Complete T03 with native OpenRouter authentication evidence
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
parent
ec7263dc3f
commit
4a8ea4f591
7 changed files with 551 additions and 2 deletions
39
docs/evidence/2026-09-15-t03-native-execution.json
Normal file
39
docs/evidence/2026-09-15-t03-native-execution.json
Normal file
|
|
@ -0,0 +1,39 @@
|
||||||
|
{
|
||||||
|
"status": "failed",
|
||||||
|
"phase": "verify_attempt_started",
|
||||||
|
"observed_at": "2026-09-16T00:04:58.620710+00:00",
|
||||||
|
"actions": [
|
||||||
|
{
|
||||||
|
"action": "apply",
|
||||||
|
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
|
||||||
|
"exit_code": 0,
|
||||||
|
"limits": {
|
||||||
|
"token_ttl": 900,
|
||||||
|
"token_max_ttl": 1800,
|
||||||
|
"secret_id_ttl": 900,
|
||||||
|
"secret_id_num_uses": 1,
|
||||||
|
"token_num_uses": 8
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"health_before": {
|
||||||
|
"deployment": [
|
||||||
|
{
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"name": "llm-connect",
|
||||||
|
"ready": 1
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"externalsecret": [
|
||||||
|
{
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"name": "llm-connect-provider-secrets",
|
||||||
|
"ready": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"failure_type": "ValueError",
|
||||||
|
"failure_location": "/home/worsch/railiance-platform/scripts/t03-native-execution.py:25",
|
||||||
|
"failure_code": "revoked_token_still_usable",
|
||||||
|
"owner_forwards_closed": true
|
||||||
|
}
|
||||||
381
docs/evidence/2026-09-16-t03-completion.json
Normal file
381
docs/evidence/2026-09-16-t03-completion.json
Normal file
|
|
@ -0,0 +1,381 @@
|
||||||
|
{
|
||||||
|
"task": "SECRETS-WP-0010-T03",
|
||||||
|
"status": "passed",
|
||||||
|
"scope": "Exact pinned read-only OpenRouter key-check recipient; no inference",
|
||||||
|
"initial_receipt": "2026-09-15-t03-native-execution.json",
|
||||||
|
"continuation_receipt": "2026-09-16-t03-resume-exec.json",
|
||||||
|
"reconciliation": "Initial supplemental revocation lookup fell back to admin helper after session token cleared; native verify itself passed. Continuation checked exact applied policy/role and consumed apply/verify state, tested the explicit revoked token (403), then consumed only exec.",
|
||||||
|
"native_evidence": [
|
||||||
|
{
|
||||||
|
"action": "apply",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "",
|
||||||
|
"detail": {
|
||||||
|
"approval_status": "pending",
|
||||||
|
"decision_ref": "CCR-2026-0003"
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
|
||||||
|
"result": "attempt",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:08.084607+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "443aeeaf-bae7-479d-a2d1-3d90ccd58594",
|
||||||
|
"related_record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:08.202043+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "apply",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "decision:dc57b3b9614aa15b",
|
||||||
|
"detail": {
|
||||||
|
"applied": [
|
||||||
|
"policy se-prod-openrouter-llm-connect",
|
||||||
|
"approle se-prod-openrouter-llm-connect -> [se-prod-openrouter-llm-connect]"
|
||||||
|
],
|
||||||
|
"approval_consume_idempotent": false,
|
||||||
|
"approval_consumed": true,
|
||||||
|
"approval_consumed_at": "2026-09-16T00:05:09+00:00",
|
||||||
|
"approval_human_control": true,
|
||||||
|
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
|
||||||
|
"approval_status": "approved",
|
||||||
|
"auth_provider": "env",
|
||||||
|
"authorization_decision_id": "decision:dc57b3b9614aa15b",
|
||||||
|
"authorization_expires_at": "2026-09-16T00:20:09+00:00",
|
||||||
|
"decision_id": "decision:dc57b3b9614aa15b",
|
||||||
|
"decision_ref": "CCR-2026-0003",
|
||||||
|
"request_digest": "sha256:c5c44adc715385640dffeb3305ff854fc69bd800929f8c31f93a536524089831",
|
||||||
|
"skipped": [
|
||||||
|
"kv-mount platform (externally managed; no mutation)"
|
||||||
|
],
|
||||||
|
"stance_authorized": true,
|
||||||
|
"stance_demo_exception": false,
|
||||||
|
"stance_failure_mode": "fail_closed",
|
||||||
|
"stance_stage": "prod"
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
|
||||||
|
"result": "applied",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:09.827448+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "decision:dc57b3b9614aa15b",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "783c71dc-d848-4511-bb52-a8d2f99f6048",
|
||||||
|
