secrets-engine/workplans/SECRETS-WP-0010-openrouter-native-access.md
tegwick c7582b1f0c
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record attended login recovery and remaining T03 prerequisites
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 03:55:43 +02:00

12 KiB

id type title domain repo status owner topic_slug created updated related_workplans state_hub_workstream_id
SECRETS-WP-0010 workplan Native OpenRouter access for intelligence-radar infotech secrets-engine active codex netkingdom 2026-09-14 2026-09-14
IR-WP-0004
FLEX-WP-0026
SECRETS-WP-0007
SECRETS-WP-0006
e1e68392-e7c4-50ab-91e4-4793e3591cac

Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f. Implementation and execution procedure: docs/openrouter-native-access.md.

Bind approval to actual native custody and delivery inputs

id: SECRETS-WP-0010-T01
status: done
priority: high
state_hub_task_id: "b315d0bd-63c5-530d-afde-b82973cee3a9"

Implemented context.catalog_target and complete plan limits. Changed paths, mounts, owners and token limits refuse replay before consume/backend against real local components. Existing exec-owner and human-control contracts retained. 410 repository tests and 26 component checks passed. Receipts in docs/evidence.

Prepare value-safe first recipient and exact native plan

id: SECRETS-WP-0010-T02
status: done
priority: high
state_hub_task_id: "564496a4-2ea9-51e5-9573-84003d955666"

Implemented the fixed read-only OpenRouter key-check script and synthetic tests. Inactive proposed overlay declares human control and a pending exact recipient; active llm-connect catalog admission is not broadened. Non-secret apply request and bounded plan are review artifacts, not runtime grants.

Admit and verify real native delivery

id: SECRETS-WP-0010-T03
status: wait
priority: high
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"

Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4, 11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05 (identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader admission, exact installed recipient admission, real human approval/consume and scoped attended platform authority. No Approval Engine StatefulSet/pod/Service was present in its declared namespace at the 2026-09-14 inspection.

Then execute docs/openrouter-native-access.md steps: bounded native apply, positive/negative checks, ESO/app health, value-safe key check and session revoke. SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and IR-WP-0004-T02 waiting until the native route passes. Trials require a separately bound recipient and the existing campaign/budget reconciliation.

T03 continuation — 2026-09-14

User explicitly requested execution of T03. Completed the independently runnable prerequisites: Approval Engine is now deployed and restart/backup/restore verified (APPROVAL-WP-0002-T03 done). Existing audit sender custody/ESO and KeyCape consumer registration were already complete; neither was reprovisioned. Live JWKS/readiness/anonymous and invalid-bearer refusal plus durable heartbeat/outbox checks pass. See docs/evidence/2026-09-14-approval-engine-deployment.json.

Installed the read-only checker in the owner-private versioned local directory, using pinned /usr/bin/python3.12 -I -B <script>, fixed environment and private runtime cwd. docs/proposals/openrouter-key-check.yaml now has a configured recipient; it remains outside the active catalog and does not admit key use. Runtime trust is the system-owned Python standard library plus pinned executable and script. The install receipt and finalized apply/verify/exec request JSONs are under docs/evidence. No provider request or credential read was made.

Operator input received, 2026-09-14: the user explicitly selected net-kingdom-admins for CCR-2026-0019. The platform source now records that binding and the approved metadata apply. The guarded applier requires role secrets-engine-approval-client-workload-kv-read; its dry run passes. Attended apply/readback passed: exact group, policy and 900-second TTL verified. Warden completed its contained session successfully. Platform receipt: docs/evidence/2026-09-14-ccr0019-operator-binding.json. Native scoped delivery proof remains pending; no credential was read and the front door stays disabled. A separately admitted approval:create requester and real human approver flow also remain necessary: the withdrawn approval-engine-operator convenience client must not be restored or used to create and approve its own requests. Informed Decision's native review flow and requester admission are dependencies, not replaced by a service token or a seeded live approval. T03 remains open until real approval/consume, attended OpenBao apply, key check, positive/negative native delivery and revocation are evidenced.

Native reader acceptance — 2026-09-14

The scoped Warden login lane secrets-engine-approval-client-login now routes to the applied OIDC reader and the platform's silent preflight. The installed Warden package still carries an older catalog; use the explicit source catalog WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml until its next normal installation refresh. This lane authenticates the reader; it is not a raw secret fetch or retained-file delivery interface.

Live effective-policy and capability checks passed: only exact data/metadata read, no sibling secret, parent listing, write or control-plane authority. A second contained session read existing version 1 into an operator-owned 0600 file in a private 0700 runtime tmpfs directory. The native consumer exchanged separate read and consume scopes; Approval Engine verified the read token before returning 404 for a fresh nonexistent approval, and refused the consume-only token's read request with 403. No approval was created, bound or consumed. Both Warden sessions exited 0 after self-revocation/helper cleanup; temporary credential file and directory were removed. Four refusal/path/redirect tests pass. Receipts are in platform docs/evidence/2026-09-14-ccr0019-{reader-preflight,delivery-check}.json.

Remaining: an actual nonmember login refusal, real approval claim/consume, separate narrow requester admission and deployed Informed Decision review with an explicitly admitted human mandate. The reader group alone grants no review mandate. T03 and CCR delivery activation remain open; no OpenRouter key was read.

T03 scoped review deployment — 2026-09-14

The operator explicitly admitted net-kingdom-admins as the human review group for only the T03 apply, verify and read-only key-check records, separately from its credential-reader membership. The review service is live and ready at https://decisions.coulomb.social with verified KeyCape groups, fresh MFA and a dedicated caller-bound Flex Auth policy. Its mandate does not grant consumption.

The new secrets-engine-requester client has subject secrets-engine, tenant tenant:platform, role secrets-engine-requester, and only approval:create. CCR-2026-0024 and CCR-2026-0025 provide distinct verifier and attended reader custody. Native signature, subject, scope and TTL checks passed; excess scopes and a wrong secret were refused. Existing consumer identity is unchanged. Three real requested approvals were created with human control, required count one, and zero entries. Platform evidence is docs/evidence/2026-09-14-t03-native-approval-requests.json.

Review image: sha256:8f55bcecf37a8d65f96e073510b1ffb4636c0a91d75e1ee7d582ad4bce8b953a. Policy image: sha256:c9f028b49dfcede930a9cc48757ec8371ecc71d20b1bfee2733e55298dffcc7c. Review tests: 339 passed, 39 optional integration tests skipped; 11 container checks and HIGH/CRITICAL image scan passed. Policy checks: 57 local and 6 native caller checks passed, using synthetic subjects, not human binding evidence. Approval Engine CPU request was reduced from 25m to 10m after observing 1m use; review requests 20m and its PDP 5m. Limits are unchanged. Native services ready.

Remaining T03 gate: the operator's exact signed-in account is needed to address three prepared immutable memos, followed by real acknowledgements and acceptance in Informed Decision. No human entry or consume has been generated by an agent. Then execute claim -> validated PDP Check -> CAS consume separately for apply, verify and exec using scoped attended authority, and capture native denial, revocation, workload health and key-check evidence. No OpenRouter credential has been read and no inference or spend was performed. T03 remains waiting; this entry supersedes earlier statements that requester or group admission is missing.

Live browser registration correction — 2026-09-14

The user's login exposed invalid_profile_usage: unknown client_id: the public informed-decision-approver registration existed in the source example but was absent from live KeyCape. Applied exactly the existing admitted registration, with UID/resourceVersion guards and byte-preserving insertion; unrelated clients, configuration, signing key and pinned image were preserved. KeyCape is ready. The actual review-site /auth/start now redirects through KeyCape to auth.coulomb.social. Wrong redirect, consume scope and absent PKCE are refused. Receipt: key-cape/docs/evidence/2026-09-14-informed-decision-browser-registration.json. Repeatable contained helper: key-cape/tools/register-informed-decision.py (default preflight; --apply mutates only a missing exact registration). Human callback/MFA/token proof and T03 approval entries remain pending. The previous ready check established service health, not browser login acceptance.

Human approval and execution preparation — 2026-09-14

The three native Approval Engine records are approved by the actual signed-in human uid=platform-root,ou=people,dc=netkingdom,dc=local, with one human entry each and no consumption at inspection. The exact action/memo IDs remain unchanged. Execution preflight found and corrected two CLI gaps: missing explicit policy/ role targets, and an unnecessary hub/fixture lookup after an already validated native claim/PDP join. Real claim validation and mandatory CAS remain in place; unserved legacy review paths are unchanged. 414 regression tests passed, including frozen approved-request comparisons and consume-refusal/backend isolation. The attended owner procedure is in platform scripts/t03-native-execution.py and t03-attended-delivery.py. It uses the exact scoped client reader, contained platform administration, named/pinned native pods, private runtime storage, and native CLI handlers. No approval has yet been consumed by this preparation.

Attended reader handoff pending — 2026-09-14

Informed Decision confirms three native submissions and delivered audit records; Approval Engine still records all three actions approved and unconsumed. The attended reader login exited 5 before handing off the command. Warden removed its isolated helper/home; it could not confirm revocation of any possible issued login session. No owner procedure started, no approval was consumed and no provider key was read. Asked the operator whether the browser sign-in window opened before retrying. Do not repeat the human memo approvals. T03 remains wait for the attended credential flow and actual execution. Metadata receipt: docs/evidence/2026-09-14-t03-approved-awaiting-reader.json.

Identity recovery and latest attended attempt — 2026-09-14

KeyCape's expired factor-reader credential recovered after restoring scheduling headroom for its native renewal Job; recurring capacity is handed to CUST-WP-0071-T01. The latest attempt obtained and validated the scoped reader, but its nested administrator handoff failed before the native execution worker started. All three approvals remain approved and unconsumed. Reader revocation was confirmed; helper roots and private runtime directories were removed. Administrator revocation cannot be inferred from the outer receipt.

Native preflight also exposed workstation clock drift. The approved runtime clock source change from tsc to hyperv_clocksource_tsc_page plus restarting systemd-timesyncd briefly established synchronization, but the latest check again reports unsynchronized. No persistent boot configuration was changed. This is not a confirmed clock fix. T03 remains wait and owns stable-time verification, the attended-login diagnosis and actual native execution as live remaining work. Do not repeat the human memo reviews or consume requests until those prerequisites pass. The bounded decision-start wait preserves actual validity boundaries; the complete regression suite passed 420 tests. Receipt: docs/evidence/2026-09-14-t03-login-recovery.json; platform attempt: docs/evidence/2026-09-14-t03-attended-delivery-attempt-02.json.