Bind native OpenRouter approval to custody and delivery inputs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 00:54:55 +02:00
parent 0783b50216
commit 7ba1b6223e
16 changed files with 656 additions and 7 deletions

View file

@ -710,9 +710,15 @@ priority: high
state_hub_task_id: "a0a1dd92-d703-5a95-b488-d895f34d5cf7"
```
Dependency: T01T03, T05, T06 are done. T04 still waits on the durable
ActionAuthorization serving path. Also requires explicit per-lane approvals
and scoped production authority from railiance-platform.
Dependency: T01T03, T05, T06 are done. T04 implements claim/PDP Check/CAS consume;
ActionAuthorization is deferred, not its serving prerequisite. Production still
waits on the admitted Approval Engine identity/audit/service and client-reader
path, explicit per-lane approval and scoped attended platform authority.
2026-09-14: SECRETS-WP-0010-T01/T02 implemented exact catalog-target binding and
the proposed value-safe OpenRouter recipient. FLEX-WP-0026 promoted the dedicated
PDP to revision 4 and verified the live replay join. Native admission/verification
remains SECRETS-WP-0010-T03; no real key was retrieved and this task remains wait.
Resume `SECRETS-WP-0006-T05` lane by lane. Apply only the exact native policy and
bounded AppRole, verify every field plus unrelated-consumer denial, confirm the

View file

@ -0,0 +1,68 @@
---
id: SECRETS-WP-0010
type: workplan
title: "Native OpenRouter access for intelligence-radar"
domain: infotech
repo: secrets-engine
status: blocked
owner: codex
topic_slug: netkingdom
created: "2026-09-14"
updated: "2026-09-14"
related_workplans:
- IR-WP-0004
- FLEX-WP-0026
- SECRETS-WP-0007
- SECRETS-WP-0006
---
Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f.
Implementation and execution procedure: `docs/openrouter-native-access.md`.
## Bind approval to actual native custody and delivery inputs
```task
id: SECRETS-WP-0010-T01
status: done
priority: high
```
Implemented context.catalog_target and complete plan limits. Changed paths,
mounts, owners and token limits refuse replay before consume/backend against
real local components. Existing exec-owner and human-control contracts retained.
410 repository tests and 26 component checks passed. Receipts in docs/evidence.
## Prepare value-safe first recipient and exact native plan
```task
id: SECRETS-WP-0010-T02
status: done
priority: high
```
Implemented the fixed read-only OpenRouter key-check script and synthetic tests.
Inactive proposed overlay declares human control and a pending exact recipient;
active llm-connect catalog admission is not broadened. Non-secret apply request
and bounded plan are review artifacts, not runtime grants.
## Admit and verify real native delivery
```task
id: SECRETS-WP-0010-T03
status: wait
priority: high
```
Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4,
11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05
(identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader
admission, exact installed recipient admission, real human approval/consume and
scoped attended platform authority. No Approval Engine StatefulSet/pod/Service
was present in its declared namespace at the 2026-09-14 inspection.
Then execute `docs/openrouter-native-access.md` steps: bounded native apply,
positive/negative checks, ESO/app health, value-safe key check and session revoke.
SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan
must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and
IR-WP-0004-T02 waiting until the native route passes. Trials require a separately
bound recipient and the existing campaign/budget reconciliation.