"related_record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:09.941648+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "verify",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "",
|
||||||
|
"detail": {
|
||||||
|
"approval_status": "pending",
|
||||||
|
"decision_ref": "CCR-2026-0003",
|
||||||
|
"fields": [
|
||||||
|
"OPENROUTER_API_KEY"
|
||||||
|
],
|
||||||
|
"negative_requested": true,
|
||||||
|
"positive_requested": true
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
|
||||||
|
"result": "attempt",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:10.134582+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "cbca0831-44f3-472a-99c5-e7033f59e450",
|
||||||
|
"related_record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:10.250783+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "verify-check",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"detail": {
|
||||||
|
"field": "OPENROUTER_API_KEY",
|
||||||
|
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
|
||||||
|
"reason": "approved consumer can read lane field",
|
||||||
|
"role": "se-prod-openrouter-llm-connect",
|
||||||
|
"session": {
|
||||||
|
"established": true,
|
||||||
|
"revocation_attempted": true,
|
||||||
|
"revocation_succeeded": true,
|
||||||
|
"session_handle": "4c0eb1a18281"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
|
||||||
|
"result": "positive:pass",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:12.330802+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "1e8511a0-1b43-4626-a04a-07084c026bd9",
|
||||||
|
"related_record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:12.450529+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "verify-check",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"detail": {
|
||||||
|
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
|
||||||
|
"reason": "unrelated token denied read"
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
|
||||||
|
"result": "negative:pass",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:12.456767+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "3d203e9b-b441-4336-b18a-248cea35dde0",
|
||||||
|
"related_record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:12.559760+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "verify",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"detail": {
|
||||||
|
"approval_consume_idempotent": false,
|
||||||
|
"approval_consumed": true,
|
||||||
|
"approval_consumed_at": "2026-09-16T00:05:11+00:00",
|
||||||
|
"approval_human_control": true,
|
||||||
|
"approval_id": "273d6882-6253-5dc9-ac54-544f92ef5e56",
|
||||||
|
"approval_status": "approved",
|
||||||
|
"auth_provider": "env",
|
||||||
|
"authorization_decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"authorization_expires_at": "2026-09-16T00:20:11+00:00",
|
||||||
|
"check_count": 2,
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"decision_ref": "CCR-2026-0003",
|
||||||
|
"fields": [
|
||||||
|
"OPENROUTER_API_KEY"
|
||||||
|
],
|
||||||
|
"negative_requested": true,
|
||||||
|
"positive_requested": true,
|
||||||
|
"request_digest": "sha256:a735896e9d208032ea08b073bcc819864b12116bdf60852fcdd2e54dad2e62bf",
|
||||||
|
"stance_authorized": true,
|
||||||
|
"stance_demo_exception": false,
|
||||||
|
"stance_failure_mode": "fail_closed",
|
||||||
|
"stance_stage": "prod"
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
|
||||||
|
"result": "pass",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:12.565647+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "decision:b4fca706e4c55b9a",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "0ddce2fc-b552-4d62-8c24-6c167ff3826d",
|
||||||
|
"related_record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:05:12.741772+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "exec",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "",
|
||||||
|
"detail": {
|
||||||
|
"approval_status": "pending",
|
||||||
|
"command": "/usr/bin/python3.12",
|
||||||
|
"decision_ref": "CCR-2026-0003",
|
||||||
|
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
|
||||||
|
"field": "OPENROUTER_API_KEY",
|
||||||
|
"mode": "exec-env",
|
||||||
|
"session": {}
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
|
||||||
|
"result": "attempt",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:08:28.639246+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "b14a7442-c26b-4368-a4a0-fc39cd902143",
|
||||||
|
