id: activity-core-metered-worker-token kind: kv org: coulomb repo: activity-core stage: prod description: Activity Core queue token for rein-aharness-metered@railiance01, delivered only as a companion of the Glas metered owner. Custody and issuance are activity-core's (ACTIVITY-WP-0039); secrets-engine only reads. mount: platform path: workloads/activity-core/ops-run-workers/rein-aharness-metered-railiance01 mount_management: existing fields: - token consumers: - name: rein-aharness-metered-railiance01 auth: approle claim: catalog:activity-core-metered-worker-token purpose: Claim the admitted hfact-metered ops_run as rein-aharness-metered@railiance01 inside the catalog-bound Glas metered owner workload_delivery: [] delivery_config: companion_of: - glas-claude-agent-dev-anthropic delivery_modes: - exec-env delivery_auth: method: approle management: engine policy_name: se-prod-activity-core-metered-worker-token role_name: se-prod-activity-core-metered-worker-token metadata_read: false token_ttl: 5m token_max_ttl: 15m secret_id_ttl: 5m secret_id_num_uses: 1 token_num_uses: 8 approval: model: decision decision_ref: ACTIVITY-WP-0039 notes: Ordinary lane approval, no human control (operator decision 2026-09-23, SECRETS-WP-0011). Native apply and exec still need per-lane claim, PDP decision and consume. This entry is not authorization. verification: positive: Exact scoped AppRole reads only token, delivered as ACTIVITY_CORE_WORKER_TOKEN into the bound Glas metered owner. negative: The claim-loop worker path, sibling KV, metadata, listing and writes denied; the Glas lane AppRole cannot read this path. risk: classification: standard notes: Lets the holder claim, heartbeat and close ops_runs as the metered identity only. No provider spend by itself. rotation: owner: activity-core expectation: Mint a new value at the same path via ACTIVITY-WP-0039 procedure; ESO resyncs actcore-runtime-secret; next exec reads the new value. ttl: owner-defined deactivation: owner: activity-core expectation: Remove the identity from ACTIVITY_CORE_WORKERS and the path; revoke the se-prod AppRole and policy. audit: evidence: Lane id, companion primary, actor, exact path, field name, timestamps, and pass/fail only