/ESO health. Evidence:
`docs/evidence/2026-09-16-t03-completion.json`. No inference was performed.
This supplies one lane's evidence; this workplan retains its existing broader
live adoption tasks. SECRETS-WP-0006-T05/T06 own other-lane acceptance and
routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readiness.
Do not reuse the consumed approvals or treat the temporary key-check overlay as
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.

View file

@ -4,7 +4,7 @@ type: workplan
title: "Native OpenRouter access for intelligence-radar" title: "Native OpenRouter access for intelligence-radar"
domain: infotech domain: infotech
repo: secrets-engine repo: secrets-engine
status: active status: finished
flavor: implementation flavor: implementation
owner: codex owner: codex
topic_slug: netkingdom topic_slug: netkingdom
@ -53,7 +53,7 @@ and bounded plan are review artifacts, not runtime grants.
```task ```task
id: SECRETS-WP-0010-T03 id: SECRETS-WP-0010-T03
status: wait status: done
priority: high priority: high
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405" state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"
``` ```
@ -260,3 +260,31 @@ T03 remains wait for the real human acknowledgements/acceptance and then native
apply, verify, consume, key check and revocation. No OpenRouter key was read or apply, verify, consume, key check and revocation. No OpenRouter key was read or
inference performed. Review expiry is 2026-09-16 22:28 UTC (September 17 00:28 inference performed. Review expiry is 2026-09-16 22:28 UTC (September 17 00:28
Europe/Berlin). Evidence: docs/evidence/2026-09-16-t03-renewed-review-handoff.json. Europe/Berlin). Evidence: docs/evidence/2026-09-16-t03-renewed-review-handoff.json.
### T03 completed with native delivery — 2026-09-16
All three renewed version-2 memos received real human acceptance. Native
claims/PDP checks and separate CAS consumption preceded apply, verify and exec.
The bounded policy/AppRole was applied; positive read and unrelated-reader
negative verification passed. The exact pinned recipient authenticated with
OpenRouter GET /api/v1/key (HTTP 200). Explicit revoked-token lookup returned
403, unrelated paths were denied, llm-connect and ESO remained ready, private
runtime storage was removed, and the final attended Warden procedure exited 0.
The initial procedure stopped after successful verify because a supplemental
probe used the admin helper after the scoped client cleared its token. The
failure receipt is retained. A guarded continuation revalidated the applied
objects and native consumption state, repaired the probe and executed only the
remaining approval. No consumed action was replayed. Four focused recovery
checks and frozen recipient/request preflight passed.
Canonical receipt: `docs/evidence/2026-09-16-t03-completion.json`; original
attempt and continuation are linked there. No provider key rotation, inference
or campaign billing reconciliation occurred. Existing general adoption/routing
work remains in SECRETS-WP-0006-T05/T06 and SECRETS-WP-0007-T04/T07 (handoff
notes added). IR-WP-0005 owns radar delivery acceptance, IR-WP-0006 the pending
USD 0.023712 reservation and USD 10 ceiling. Fresh-login reliability is the
live residual INFD-IN-0005. The three consumed approvals cannot authorize a
future key check or a different trial recipient. This closes the bounded T03
objective, not those broader work records.