Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Multi-lane exec-owner delivery"
domain: infotech
repo: secrets-engine
status: active
status: finished
flavor: implementation
owner: claude-code
topic_slug: netkingdom
@ -91,12 +91,15 @@ a throwaway OpenBao dev server.
```task
id: SECRETS-WP-0011-T04
status: wait
status: done
priority: high
blocking_reason: "Activity Core reports ACTIVITY-WP-0039 finished and metered identity authentication proved (2026-09-24). Remaining: admit the configured Glas owner, obtain exact per-lane approvals, and perform attended native apply/verify/delivery under SECRETS-WP-0009-T03."
state_hub_task_id: "cf465065-de7a-5d9c-bc80-fee16ffef70d"
```
Completed 2026-09-27: custody handoff received, companion cataloged and wired
into the configured Glas owner after fresh backend-free host verification.
Native activation remains in existing SECRETS-WP-0009-T03, as detailed below.
Request activity-core to move the worker token into OpenBao custody, synced to
`actcore-runtime-secret` by their existing `openbao-activity-core` store. Then
catalog a read lane for the metered owner and add it as the Glas lane's
@ -172,3 +175,27 @@ T04 remains wait for native lane activation with SECRETS-WP-0009-T03: current
owner admission/pins, exact per-lane approvals and attended apply/verify/exec.
The draft binds `rein-aharness-metered@railiance01` and `hfact-metered`, matching
the handoff. No production policy, role, catalog binding or credential changed.
## Catalog task and workplan completed — 2026-09-27
T04's stated work is custody coordination, the worker-token catalog entry and
adding that entry as the Glas owner's companion. All three are now complete.
Activity Core's 2026-09-24 handoff supplies the custody/identity return. The
configured binding is now in `catalog/glas-claude-agent-dev-anthropic.yaml`,
including the worker identity/label and a private spend-policy file pin.
A fresh backend-free check on railiance01 verified the installed owner with
`metered-once --check --no-hub` (dispatch disabled), and this checkout's exact
path/ownership/mode/hash checks passed for the executable, owner configuration,
spend policy and private working directory. Receipt:
`docs/evidence/2026-09-27-companion-catalog-readiness.json`.
The owner digest is `46ab4f3fab1c5996ee61c96061b90518d625ffb3fa0966c9bbf7550f422b884b`.
The previous wait reason conflated catalog completion with native activation.
That activation was already owned by SECRETS-WP-0009-T03 and stays there: exact
per-lane action approvals, scoped attended apply, positive/negative verification,
actual bounded delivery and session revocation. No new task is needed. This
workplan's completion claims the configured multi-lane contract, its tests and
catalog wiring, not production delivery. No credential was requested or read,
no queue row was claimed, and no provider request was made.