secrets-engine/workplans/SECRETS-WP-0010-openrouter-native-access.md
tegwick caca122b49
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record native approval client delivery acceptance for T03
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 01:46:47 +02:00

6.3 KiB

id type title domain repo status owner topic_slug created updated related_workplans state_hub_workstream_id
SECRETS-WP-0010 workplan Native OpenRouter access for intelligence-radar infotech secrets-engine blocked codex netkingdom 2026-09-14 2026-09-14
IR-WP-0004
FLEX-WP-0026
SECRETS-WP-0007
SECRETS-WP-0006
e1e68392-e7c4-50ab-91e4-4793e3591cac

Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f. Implementation and execution procedure: docs/openrouter-native-access.md.

Bind approval to actual native custody and delivery inputs

id: SECRETS-WP-0010-T01
status: done
priority: high
state_hub_task_id: "b315d0bd-63c5-530d-afde-b82973cee3a9"

Implemented context.catalog_target and complete plan limits. Changed paths, mounts, owners and token limits refuse replay before consume/backend against real local components. Existing exec-owner and human-control contracts retained. 410 repository tests and 26 component checks passed. Receipts in docs/evidence.

Prepare value-safe first recipient and exact native plan

id: SECRETS-WP-0010-T02
status: done
priority: high
state_hub_task_id: "564496a4-2ea9-51e5-9573-84003d955666"

Implemented the fixed read-only OpenRouter key-check script and synthetic tests. Inactive proposed overlay declares human control and a pending exact recipient; active llm-connect catalog admission is not broadened. Non-secret apply request and bounded plan are review artifacts, not runtime grants.

Admit and verify real native delivery

id: SECRETS-WP-0010-T03
status: wait
priority: high
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"

Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4, 11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05 (identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader admission, exact installed recipient admission, real human approval/consume and scoped attended platform authority. No Approval Engine StatefulSet/pod/Service was present in its declared namespace at the 2026-09-14 inspection.

Then execute docs/openrouter-native-access.md steps: bounded native apply, positive/negative checks, ESO/app health, value-safe key check and session revoke. SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and IR-WP-0004-T02 waiting until the native route passes. Trials require a separately bound recipient and the existing campaign/budget reconciliation.

T03 continuation — 2026-09-14

User explicitly requested execution of T03. Completed the independently runnable prerequisites: Approval Engine is now deployed and restart/backup/restore verified (APPROVAL-WP-0002-T03 done). Existing audit sender custody/ESO and KeyCape consumer registration were already complete; neither was reprovisioned. Live JWKS/readiness/anonymous and invalid-bearer refusal plus durable heartbeat/outbox checks pass. See docs/evidence/2026-09-14-approval-engine-deployment.json.

Installed the read-only checker in the owner-private versioned local directory, using pinned /usr/bin/python3.12 -I -B <script>, fixed environment and private runtime cwd. docs/proposals/openrouter-key-check.yaml now has a configured recipient; it remains outside the active catalog and does not admit key use. Runtime trust is the system-owned Python standard library plus pinned executable and script. The install receipt and finalized apply/verify/exec request JSONs are under docs/evidence. No provider request or credential read was made.

Operator input received, 2026-09-14: the user explicitly selected net-kingdom-admins for CCR-2026-0019. The platform source now records that binding and the approved metadata apply. The guarded applier requires role secrets-engine-approval-client-workload-kv-read; its dry run passes. Attended apply/readback passed: exact group, policy and 900-second TTL verified. Warden completed its contained session successfully. Platform receipt: docs/evidence/2026-09-14-ccr0019-operator-binding.json. Native scoped delivery proof remains pending; no credential was read and the front door stays disabled. A separately admitted approval:create requester and real human approver flow also remain necessary: the withdrawn approval-engine-operator convenience client must not be restored or used to create and approve its own requests. Informed Decision's native review flow and requester admission are dependencies, not replaced by a service token or a seeded live approval. T03 remains open until real approval/consume, attended OpenBao apply, key check, positive/negative native delivery and revocation are evidenced.

Native reader acceptance — 2026-09-14

The scoped Warden login lane secrets-engine-approval-client-login now routes to the applied OIDC reader and the platform's silent preflight. The installed Warden package still carries an older catalog; use the explicit source catalog WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml until its next normal installation refresh. This lane authenticates the reader; it is not a raw secret fetch or retained-file delivery interface.

Live effective-policy and capability checks passed: only exact data/metadata read, no sibling secret, parent listing, write or control-plane authority. A second contained session read existing version 1 into an operator-owned 0600 file in a private 0700 runtime tmpfs directory. The native consumer exchanged separate read and consume scopes; Approval Engine verified the read token before returning 404 for a fresh nonexistent approval, and refused the consume-only token's read request with 403. No approval was created, bound or consumed. Both Warden sessions exited 0 after self-revocation/helper cleanup; temporary credential file and directory were removed. Four refusal/path/redirect tests pass. Receipts are in platform docs/evidence/2026-09-14-ccr0019-{reader-preflight,delivery-check}.json.

Remaining: an actual nonmember login refusal, real approval claim/consume, separate narrow requester admission and deployed Informed Decision review with an explicitly admitted human mandate. The reader group alone grants no review mandate. T03 and CCR delivery activation remain open; no OpenRouter key was read.