Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -1,7 +1,6 @@
# Draft exec_owner for glas-claude-agent-dev-anthropic (SECRETS-WP-0009-T03).
# Not in the catalog. Activity Core reports custody and identity live as of
# 2026-09-24 (ACTIVITY-WP-0039). Admission still requires current owner/pin
# validation and exact per-lane approvals for attended native activation.
# Configured binding promoted to catalog/glas-claude-agent-dev-anthropic.yaml
# on 2026-09-27 after backend-free owner and path/pin validation.
# Configuration is not runtime approval; native activation is SECRETS-WP-0009-T03.
exec_owner:
status: configured
owner: rein-aharness MessagesOwner (metered-once) with sand-boxer runtime boundary
@ -24,8 +23,8 @@ exec_owner:
AGENT_HARNESS_OPS_LABELS: hfact-metered
AGENT_HARNESS_OPS_LABELS_MODE: all
AGENT_HARNESS_EXECUTION_PROJECT: prj-helixforge-factory
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: "1"
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: "1"
AGENT_HARNESS_REQUIRE_SPEND_ADMISSION: '1'
AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION: '1'
AGENT_HARNESS_SPEND_POLICY: /home/tegwick/hfact/owner-metered/spend-policy.json
AGENT_HARNESS_SPEND_LEDGER: /home/tegwick/hfact/owner-metered/spend.sqlite3
AGENT_HARNESS_REPO_MAP: '{"hfact-glas-proof":"/home/tegwick/hfact/targets/hfact-glas-proof"}'
@ -36,6 +35,9 @@ exec_owner:
/home/tegwick/hfact/owner-metered/owner.json:
sha256: 0e263f8299a42f63caf3595ff3eb7adc10354673f7b5125e0811def3bea7c274
private: true
/home/tegwick/hfact/owner-metered/spend-policy.json:
sha256: f31c585916de1ea8bd8e48c72421803dfde1015e6201704b9320f77d2c545d9c
private: true
companions:
- catalog: activity-core-metered-worker-token
field: token