"related_record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:08:28.752134+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "exec",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"completeness_claimed": false,
|
||||||
|
"decision_id": "decision:82cec64febcf635f",
|
||||||
|
"detail": {
|
||||||
|
"approval_consume_idempotent": false,
|
||||||
|
"approval_consumed": true,
|
||||||
|
"approval_consumed_at": "2026-09-16T00:08:32+00:00",
|
||||||
|
"approval_human_control": true,
|
||||||
|
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
|
||||||
|
"approval_status": "approved",
|
||||||
|
"auth_provider": "env",
|
||||||
|
"authorization_decision_id": "decision:82cec64febcf635f",
|
||||||
|
"authorization_expires_at": "2026-09-16T00:23:31+00:00",
|
||||||
|
"command": "/usr/bin/python3.12",
|
||||||
|
"decision_id": "decision:82cec64febcf635f",
|
||||||
|
"decision_ref": "CCR-2026-0003",
|
||||||
|
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
|
||||||
|
"field": "OPENROUTER_API_KEY",
|
||||||
|
"mode": "exec-env",
|
||||||
|
"request_digest": "sha256:4082d2ccad78097a8be34ff0b0221ed2c4b6407fdbaf36e4a583927ae9acc820",
|
||||||
|
"session": {
|
||||||
|
"established": true,
|
||||||
|
"revocation_attempted": true,
|
||||||
|
"revocation_succeeded": true,
|
||||||
|
"session_handle": "6b9b4927b6ba"
|
||||||
|
},
|
||||||
|
"stance_authorized": true,
|
||||||
|
"stance_demo_exception": false,
|
||||||
|
"stance_failure_mode": "fail_closed",
|
||||||
|
"stance_stage": "prod"
|
||||||
|
},
|
||||||
|
"evidence_kind": "attributive",
|
||||||
|
"evidence_rule": "default-attributive",
|
||||||
|
"hub_delivery_requested": true,
|
||||||
|
"record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
|
||||||
|
"result": "exit-0",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:08:30.937892+00:00"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"action": "evidence-delivery",
|
||||||
|
"actor": "worsch",
|
||||||
|
"catalog_id": "openrouter-llm-connect",
|
||||||
|
"decision_id": "decision:82cec64febcf635f",
|
||||||
|
"detail": {},
|
||||||
|
"hub_delivery_requested": false,
|
||||||
|
"record_id": "6b1208b7-32fd-4245-b73b-d35968e3a960",
|
||||||
|
"related_record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
|
||||||
|
"result": "delivered",
|
||||||
|
"stage": "prod",
|
||||||
|
"ts": "2026-09-16T00:08:31.048605+00:00"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"clock_acceptance": {
|
||||||
|
"scope": "production authority acceptance",
|
||||||
|
"host": "railiance01",
|
||||||
|
"client": "Linux/WSL via SSH loopback",
|
||||||
|
"os_clocks_changed": false,
|
||||||
|
"samples": [
|
||||||
|
{
|
||||||
|
"width_ms": 132.40261,
|
||||||
|
"railiance_minus_local_midpoint_ms": 1334.507298,
|
||||||
|
"independent_host_cross_check": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"width_ms": 127.548741,
|
||||||
|
"railiance_minus_local_midpoint_ms": 1391.968235,
|
||||||
|
"independent_host_cross_check": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"width_ms": 126.412228,
|
||||||
|
"railiance_minus_local_midpoint_ms": 1445.070823,
|
||||||
|
"independent_host_cross_check": true
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"wrong_kid_refused": true,
|
||||||
|
"epoch": "b1164ccb-a4c2-4cc8-adf8-1d5597de697b",
|
||||||
|
"kid": "railiance01-clock-20260915-v1",
|
||||||
|
"public_key_sha256": "bd583446b5ed61d086806b2a0c5aaf33a875b751e45599e75335d1f415be609a",
|
||||||
|
"trust_lifetime_seconds": 900
|
||||||
|
},
|
||||||
|
"residual_handoffs": [
|
||||||
|
"INFD-IN-0005",
|
||||||
|
"SECRETS-WP-0006-T05",
|
||||||
|
"SECRETS-WP-0006-T06",
|
||||||
|
"SECRETS-WP-0007-T04",
|
||||||
|
"SECRETS-WP-0007-T07",
|
||||||
|
"IR-WP-0005",
|
||||||
|
"IR-WP-0006"
|
||||||
|
],
|
||||||
|
"approval_state": "All three native claims inspected as consumed after completion",
|
||||||
|
"inference_performed": false,
|
||||||
|
"provider_key_rotated": false
|
||||||
|
}
|
||||||
59
docs/evidence/2026-09-16-t03-resume-exec.json
Normal file
59
docs/evidence/2026-09-16-t03-resume-exec.json
Normal file
|
|
@ -0,0 +1,59 @@
|
||||||
|
{
|
||||||
|
"status": "passed",
|
||||||
|
"phase": "all_actions_completed",
|
||||||
|
"observed_at": "2026-09-16T00:08:21.161761+00:00",
|
||||||
|
"actions": [
|
||||||
|
{
|
||||||
|
"action": "exec",
|
||||||
|
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
|
||||||
|
"exit_code": 0,
|
||||||
|
"key_check": {
|
||||||
|
"http_status": 200,
|
||||||
|
"result": "authenticated"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"health_before": {
|
||||||
|
"deployment": [
