secrets-engine/docs/glas-claude-delivery.md
tegwick e33f9c3ca5
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
Finish companion catalog work and reconcile completed approval tasks
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
2026-09-27 16:15:01 +02:00

4 KiB

Glas Claude exec delivery

Proposed native lane glas-claude-agent-dev-anthropic, provenance railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-0009. KV custody is already confirmed at version 2. Do not provision or rotate it as part of native read-lane adoption.

2026-09-10: the factory continuation uses a metered MessagesOwner outside the sandbox. Its exact runtime is installed and synthetically proved on Railiance. That initial pending binding has since been replaced by the pinned configuration reviewed on 2026-09-27; native activation remains separate. See exec owner binding. The older transport description below records the original child-key route; it cannot admit the metered holder.

The generated plan checks existing mount platform, creates policy and AppRole se-prod-glas-claude-agent-dev-anthropic, and grants read only on platform/data/workloads/glas-harness/claude-agent-dev. Field ANTHROPIC_API_KEY is selected by the exec adapter; KV policies scope entries, not fields. delivery_auth.metadata_read: false excludes the metadata endpoint; existing lanes retain their previous metadata access by default. Token TTL 5m, maximum 15m, SecretID TTL 5m and single use, token use budget 8. No wildcard, listing, workload writes, mount mutation, provider creation or default-policy change is included in this plan. Verify effective token identity policies at activation.

Sand-boxer's owner-configured credential route binds profile, project, actor and nonempty run id before invoking secrets-engine's exec-env interface. The provider injects the key into a private host helper that directly forwards it to the namespace broker. The broker injects only ANTHROPIC_API_KEY into the command and redacts exact values before truncating output. No OpenBao token crosses into the sandbox; no key is returned through Glas's API. Values are available to the trusted workload and descendants; encoding/exfiltration by hostile workload code is not prevented by an output redactor. Existing sandbox, egress, artifact verification and profile admission boundaries remain required.

A synthetic provider proves the transport only. It does not stand in for native approval, OpenBao access, provider authentication or production readiness.

Activation requirements

As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from SECRETS-WP-0010-T03. The Glas catalog now has a configured owner binding and worker companion, verified by backend-free checks on railiance01. It refuses substituted children and still requires fresh exact approvals and verified delivery state. The earlier lack of a served decision path is no longer the current activation blocker.

The metered owner configuration and binding were prepared on 2026-09-23. Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the separate rein-aharness-metered@railiance01 identity are live. See the exact handoff in SECRETS-WP-0011. Its worker token is companion-only; direct exec of activity-core-metered-worker-token is refused. The intended recipient is the metered MessagesOwner described in exec owner binding, not the historical sandbox helper above.

SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended activation. Revalidate the configured binding, installed files and private state in the execution window, and obtain exact per-action/per-lane approvals. Apply the scoped policy/AppRole, verify positive read and denied metadata/sibling/write access with an unrelated negative identity, then prove bounded owner delivery and session revocation. Both lanes must independently pass approval, PDP, consume and delivery readiness. The handoff and catalog configuration are not runtime authorization. No production activation was performed in this review.

Rotation: store replacement with CAS, stop old runs, verify replacement, revoke predecessor at Anthropic and prove denial. Bao session expiration does not revoke the provider key. Compromise disables the provider key and affected runs first.