secrets-engine/workplans/SECRETS-WP-0010-openrouter-native-access.md
tegwick 13ecd42077
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Record native T03 review deployment and remaining human gate
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 02:47:32 +02:00

166 lines
8.5 KiB
Markdown

---
id: SECRETS-WP-0010
type: workplan
title: "Native OpenRouter access for intelligence-radar"
domain: infotech
repo: secrets-engine
status: blocked
owner: codex
topic_slug: netkingdom
created: "2026-09-14"
updated: "2026-09-14"
related_workplans:
- IR-WP-0004
- FLEX-WP-0026
- SECRETS-WP-0007
- SECRETS-WP-0006
state_hub_workstream_id: "e1e68392-e7c4-50ab-91e4-4793e3591cac"
---
Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f.
Implementation and execution procedure: `docs/openrouter-native-access.md`.
## Bind approval to actual native custody and delivery inputs
```task
id: SECRETS-WP-0010-T01
status: done
priority: high
state_hub_task_id: "b315d0bd-63c5-530d-afde-b82973cee3a9"
```
Implemented context.catalog_target and complete plan limits. Changed paths,
mounts, owners and token limits refuse replay before consume/backend against
real local components. Existing exec-owner and human-control contracts retained.
410 repository tests and 26 component checks passed. Receipts in docs/evidence.
## Prepare value-safe first recipient and exact native plan
```task
id: SECRETS-WP-0010-T02
status: done
priority: high
state_hub_task_id: "564496a4-2ea9-51e5-9573-84003d955666"
```
Implemented the fixed read-only OpenRouter key-check script and synthetic tests.
Inactive proposed overlay declares human control and a pending exact recipient;
active llm-connect catalog admission is not broadened. Non-secret apply request
and bounded plan are review artifacts, not runtime grants.
## Admit and verify real native delivery
```task
id: SECRETS-WP-0010-T03
status: wait
priority: high
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"
```
Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4,
11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05
(identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader
admission, exact installed recipient admission, real human approval/consume and
scoped attended platform authority. No Approval Engine StatefulSet/pod/Service
was present in its declared namespace at the 2026-09-14 inspection.
Then execute `docs/openrouter-native-access.md` steps: bounded native apply,
positive/negative checks, ESO/app health, value-safe key check and session revoke.
SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan
must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and
IR-WP-0004-T02 waiting until the native route passes. Trials require a separately
bound recipient and the existing campaign/budget reconciliation.
### T03 continuation — 2026-09-14
User explicitly requested execution of T03. Completed the independently runnable
prerequisites: Approval Engine is now deployed and restart/backup/restore verified
(APPROVAL-WP-0002-T03 done). Existing audit sender custody/ESO and KeyCape
consumer registration were already complete; neither was reprovisioned. Live
JWKS/readiness/anonymous and invalid-bearer refusal plus durable heartbeat/outbox
checks pass. See `docs/evidence/2026-09-14-approval-engine-deployment.json`.
Installed the read-only checker in the owner-private versioned local directory,
using pinned `/usr/bin/python3.12 -I -B <script>`, fixed environment and private
runtime cwd. `docs/proposals/openrouter-key-check.yaml` now has a configured
recipient; it remains outside the active catalog and does not admit key use.
Runtime trust is the system-owned Python standard library plus pinned executable
and script. The install receipt and finalized apply/verify/exec request JSONs are
under docs/evidence. No provider request or credential read was made.
Operator input received, 2026-09-14: the user explicitly selected
`net-kingdom-admins` for CCR-2026-0019. The platform source now records that
binding and the approved metadata apply. The guarded applier requires role
`secrets-engine-approval-client-workload-kv-read`; its dry run passes.
Attended apply/readback passed: exact group, policy and 900-second TTL verified.
Warden completed its contained session successfully. Platform receipt:
`docs/evidence/2026-09-14-ccr0019-operator-binding.json`. Native scoped delivery
proof remains pending; no credential was read and the front door stays disabled.
