Preserve accepted budget renewal candidate and native action bindings
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
tegwick 2026-09-27 20:34:53 +02:00
parent 0b49b7e82f
commit 97cde1740d
7 changed files with 2663 additions and 0 deletions

View file

@ -0,0 +1,63 @@
id: activity-core-metered-worker-token
kind: kv
org: coulomb
repo: activity-core
stage: prod
description: Activity Core queue token for rein-aharness-metered@railiance01,
delivered only as a companion of the Glas metered owner. Custody and issuance
are activity-core's (ACTIVITY-WP-0039); secrets-engine only reads.
mount: platform
path: workloads/activity-core/ops-run-workers/rein-aharness-metered-railiance01
mount_management: existing
fields:
- token
consumers:
- name: rein-aharness-metered-railiance01
auth: approle
claim: catalog:activity-core-metered-worker-token
purpose: Claim the admitted hfact-metered ops_run as rein-aharness-metered@railiance01
inside the catalog-bound Glas metered owner
workload_delivery: []
delivery_config:
companion_of:
- glas-claude-agent-dev-anthropic
delivery_modes:
- exec-env
delivery_auth:
method: approle
management: engine
policy_name: se-prod-activity-core-metered-worker-token
role_name: se-prod-activity-core-metered-worker-token
metadata_read: false
token_ttl: 5m
token_max_ttl: 15m
secret_id_ttl: 5m
secret_id_num_uses: 1
token_num_uses: 8
approval:
model: decision
decision_ref: ACTIVITY-WP-0039
notes: Ordinary lane approval, no human control (operator decision 2026-09-23,
SECRETS-WP-0011). Native apply and exec still need per-lane claim, PDP decision
and consume. This entry is not authorization.
verification:
positive: Exact scoped AppRole reads only token, delivered as ACTIVITY_CORE_WORKER_TOKEN
into the bound Glas metered owner.
negative: The claim-loop worker path, sibling KV, metadata, listing and writes denied;
the Glas lane AppRole cannot read this path.
risk:
classification: standard
notes: Lets the holder claim, heartbeat and close ops_runs as the metered identity
only. No provider spend by itself.
rotation:
owner: activity-core
expectation: Mint a new value at the same path via ACTIVITY-WP-0039 procedure; ESO
resyncs actcore-runtime-secret; next exec reads the new value.
ttl: owner-defined
deactivation:
owner: activity-core
expectation: Remove the identity from ACTIVITY_CORE_WORKERS and the path; revoke
the se-prod AppRole and policy.
audit:
evidence: Lane id, companion primary, actor, exact path, field name, timestamps,
and pass/fail only

View file

@ -0,0 +1,104 @@
id: glas-claude-agent-dev-anthropic
kind: kv
org: coulomb
repo: sand-boxer
stage: prod
description: Catalog-bound metered owner with Activity Core worker-token companion.
The 2026-09-27 corrected owner pin requires reviewed host installation; the old
200k/32k owner is not admitted by this catalog. Native activation remains SECRETS-WP-0009-T03.
mount: platform
path: workloads/glas-harness/claude-agent-dev
mount_management: existing
fields:
- ANTHROPIC_API_KEY
consumers:
- name: sand-boxer-glas-agent-dev
auth: approle
claim: catalog:glas-claude-agent-dev-anthropic
purpose: Owner-admitted glas-harness agt run through the reviewed local profile;
no caller-facing key fetch
workload_delivery: []
delivery_config:
exec_owner:
status: configured
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
command:
- /home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3
- -I
- -B
- -m
- rein_aharness.cli
- metered-once
- --owner-config
- /home/tegwick/hfact/owner-metered/owner.json
cwd: /home/tegwick/hfact/owner-metered
environment:
PATH: /usr/bin:/bin
LANG: C.UTF-8
HOME: /home/tegwick
ACTIVITY_CORE_URL: http://127.0.0.1:8010
AGENT_HARNESS_WORKER_ID: rein-aharness-metered@railiance01
AGENT_HARNESS_OPS_LABELS: hfact-metered
AGENT_HARNESS_OPS_LABELS_MODE: all
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend-tool-proof-renewal-20260927.sqlite3
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
files:
/home/tegwick/.helixforge-factory/runtimes/b6e4e8a429393d68831c996a65c0489664205df969ac9882e581983ec2da4969/bin/python3:
sha256: e50d468e8b0adfb05733f5b87b3cff34829c4a8c1aea50c865aa8bdfe4bb150f
private: false
/home/tegwick/hfact/owner-metered/owner.json:
sha256: fed3f80fb451b742bf306e89b6800a742db5cf75d1a6e2ed5556ee204597b9db
private: true
/home/tegwick/hfact/owner-metered/spend-policy.json:
sha256: 69ea0071d2cc4311895b1df16039438f7bbc9f6dd3c797af05d4bc845d7afde2
private: true
companions:
- catalog: activity-core-metered-worker-token
field: token
env: ACTIVITY_CORE_WORKER_TOKEN
delivery_modes:
- exec-env
- read-check
delivery_auth:
method: approle
management: engine
policy_name: se-prod-glas-claude-agent-dev-anthropic
role_name: se-prod-glas-claude-agent-dev-anthropic
metadata_read: false
token_ttl: 5m
token_max_ttl: 15m
secret_id_ttl: 5m
secret_id_num_uses: 1
token_num_uses: 8
approval:
model: ccr
human_control: true
decision_ref: CCR-2026-0016
notes: Custody only has been completed. Native apply and exec require durable exact-action
authorization, engine consume, scoped backend authority and verified delivery
state. This entry is not authorization.
verification:
positive: Exact scoped AppRole reads only ANTHROPIC_API_KEY into the approved child;
owner binding and redaction pass.
negative: Wrong owner profile/project/actor, direct caller fetch, sibling KV, metadata,
listing and writes denied.
risk:
classification: high
notes: API spend; provider expiry 2027-01-31T21:00:00Z is not enforced by Bao token
TTL. Workspace scope and budget unverified.
rotation:
owner: railiance-platform + sand-boxer
expectation: Provider replacement, versioned CAS custody, stop old runs, verify
replacement then revoke predecessor at Anthropic and prove denial.
ttl: provider-defined
deactivation:
owner: railiance-platform + sand-boxer
expectation: Disable lane, stop affected runs, revoke Bao sessions and provider
key. Preserve custody history.
audit:
evidence: CCR id, actor, exact path, field name, provider key identifier if non-secret,
timestamps, and pass/fail only