Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
3.2 KiB
Glas Claude exec delivery
Proposed native lane glas-claude-agent-dev-anthropic, provenance
railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-0009.
KV custody is already confirmed at version 2. Do not provision or rotate it as
part of native read-lane adoption.
The generated plan checks existing mount platform, creates policy and AppRole
se-prod-glas-claude-agent-dev-anthropic, and grants read only on
platform/data/workloads/glas-harness/claude-agent-dev. Field ANTHROPIC_API_KEY
is selected by the exec adapter; KV policies scope entries, not fields.
delivery_auth.metadata_read: false excludes the metadata endpoint; existing
lanes retain their previous metadata access by default. Token TTL 5m, maximum
15m, SecretID TTL 5m and single use, token use budget 8. No wildcard, listing,
workload writes, mount mutation, provider creation or default-policy change is
included in this plan. Verify effective token identity policies at activation.
Sand-boxer's owner-configured credential route binds profile, project, actor and nonempty run id before invoking secrets-engine's exec-env interface. The provider injects the key into a private host helper that directly forwards it to the namespace broker. The broker injects only ANTHROPIC_API_KEY into the command and redacts exact values before truncating output. No OpenBao token crosses into the sandbox; no key is returned through Glas's API. Values are available to the trusted workload and descendants; encoding/exfiltration by hostile workload code is not prevented by an output redactor. Existing sandbox, egress, artifact verification and profile admission boundaries remain required.
A synthetic provider proves the transport only. It does not stand in for native approval, OpenBao access, provider authentication or production readiness.
Activation requirements
The current engine's production stance refuses before opening the backend:
production action 'exec' requires a durable access-engine decision record; live production remains disabled. This refusal was exercised with the proposed
catalog and service-jwt selection. No real value was requested.
Activation depends on SECRETS-WP-0007-T04 (exact production actions) and SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require canonical ActionAuthorization for each protected action, successful consume, and exact scoped backend authority. This draft cannot authorize itself; an operator browser token or unsafe-demo flag is not a runtime substitute.
Once those services exist: obtain the reviewed apply authorization, apply this exact policy/AppRole with scoped authority, verify positive read and denied metadata/sibling/write access without exposing values, and record delivery-ready state. Bind approved exec authorization and named engine service authentication to the sand-boxer owner route. Prove actual provider authentication and a bounded Glas task, then activate routing and only the validated profile.
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke predecessor at Anthropic and prove denial. Bao session expiration does not revoke the provider key. Compromise disables the provider key and affected runs first.