Enforce companion-only credential delivery and refresh activation handoff
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 7s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 15:58:53 +02:00
parent 303cbf652b
commit 5c6f2b319d
8 changed files with 150 additions and 24 deletions

View file

@ -37,23 +37,27 @@ approval, OpenBao access, provider authentication or production readiness.
## Activation requirements
The current engine's production stance refuses before opening the backend:
`production action 'exec' requires a durable access-engine decision record;
live production remains disabled`. This refusal was exercised with the proposed
catalog and service-jwt selection. No real value was requested.
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and
refuses exec before approval consumption or backend access. The earlier lack
of a served decision path is no longer the current activation blocker.
Activation depends on SECRETS-WP-0007-T04 (exact production actions) and
SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require
canonical validated DecisionEnvelope for each protected action, successful consume,
and exact scoped backend authority. This draft cannot authorize itself; an
operator browser token or unsafe-demo flag is not a runtime substitute.
The metered owner configuration and binding were prepared on 2026-09-23.
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
separate `rein-aharness-metered@railiance01` identity are live. See the exact
handoff in SECRETS-WP-0011. Its worker token is companion-only; direct exec of
`activity-core-metered-worker-token` is refused. The intended recipient is the
metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
not the historical sandbox helper above.
Once those services exist: obtain the reviewed apply authorization, apply this
exact policy/AppRole with scoped authority, verify positive read and denied
metadata/sibling/write access without exposing values, and record delivery-ready
state. Bind approved exec authorization and named engine service authentication
to the sand-boxer owner route. Prove actual provider authentication and a bounded
Glas task, then activate routing and only the validated profile.
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
activation. Review the draft binding, revalidate installed files and private
state, configure the approved owner, and obtain exact per-action/per-lane
approvals. Apply the scoped policy/AppRole, verify positive read and denied
metadata/sibling/write access with an unrelated negative identity, then prove
bounded owner delivery and session revocation. Both lanes must independently
pass approval, PDP, consume and delivery readiness. The handoff and draft are
not runtime authorization. No production activation was performed in this review.
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
predecessor at Anthropic and prove denial. Bao session expiration does not revoke