Enforce companion-only credential delivery and refresh activation handoff
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
303cbf652b
commit
5c6f2b319d
8 changed files with 150 additions and 24 deletions
|
|
@ -37,23 +37,27 @@ approval, OpenBao access, provider authentication or production readiness.
|
|||
|
||||
## Activation requirements
|
||||
|
||||
The current engine's production stance refuses before opening the backend:
|
||||
`production action 'exec' requires a durable access-engine decision record;
|
||||
live production remains disabled`. This refusal was exercised with the proposed
|
||||
catalog and service-jwt selection. No real value was requested.
|
||||
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
|
||||
SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and
|
||||
refuses exec before approval consumption or backend access. The earlier lack
|
||||
of a served decision path is no longer the current activation blocker.
|
||||
|
||||
Activation depends on SECRETS-WP-0007-T04 (exact production actions) and
|
||||
SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require
|
||||
canonical validated DecisionEnvelope for each protected action, successful consume,
|
||||
and exact scoped backend authority. This draft cannot authorize itself; an
|
||||
operator browser token or unsafe-demo flag is not a runtime substitute.
|
||||
The metered owner configuration and binding were prepared on 2026-09-23.
|
||||
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
|
||||
separate `rein-aharness-metered@railiance01` identity are live. See the exact
|
||||
handoff in SECRETS-WP-0011. Its worker token is companion-only; direct exec of
|
||||
`activity-core-metered-worker-token` is refused. The intended recipient is the
|
||||
metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
|
||||
not the historical sandbox helper above.
|
||||
|
||||
Once those services exist: obtain the reviewed apply authorization, apply this
|
||||
exact policy/AppRole with scoped authority, verify positive read and denied
|
||||
metadata/sibling/write access without exposing values, and record delivery-ready
|
||||
state. Bind approved exec authorization and named engine service authentication
|
||||
to the sand-boxer owner route. Prove actual provider authentication and a bounded
|
||||
Glas task, then activate routing and only the validated profile.
|
||||
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
|
||||
activation. Review the draft binding, revalidate installed files and private
|
||||
state, configure the approved owner, and obtain exact per-action/per-lane
|
||||
approvals. Apply the scoped policy/AppRole, verify positive read and denied
|
||||
metadata/sibling/write access with an unrelated negative identity, then prove
|
||||
bounded owner delivery and session revocation. Both lanes must independently
|
||||
pass approval, PDP, consume and delivery readiness. The handoff and draft are
|
||||
not runtime authorization. No production activation was performed in this review.
|
||||
|
||||
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
|
||||
predecessor at Anthropic and prove denial. Bao session expiration does not revoke
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue