Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
12 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related_workplans | state_hub_workstream_id | ||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SECRETS-WP-0010 | workplan | Native OpenRouter access for intelligence-radar | infotech | secrets-engine | active | codex | netkingdom | 2026-09-14 | 2026-09-14 |
|
e1e68392-e7c4-50ab-91e4-4793e3591cac |
Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f.
Implementation and execution procedure: docs/openrouter-native-access.md.
Bind approval to actual native custody and delivery inputs
id: SECRETS-WP-0010-T01
status: done
priority: high
state_hub_task_id: "b315d0bd-63c5-530d-afde-b82973cee3a9"
Implemented context.catalog_target and complete plan limits. Changed paths, mounts, owners and token limits refuse replay before consume/backend against real local components. Existing exec-owner and human-control contracts retained. 410 repository tests and 26 component checks passed. Receipts in docs/evidence.
Prepare value-safe first recipient and exact native plan
id: SECRETS-WP-0010-T02
status: done
priority: high
state_hub_task_id: "564496a4-2ea9-51e5-9573-84003d955666"
Implemented the fixed read-only OpenRouter key-check script and synthetic tests. Inactive proposed overlay declares human control and a pending exact recipient; active llm-connect catalog admission is not broadened. Non-secret apply request and bounded plan are review artifacts, not runtime grants.
Admit and verify real native delivery
id: SECRETS-WP-0010-T03
status: wait
priority: high
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"
Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4, 11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05 (identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader admission, exact installed recipient admission, real human approval/consume and scoped attended platform authority. No Approval Engine StatefulSet/pod/Service was present in its declared namespace at the 2026-09-14 inspection.
Then execute docs/openrouter-native-access.md steps: bounded native apply,
positive/negative checks, ESO/app health, value-safe key check and session revoke.
SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan
must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and
IR-WP-0004-T02 waiting until the native route passes. Trials require a separately
bound recipient and the existing campaign/budget reconciliation.
T03 continuation — 2026-09-14
User explicitly requested execution of T03. Completed the independently runnable
prerequisites: Approval Engine is now deployed and restart/backup/restore verified
(APPROVAL-WP-0002-T03 done). Existing audit sender custody/ESO and KeyCape
consumer registration were already complete; neither was reprovisioned. Live
JWKS/readiness/anonymous and invalid-bearer refusal plus durable heartbeat/outbox
checks pass. See docs/evidence/2026-09-14-approval-engine-deployment.json.
Installed the read-only checker in the owner-private versioned local directory,
using pinned /usr/bin/python3.12 -I -B <script>, fixed environment and private
runtime cwd. docs/proposals/openrouter-key-check.yaml now has a configured
recipient; it remains outside the active catalog and does not admit key use.
Runtime trust is the system-owned Python standard library plus pinned executable
and script. The install receipt and finalized apply/verify/exec request JSONs are
under docs/evidence. No provider request or credential read was made.
Operator input received, 2026-09-14: the user explicitly selected
net-kingdom-admins for CCR-2026-0019. The platform source now records that
binding and the approved metadata apply. The guarded applier requires role
secrets-engine-approval-client-workload-kv-read; its dry run passes.
Attended apply/readback passed: exact group, policy and 900-second TTL verified.
Warden completed its contained session successfully. Platform receipt:
docs/evidence/2026-09-14-ccr0019-operator-binding.json. Native scoped delivery
proof remains pending; no credential was read and the front door stays disabled.
A separately admitted approval:create requester and real human approver flow
also remain necessary: the withdrawn approval-engine-operator convenience client
must not be restored or used to create and approve its own requests. Informed
Decision's native review flow and requester admission are dependencies, not
replaced by a service token or a seeded live approval. T03 remains open until
real approval/consume, attended OpenBao apply, key check, positive/negative
native delivery and revocation are evidenced.
Native reader acceptance — 2026-09-14
The scoped Warden login lane secrets-engine-approval-client-login now routes
to the applied OIDC reader and the platform's silent preflight. The installed
Warden package still carries an older catalog; use the explicit source catalog
WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml
until its next normal installation refresh. This lane authenticates the reader;
it is not a raw secret fetch or retained-file delivery interface.
Live effective-policy and capability checks passed: only exact data/metadata
read, no sibling secret, parent listing, write or control-plane authority.
A second contained session read existing version 1 into an operator-owned 0600
file in a private 0700 runtime tmpfs directory. The native consumer exchanged
separate read and consume scopes; Approval Engine verified the read token before
returning 404 for a fresh nonexistent approval, and refused the consume-only
token's read request with 403. No approval was created, bound or consumed.
Both Warden sessions exited 0 after self-revocation/helper cleanup; temporary
credential file and directory were removed. Four refusal/path/redirect tests
pass. Receipts are in platform docs/evidence/2026-09-14-ccr0019-{reader-preflight,delivery-check}.json.
Remaining: an actual nonmember login refusal, real approval claim/consume, separate narrow requester admission and deployed Informed Decision review with an explicitly admitted human mandate. The reader group alone grants no review mandate. T03 and CCR delivery activation remain open; no OpenRouter key was read.
T03 scoped review deployment — 2026-09-14
The operator explicitly admitted net-kingdom-admins as the human review group
for only the T03 apply, verify and read-only key-check records, separately from
its credential-reader membership. The review service is live and ready at
https://decisions.coulomb.social with verified KeyCape groups, fresh MFA and a
dedicated caller-bound Flex Auth policy. Its mandate does not grant consumption.
The new secrets-engine-requester client has subject secrets-engine, tenant
tenant:platform, role secrets-engine-requester, and only approval:create.
CCR-2026-0024 and CCR-2026-0025 provide distinct verifier and attended reader
custody. Native signature, subject, scope and TTL checks passed; excess scopes
and a wrong secret were refused. Existing consumer identity is unchanged.
Three real requested approvals were created with human control, required count
one, and zero entries. Platform evidence is
docs/evidence/2026-09-14-t03-native-approval-requests.json.
Review image: sha256:8f55bcecf37a8d65f96e073510b1ffb4636c0a91d75e1ee7d582ad4bce8b953a. Policy image: sha256:c9f028b49dfcede930a9cc48757ec8371ecc71d20b1bfee2733e55298dffcc7c. Review tests: 339 passed, 39 optional integration tests skipped; 11 container checks and HIGH/CRITICAL image scan passed. Policy checks: 57 local and 6 native caller checks passed, using synthetic subjects, not human binding evidence. Approval Engine CPU request was reduced from 25m to 10m after observing 1m use; review requests 20m and its PDP 5m. Limits are unchanged. Native services ready.
Remaining T03 gate: the operator's exact signed-in account is needed to address three prepared immutable memos, followed by real acknowledgements and acceptance in Informed Decision. No human entry or consume has been generated by an agent. Then execute claim -> validated PDP Check -> CAS consume separately for apply, verify and exec using scoped attended authority, and capture native denial, revocation, workload health and key-check evidence. No OpenRouter credential has been read and no inference or spend was performed. T03 remains waiting; this entry supersedes earlier statements that requester or group admission is missing.
Live browser registration correction — 2026-09-14
The user's login exposed invalid_profile_usage: unknown client_id: the public
informed-decision-approver registration existed in the source example but was
absent from live KeyCape. Applied exactly the existing admitted registration,
with UID/resourceVersion guards and byte-preserving insertion; unrelated clients,
configuration, signing key and pinned image were preserved. KeyCape is ready.
The actual review-site /auth/start now redirects through KeyCape to
auth.coulomb.social. Wrong redirect, consume scope and absent PKCE are refused.
Receipt: key-cape/docs/evidence/2026-09-14-informed-decision-browser-registration.json.
Repeatable contained helper: key-cape/tools/register-informed-decision.py
(default preflight; --apply mutates only a missing exact registration).
Human callback/MFA/token proof and T03 approval entries remain pending. The
previous ready check established service health, not browser login acceptance.
Human approval and execution preparation — 2026-09-14
The three native Approval Engine records are approved by the actual signed-in human uid=platform-root,ou=people,dc=netkingdom,dc=local, with one human entry each and no consumption at inspection. The exact action/memo IDs remain unchanged. Execution preflight found and corrected two CLI gaps: missing explicit policy/ role targets, and an unnecessary hub/fixture lookup after an already validated native claim/PDP join. Real claim validation and mandatory CAS remain in place; unserved legacy review paths are unchanged. 414 regression tests passed, including frozen approved-request comparisons and consume-refusal/backend isolation. The attended owner procedure is in platform scripts/t03-native-execution.py and t03-attended-delivery.py. It uses the exact scoped client reader, contained platform administration, named/pinned native pods, private runtime storage, and native CLI handlers. No approval has yet been consumed by this preparation.
Attended reader handoff pending — 2026-09-14
Informed Decision confirms three native submissions and delivered audit records;
Approval Engine still records all three actions approved and unconsumed. The
attended reader login exited 5 before handing off the command. Warden removed
its isolated helper/home; it could not confirm revocation of any possible issued
login session. No owner procedure started, no approval was consumed and no
provider key was read. Asked the operator whether the browser sign-in window
opened before retrying. Do not repeat the human memo approvals. T03 remains wait
for the attended credential flow and actual execution. Metadata receipt:
docs/evidence/2026-09-14-t03-approved-awaiting-reader.json.
Identity recovery and latest attended attempt — 2026-09-14
KeyCape's expired factor-reader credential recovered after restoring scheduling headroom for its native renewal Job; recurring capacity is handed to CUST-WP-0071-T01. The latest attempt obtained and validated the scoped reader, but its nested administrator handoff failed before the native execution worker started. All three approvals remain approved and unconsumed. Reader revocation was confirmed; helper roots and private runtime directories were removed. Administrator revocation cannot be inferred from the outer receipt.
Native preflight also exposed workstation clock drift. The approved runtime clock source change from tsc to hyperv_clocksource_tsc_page plus restarting systemd-timesyncd briefly established synchronization, but the latest check again reports unsynchronized. No persistent boot configuration was changed. This is not a confirmed clock fix. T03 remains wait and owns stable-time verification, the attended-login diagnosis and actual native execution as live remaining work. Do not repeat the human memo reviews or consume requests until those prerequisites pass. The bounded decision-start wait preserves actual validity boundaries; the complete regression suite passed 420 tests. Receipt: docs/evidence/2026-09-14-t03-login-recovery.json; platform attempt: docs/evidence/2026-09-14-t03-attended-delivery-attempt-02.json.