|
||||||
|
{
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"name": "llm-connect",
|
||||||
|
"ready": 1
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"externalsecret": [
|
||||||
|
{
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"name": "llm-connect-provider-secrets",
|
||||||
|
"ready": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"prior_receipt": "2026-09-15-t03-native-execution.json",
|
||||||
|
"completed_actions_not_replayed": [
|
||||||
|
"apply",
|
||||||
|
"verify"
|
||||||
|
],
|
||||||
|
"supplemental_cleanup": {
|
||||||
|
"unrelated_path_denied": true,
|
||||||
|
"session_revocation_verified": true,
|
||||||
|
"revoked_token_lookup_status": 403
|
||||||
|
},
|
||||||
|
"health_after": {
|
||||||
|
"deployment": [
|
||||||
|
{
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"name": "llm-connect",
|
||||||
|
"ready": 1
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"externalsecret": [
|
||||||
|
{
|
||||||
|
"namespace": "activity-core",
|
||||||
|
"name": "llm-connect-provider-secrets",
|
||||||
|
"ready": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"owner_forwards_closed": true
|
||||||
|
}
|
||||||
|
|
@ -91,3 +91,15 @@ records the live binding. Attended apply/readback passed; scoped credential
|
||||||
delivery verification remains pending. Native requesting
|
delivery verification remains pending. Native requesting
|
||||||
identity (`approval:create`) and Informed Decision human review are also needed;
|
identity (`approval:create`) and Informed Decision human review are also needed;
|
||||||
do not reuse the withdrawn combined operator client or seed a production approval.
|
do not reuse the withdrawn combined operator client or seed a production approval.
|
||||||
|
|
||||||
|
|
||||||
|
## Native acceptance completed — 2026-09-16
|
||||||
|
|
||||||
|
The sequence above has now passed for the exact pinned key-check recipient.
|
||||||
|
See `docs/evidence/2026-09-16-t03-completion.json` for native positive/negative
|
||||||
|
verification, three distinct consumed human approvals, OpenRouter HTTP 200,
|
||||||
|
revocation HTTP 403, application/ESO health and Railiance Clock admission.
|
||||||
|
The first supplemental revocation probe failed due to admin-helper fallback;
|
||||||
|
the retained continuation fixes that check without replaying apply or verify.
|
||||||
|
Future executions require new approvals. Trials and billing readiness remain
|
||||||
|
owned by IR-WP-0005/0006; general proxy retirement remains SECRETS-WP-0006-T06.
|
||||||
|
|
|
||||||
|
|
@ -313,3 +313,18 @@ unchanged.
|
||||||
verification.
|
verification.
|
||||||
- The two generic/non-owned routes are not mislabeled as secrets-engine lanes.
|
- The two generic/non-owned routes are not mislabeled as secrets-engine lanes.
|
||||||
- No secret material is recorded in repository or coordination evidence.
|
- No secret material is recorded in repository or coordination evidence.
|
||||||
|
|
||||||
|
|
||||||
|
### Native OpenRouter handoff from SECRETS-WP-0010 — 2026-09-16
|
||||||
|
|
||||||
|
SECRETS-WP-0010-T03 completed the exact read-only key-check recipient: native
|
||||||
|
apply and verify, distinct human-approved CAS consumption for all three actions,
|
||||||
|
OpenRouter GET /api/v1/key HTTP 200, unrelated identity/path denials, explicit
|
||||||
|
revoked-token HTTP 403, and unchanged llm-connect/ESO health. Evidence:
|
||||||
|
`docs/evidence/2026-09-16-t03-completion.json`. No inference was performed.
|
||||||
|
This supplies one lane's evidence; this workplan retains its existing broader
|
||||||
|
live adoption tasks. SECRETS-WP-0006-T05/T06 own other-lane acceptance and
|
||||||
|
routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readiness.
|
||||||
|
Do not reuse the consumed approvals or treat the temporary key-check overlay as
|
||||||
|
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
|
||||||
|
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
|
||||||
|
|
|
||||||
|
|
@ -772,3 +772,18 @@ not transfer custody or authorization ownership into this repository.
|
||||||
native verification/cutover path; remaining lanes have explicit external
|
native verification/cutover path; remaining lanes have explicit external
|
||||||
blockers rather than engine-safety blockers.
|
blockers rather than engine-safety blockers.
|
||||||
- Service-mode design remains deferred until these guarantees are demonstrated.
|
- Service-mode design remains deferred until these guarantees are demonstrated.
