secrets-engine/docs/glas-claude-delivery.md
tegwick 5c6f2b319d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 7s
Enforce companion-only credential delivery and refresh activation handoff
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
2026-09-27 15:58:53 +02:00

3.9 KiB

Glas Claude exec delivery

Proposed native lane glas-claude-agent-dev-anthropic, provenance railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-0009. KV custody is already confirmed at version 2. Do not provision or rotate it as part of native read-lane adoption.

2026-09-10: the factory continuation uses a metered MessagesOwner outside the sandbox. Its exact runtime is installed and synthetically proved on Railiance. The catalog now blocks exec with an explicit pending recipient binding until the native holder and immutable configuration are admitted. See exec owner binding. The older transport description below records the original child-key route; it cannot admit the metered holder.

The generated plan checks existing mount platform, creates policy and AppRole se-prod-glas-claude-agent-dev-anthropic, and grants read only on platform/data/workloads/glas-harness/claude-agent-dev. Field ANTHROPIC_API_KEY is selected by the exec adapter; KV policies scope entries, not fields. delivery_auth.metadata_read: false excludes the metadata endpoint; existing lanes retain their previous metadata access by default. Token TTL 5m, maximum 15m, SecretID TTL 5m and single use, token use budget 8. No wildcard, listing, workload writes, mount mutation, provider creation or default-policy change is included in this plan. Verify effective token identity policies at activation.

Sand-boxer's owner-configured credential route binds profile, project, actor and nonempty run id before invoking secrets-engine's exec-env interface. The provider injects the key into a private host helper that directly forwards it to the namespace broker. The broker injects only ANTHROPIC_API_KEY into the command and redacts exact values before truncating output. No OpenBao token crosses into the sandbox; no key is returned through Glas's API. Values are available to the trusted workload and descendants; encoding/exfiltration by hostile workload code is not prevented by an output redactor. Existing sandbox, egress, artifact verification and profile admission boundaries remain required.

A synthetic provider proves the transport only. It does not stand in for native approval, OpenBao access, provider authentication or production readiness.

Activation requirements

As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from SECRETS-WP-0010-T03. The Glas catalog still has a pending owner binding and refuses exec before approval consumption or backend access. The earlier lack of a served decision path is no longer the current activation blocker.

The metered owner configuration and binding were prepared on 2026-09-23. Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the separate rein-aharness-metered@railiance01 identity are live. See the exact handoff in SECRETS-WP-0011. Its worker token is companion-only; direct exec of activity-core-metered-worker-token is refused. The intended recipient is the metered MessagesOwner described in exec owner binding, not the historical sandbox helper above.

SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended activation. Review the draft binding, revalidate installed files and private state, configure the approved owner, and obtain exact per-action/per-lane approvals. Apply the scoped policy/AppRole, verify positive read and denied metadata/sibling/write access with an unrelated negative identity, then prove bounded owner delivery and session revocation. Both lanes must independently pass approval, PDP, consume and delivery readiness. The handoff and draft are not runtime authorization. No production activation was performed in this review.

Rotation: store replacement with CAS, stop old runs, verify replacement, revoke predecessor at Anthropic and prove denial. Bao session expiration does not revoke the provider key. Compromise disables the provider key and affected runs first.