Record applied approval-client operator binding for T03
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 01:30:23 +02:00
parent 79e92d923f
commit 95e4a31892
2 changed files with 11 additions and 4 deletions

View file

@ -86,6 +86,8 @@ state their scope and cleanup. This removes the outdated PDP image dependency.
The finalized request artifacts are `docs/evidence/2026-09-14-openrouter-final-*-request.json`. The finalized request artifacts are `docs/evidence/2026-09-14-openrouter-final-*-request.json`.
They replace the earlier pending-recipient proposal as review inputs, not as an They replace the earlier pending-recipient proposal as review inputs, not as an
issued approval. Recipient proof is in `2026-09-14-openrouter-recipient-install.json`. issued approval. Recipient proof is in `2026-09-14-openrouter-recipient-install.json`.
The exact operator-group question is pending user input. Native requesting The operator confirmed `net-kingdom-admins` on 2026-09-14; CCR-2026-0019 now
records the live binding. Attended apply/readback passed; scoped credential
delivery verification remains pending. Native requesting
identity (`approval:create`) and Informed Decision human review are also needed; identity (`approval:create`) and Informed Decision human review are also needed;
do not reuse the withdrawn combined operator client or seed a production approval. do not reuse the withdrawn combined operator client or seed a production approval.

View file

@ -88,9 +88,14 @@ Runtime trust is the system-owned Python standard library plus pinned executable
and script. The install receipt and finalized apply/verify/exec request JSONs are and script. The install receipt and finalized apply/verify/exec request JSONs are
under docs/evidence. No provider request or credential read was made. under docs/evidence. No provider request or credential read was made.
Current wait: user input naming the exact authorized KeyCape operator group for Operator input received, 2026-09-14: the user explicitly selected
CCR-2026-0019 (asked during this continuation; not inferred from unrelated admin `net-kingdom-admins` for CCR-2026-0019. The platform source now records that
roles). Then complete the scoped OIDC reader and admitted native delivery. binding and the approved metadata apply. The guarded applier requires role
`secrets-engine-approval-client-workload-kv-read`; its dry run passes.
Attended apply/readback passed: exact group, policy and 900-second TTL verified.
Warden completed its contained session successfully. Platform receipt:
`docs/evidence/2026-09-14-ccr0019-operator-binding.json`. Native scoped delivery
proof remains pending; no credential was read and the front door stays disabled.
A separately admitted approval:create requester and real human approver flow A separately admitted approval:create requester and real human approver flow
also remain necessary: the withdrawn approval-engine-operator convenience client also remain necessary: the withdrawn approval-engine-operator convenience client
must not be restored or used to create and approve its own requests. Informed must not be restored or used to create and approve its own requests. Informed