A separately admitted approval:create requester and real human approver flow
also remain necessary: the withdrawn approval-engine-operator convenience client
must not be restored or used to create and approve its own requests. Informed
Decision's native review flow and requester admission are dependencies, not
replaced by a service token or a seeded live approval. T03 remains open until
real approval/consume, attended OpenBao apply, key check, positive/negative
native delivery and revocation are evidenced.
### Native reader acceptance — 2026-09-14
The scoped Warden login lane `secrets-engine-approval-client-login` now routes
to the applied OIDC reader and the platform's silent preflight. The installed
Warden package still carries an older catalog; use the explicit source catalog
`WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml`
until its next normal installation refresh. This lane authenticates the reader;
it is not a raw secret fetch or retained-file delivery interface.
Live effective-policy and capability checks passed: only exact data/metadata
read, no sibling secret, parent listing, write or control-plane authority.
A second contained session read existing version 1 into an operator-owned 0600
file in a private 0700 runtime tmpfs directory. The native consumer exchanged
separate read and consume scopes; Approval Engine verified the read token before
returning 404 for a fresh nonexistent approval, and refused the consume-only
token's read request with 403. No approval was created, bound or consumed.
Both Warden sessions exited 0 after self-revocation/helper cleanup; temporary
credential file and directory were removed. Four refusal/path/redirect tests
pass. Receipts are in platform `docs/evidence/2026-09-14-ccr0019-{reader-preflight,delivery-check}.json`.
Remaining: an actual nonmember login refusal, real approval claim/consume,
separate narrow requester admission and deployed Informed Decision review with
an explicitly admitted human mandate. The reader group alone grants no review
mandate. T03 and CCR delivery activation remain open; no OpenRouter key was read.
### T03 scoped review deployment — 2026-09-14
The operator explicitly admitted `net-kingdom-admins` as the human review group
for only the T03 apply, verify and read-only key-check records, separately from
its credential-reader membership. The review service is live and ready at
https://decisions.coulomb.social with verified KeyCape groups, fresh MFA and a
dedicated caller-bound Flex Auth policy. Its mandate does not grant consumption.
The new `secrets-engine-requester` client has subject `secrets-engine`, tenant
`tenant:platform`, role `secrets-engine-requester`, and only `approval:create`.
CCR-2026-0024 and CCR-2026-0025 provide distinct verifier and attended reader
custody. Native signature, subject, scope and TTL checks passed; excess scopes
and a wrong secret were refused. Existing consumer identity is unchanged.
Three real requested approvals were created with human control, required count
one, and zero entries. Platform evidence is
`docs/evidence/2026-09-14-t03-native-approval-requests.json`.
Review image: sha256:8f55bcecf37a8d65f96e073510b1ffb4636c0a91d75e1ee7d582ad4bce8b953a.
Policy image: sha256:c9f028b49dfcede930a9cc48757ec8371ecc71d20b1bfee2733e55298dffcc7c.
Review tests: 339 passed, 39 optional integration tests skipped; 11 container
checks and HIGH/CRITICAL image scan passed. Policy checks: 57 local and 6 native
caller checks passed, using synthetic subjects, not human binding evidence.
Approval Engine CPU request was reduced from 25m to 10m after observing 1m use;
review requests 20m and its PDP 5m. Limits are unchanged. Native services ready.
Remaining T03 gate: the operator's exact signed-in account is needed to address
three prepared immutable memos, followed by real acknowledgements and acceptance
in Informed Decision. No human entry or consume has been generated by an agent.
Then execute claim -> validated PDP Check -> CAS consume separately for apply,
verify and exec using scoped attended authority, and capture native denial,
revocation, workload health and key-check evidence. No OpenRouter credential has
been read and no inference or spend was performed. T03 remains waiting; this
entry supersedes earlier statements that requester or group admission is missing.