Record SECRETS-WP-0009-T03 metered identity and host placement
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 226514@bnt-lap001 Assistant-Session: 26ba103d-05fe-45a1-9cd7-9475bf239df6
This commit is contained in:
parent
f7c12bedc8
commit
d06aea33bc
2 changed files with 27 additions and 0 deletions
|
|
@ -445,3 +445,25 @@ A provisioning script (SpendPolicy, `spend init`, request tables, mode-0600
|
|||
owner config under `~/hfact/owner`) validates in memory. Staging it on
|
||||
railiance01 was blocked by the harness classifier as a real-world transaction.
|
||||
It has not been run. No policy, ledger or owner config exists yet.
|
||||
|
||||
### 2026-09-23 metered identity and host placement
|
||||
|
||||
activity-core accepted a dedicated worker identity (ACTIVITY-WP-0039):
|
||||
`rein-aharness-metered@railiance01`. Its token is delivered by the companion
|
||||
lane `activity-core-metered-worker-token` (SECRETS-WP-0011). The operator chose
|
||||
to re-provision under that identity. The `~/hfact/owner` set (policy
|
||||
`f1e06b0b…`, owner config `5fa8ea21…`) is **superseded and unused**. Its ledger
|
||||
has no reservations, and no `exec_owner` pin will name it. The new set goes in
|
||||
`~/hfact/owner-metered` (same envelope, runtime, profile, grant, definition and
|
||||
target), provisioned by the operator. The owner must be launched with
|
||||
`AGENT_HARNESS_WORKER_ID=rein-aharness-metered@railiance01`.
|
||||
|
||||
Placement: the operator chose to run `secrets-engine exec` on railiance01, next
|
||||
to the pinned owner. The host checkout is at `f7c12be` (origin/forgejo) with a
|
||||
Python 3.12 venv. Preflights pass there: both lanes load, and a pending-owner
|
||||
exec refuses before approval or backend. From the host, OpenBao-active,
|
||||
approval-engine, `flex-auth-secrets-engine` and KeyCape answer. The PDP and
|
||||
approval URLs must be literal loopback or HTTPS (`decision_check.py:73`,
|
||||
`approval_auth.py:90`), so the attended session needs host-side
|
||||
`kubectl port-forward` to 127.0.0.1 for both. That is a session step, not a
|
||||
standing change.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue