secrets-engine/docs/glas-claude-delivery.md
tegwick 11cc0d5452
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Correct metered Sonnet 5 admission and prepare native action packet
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e332-3365-77c0-8491-084e9ea33ac1
2026-09-27 17:00:33 +02:00

74 lines
4.5 KiB
Markdown

# Glas Claude exec delivery
Proposed native lane `glas-claude-agent-dev-anthropic`, provenance
railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-0009.
KV custody is already confirmed at version 2. Do not provision or rotate it as
part of native read-lane adoption.
2026-09-10: the factory continuation uses a metered MessagesOwner outside the
sandbox. Its exact runtime is installed and synthetically proved on Railiance.
That initial pending binding has since been replaced by the pinned configuration
reviewed on 2026-09-27; native activation remains separate. See
[exec owner binding](exec-owner-binding.md). The older transport description
below records the original child-key route; it cannot admit the metered holder.
The generated plan checks existing mount `platform`, creates policy and AppRole
`se-prod-glas-claude-agent-dev-anthropic`, and grants read only on
`platform/data/workloads/glas-harness/claude-agent-dev`. Field ANTHROPIC_API_KEY
is selected by the exec adapter; KV policies scope entries, not fields.
`delivery_auth.metadata_read: false` excludes the metadata endpoint; existing
lanes retain their previous metadata access by default. Token TTL 5m, maximum
15m, SecretID TTL 5m and single use, token use budget 8. No wildcard, listing,
workload writes, mount mutation, provider creation or default-policy change is
included in this plan. Verify effective token identity policies at activation.
Sand-boxer's owner-configured credential route binds profile, project, actor and
nonempty run id before invoking secrets-engine's exec-env interface. The
provider injects the key into a private host helper that directly forwards it to
the namespace broker. The broker injects only ANTHROPIC_API_KEY into the command
and redacts exact values before truncating output. No OpenBao token crosses
into the sandbox; no key is returned through Glas's API. Values are available
to the trusted workload and descendants; encoding/exfiltration by hostile
workload code is not prevented by an output redactor. Existing sandbox, egress,
artifact verification and profile admission boundaries remain required.
A synthetic provider proves the transport only. It does not stand in for native
approval, OpenBao access, provider authentication or production readiness.
## Activation requirements
As of 2026-09-27, the shared approval/consume/PDP chain has live evidence from
SECRETS-WP-0010-T03. The Glas catalog now has a configured owner binding and worker companion,
verified by backend-free checks on railiance01. It refuses substituted children
and still requires fresh exact approvals and verified delivery state. The earlier
lack of a served decision path is no longer the current activation blocker.
The metered owner configuration and binding were prepared on 2026-09-23.
Activity Core reports ACTIVITY-WP-0039 complete on 2026-09-24: custody and the
separate `rein-aharness-metered@railiance01` identity are live. See the exact
handoff in SECRETS-WP-0011. Its worker token is companion-only; direct exec of
`activity-core-metered-worker-token` is refused. The intended recipient is the
metered MessagesOwner described in [exec owner binding](exec-owner-binding.md),
not the historical sandbox helper above.
SECRETS-WP-0009-T03 still owns current recipient/pin admission and the attended
activation. Revalidate the configured binding, installed files and private
state in the execution window, and obtain exact per-action/per-lane approvals. Apply the scoped policy/AppRole, verify positive read and denied
metadata/sibling/write access with an unrelated negative identity, then prove
bounded owner delivery and session revocation. Both lanes must independently
pass approval, PDP, consume and delivery readiness. The handoff and catalog configuration are
not runtime authorization. No production activation was performed in this review.
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
predecessor at Anthropic and prove denial. Bao session expiration does not revoke
the provider key. Compromise disables the provider key and affected runs first.
## Current configuration correction — 2026-09-27
The earlier pin-only check is superseded for activation by the
[exact-model review packet](proposals/glas-metered-20260927/README.md). The source
catalog pins its corrected 1M-context/64k-output owner and observed beta list;
the host's older file will fail that pin. Exact Sonnet 5 synthetic target proof
passes, but host source/config installation, budget/FX acceptance and native
action approvals remain open. No new approval may name the old owner digest.