|
||||||
|
|
||||||
|
|
||||||
|
### Native OpenRouter handoff from SECRETS-WP-0010 — 2026-09-16
|
||||||
|
|
||||||
|
SECRETS-WP-0010-T03 completed the exact read-only key-check recipient: native
|
||||||
|
apply and verify, distinct human-approved CAS consumption for all three actions,
|
||||||
|
OpenRouter GET /api/v1/key HTTP 200, unrelated identity/path denials, explicit
|
||||||
|
revoked-token HTTP 403, and unchanged llm-connect/ESO health. Evidence:
|
||||||
|
`docs/evidence/2026-09-16-t03-completion.json`. No inference was performed.
|
||||||
|
This supplies one lane's evidence; this workplan retains its existing broader
|
||||||
|
live adoption tasks. SECRETS-WP-0006-T05/T06 own other-lane acceptance and
|
||||||
|
routing/proxy retirement; SECRETS-WP-0007-T04/T07 retain general native readiness.
|
||||||
|
Do not reuse the consumed approvals or treat the temporary key-check overlay as
|
||||||
|
approval for a radar trial recipient. IR-WP-0005 owns radar delivery acceptance;
|
||||||
|
IR-WP-0006 owns the outstanding USD 0.023712 billing reservation.
|
||||||
|
|
|
||||||
|
|
@ -4,7 +4,7 @@ type: workplan
|
||||||
title: "Native OpenRouter access for intelligence-radar"
|
title: "Native OpenRouter access for intelligence-radar"
|
||||||
domain: infotech
|
domain: infotech
|
||||||
repo: secrets-engine
|
repo: secrets-engine
|
||||||
status: active
|
status: finished
|
||||||
flavor: implementation
|
flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
|
|
@ -53,7 +53,7 @@ and bounded plan are review artifacts, not runtime grants.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: SECRETS-WP-0010-T03
|
id: SECRETS-WP-0010-T03
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"
|
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"
|
||||||
```
|
```
|
||||||
|
|
@ -260,3 +260,31 @@ T03 remains wait for the real human acknowledgements/acceptance and then native
|
||||||
apply, verify, consume, key check and revocation. No OpenRouter key was read or
|
apply, verify, consume, key check and revocation. No OpenRouter key was read or
|
||||||
inference performed. Review expiry is 2026-09-16 22:28 UTC (September 17 00:28
|
inference performed. Review expiry is 2026-09-16 22:28 UTC (September 17 00:28
|
||||||
Europe/Berlin). Evidence: docs/evidence/2026-09-16-t03-renewed-review-handoff.json.
|
Europe/Berlin). Evidence: docs/evidence/2026-09-16-t03-renewed-review-handoff.json.
|
||||||
|
|
||||||
|
|
||||||
|
### T03 completed with native delivery — 2026-09-16
|
||||||
|
|
||||||
|
All three renewed version-2 memos received real human acceptance. Native
|
||||||
|
claims/PDP checks and separate CAS consumption preceded apply, verify and exec.
|
||||||
|
The bounded policy/AppRole was applied; positive read and unrelated-reader
|
||||||
|
negative verification passed. The exact pinned recipient authenticated with
|
||||||
|
OpenRouter GET /api/v1/key (HTTP 200). Explicit revoked-token lookup returned
|
||||||
|
403, unrelated paths were denied, llm-connect and ESO remained ready, private
|
||||||
|
runtime storage was removed, and the final attended Warden procedure exited 0.
|
||||||
|
|
||||||
|
The initial procedure stopped after successful verify because a supplemental
|
||||||
|
probe used the admin helper after the scoped client cleared its token. The
|
||||||
|
failure receipt is retained. A guarded continuation revalidated the applied
|
||||||
|
objects and native consumption state, repaired the probe and executed only the
|
||||||
|
remaining approval. No consumed action was replayed. Four focused recovery
|
||||||
|
checks and frozen recipient/request preflight passed.
|
||||||
|
|
||||||
|
Canonical receipt: `docs/evidence/2026-09-16-t03-completion.json`; original
|
||||||
|
attempt and continuation are linked there. No provider key rotation, inference
|
||||||
|
or campaign billing reconciliation occurred. Existing general adoption/routing
|
||||||
|
work remains in SECRETS-WP-0006-T05/T06 and SECRETS-WP-0007-T04/T07 (handoff
|
||||||
|
notes added). IR-WP-0005 owns radar delivery acceptance, IR-WP-0006 the pending
|
||||||
|
USD 0.023712 reservation and USD 10 ceiling. Fresh-login reliability is the
|
||||||
|
live residual INFD-IN-0005. The three consumed approvals cannot authorize a
|
||||||
|
future key check or a different trial recipient. This closes the bounded T03
|
||||||
|
objective, not those broader work records.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue