secrets-engine/docs/glas-claude-delivery.md
tegwick 6a0daae437 feat: prepare data-only Anthropic native delivery lane
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
2026-09-06 00:25:37 +02:00

53 lines
3.2 KiB
Markdown

# Glas Claude exec delivery
Proposed native lane `glas-claude-agent-dev-anthropic`, provenance
railiance-platform CCR-2026-0016; implementation/activation record SECRETS-WP-0009.
KV custody is already confirmed at version 2. Do not provision or rotate it as
part of native read-lane adoption.
The generated plan checks existing mount `platform`, creates policy and AppRole
`se-prod-glas-claude-agent-dev-anthropic`, and grants read only on
`platform/data/workloads/glas-harness/claude-agent-dev`. Field ANTHROPIC_API_KEY
is selected by the exec adapter; KV policies scope entries, not fields.
`delivery_auth.metadata_read: false` excludes the metadata endpoint; existing
lanes retain their previous metadata access by default. Token TTL 5m, maximum
15m, SecretID TTL 5m and single use, token use budget 8. No wildcard, listing,
workload writes, mount mutation, provider creation or default-policy change is
included in this plan. Verify effective token identity policies at activation.
Sand-boxer's owner-configured credential route binds profile, project, actor and
nonempty run id before invoking secrets-engine's exec-env interface. The
provider injects the key into a private host helper that directly forwards it to
the namespace broker. The broker injects only ANTHROPIC_API_KEY into the command
and redacts exact values before truncating output. No OpenBao token crosses
into the sandbox; no key is returned through Glas's API. Values are available
to the trusted workload and descendants; encoding/exfiltration by hostile
workload code is not prevented by an output redactor. Existing sandbox, egress,
artifact verification and profile admission boundaries remain required.
A synthetic provider proves the transport only. It does not stand in for native
approval, OpenBao access, provider authentication or production readiness.
## Activation requirements
The current engine's production stance refuses before opening the backend:
`production action 'exec' requires a durable access-engine decision record;
live production remains disabled`. This refusal was exercised with the proposed
catalog and service-jwt selection. No real value was requested.
Activation depends on SECRETS-WP-0007-T04 (exact production actions) and
SECRETS-WP-0008-T02/T06 (decision consumption and service authority). Require
canonical ActionAuthorization for each protected action, successful consume,
and exact scoped backend authority. This draft cannot authorize itself; an
operator browser token or unsafe-demo flag is not a runtime substitute.
Once those services exist: obtain the reviewed apply authorization, apply this
exact policy/AppRole with scoped authority, verify positive read and denied
metadata/sibling/write access without exposing values, and record delivery-ready
state. Bind approved exec authorization and named engine service authentication
to the sand-boxer owner route. Prove actual provider authentication and a bounded
Glas task, then activate routing and only the validated profile.
Rotation: store replacement with CAS, stop old runs, verify replacement, revoke
predecessor at Anthropic and prove denial. Bao session expiration does not revoke
the provider key. Compromise disables the provider key and affected runs first.