secrets-engine/workplans/SECRETS-WP-0010-openrouter-native-access.md
tegwick 4a8ea4f591
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Complete T03 with native OpenRouter authentication evidence
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-16 02:12:45 +02:00

16 KiB

id type title domain repo status flavor owner topic_slug created updated related_workplans state_hub_workstream_id
SECRETS-WP-0010 workplan Native OpenRouter access for intelligence-radar infotech secrets-engine finished implementation codex netkingdom 2026-09-14 2026-09-16
IR-WP-0004
FLEX-WP-0026
SECRETS-WP-0007
SECRETS-WP-0006
e1e68392-e7c4-50ab-91e4-4793e3591cac

Source request: intelligence-radar message cfab5355-b0f9-4868-b4e6-61ea42c54b0f. Implementation and execution procedure: docs/openrouter-native-access.md.

Bind approval to actual native custody and delivery inputs

id: SECRETS-WP-0010-T01
status: done
priority: high
state_hub_task_id: "b315d0bd-63c5-530d-afde-b82973cee3a9"

Implemented context.catalog_target and complete plan limits. Changed paths, mounts, owners and token limits refuse replay before consume/backend against real local components. Existing exec-owner and human-control contracts retained. 410 repository tests and 26 component checks passed. Receipts in docs/evidence.

Prepare value-safe first recipient and exact native plan

id: SECRETS-WP-0010-T02
status: done
priority: high
state_hub_task_id: "564496a4-2ea9-51e5-9573-84003d955666"

Implemented the fixed read-only OpenRouter key-check script and synthetic tests. Inactive proposed overlay declares human control and a pending exact recipient; active llm-connect catalog admission is not broadened. Non-secret apply request and bounded plan are review artifacts, not runtime grants.

Admit and verify real native delivery

id: SECRETS-WP-0010-T03
status: done
priority: high
state_hub_task_id: "2aa6d2d3-bebc-5ae2-a04b-1bb2e9605405"

Live residual from FLEX-WP-0026: the dedicated PDP is now current (revision 4, 11 live checks). Actual delivery still requires APPROVAL-WP-0002-T01/T03/T05 (identity/audit/service deployment), RPF-WP-0035-T06 / CCR-2026-0019 client-reader admission, exact installed recipient admission, real human approval/consume and scoped attended platform authority. No Approval Engine StatefulSet/pod/Service was present in its declared namespace at the 2026-09-14 inspection.

Then execute docs/openrouter-native-access.md steps: bounded native apply, positive/negative checks, ESO/app health, value-safe key check and session revoke. SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06 remain wait; this workplan must not close them from synthetic evidence. Keep WARDEN-WP-0039-T03 and IR-WP-0004-T02 waiting until the native route passes. Trials require a separately bound recipient and the existing campaign/budget reconciliation.

T03 continuation — 2026-09-14

User explicitly requested execution of T03. Completed the independently runnable prerequisites: Approval Engine is now deployed and restart/backup/restore verified (APPROVAL-WP-0002-T03 done). Existing audit sender custody/ESO and KeyCape consumer registration were already complete; neither was reprovisioned. Live JWKS/readiness/anonymous and invalid-bearer refusal plus durable heartbeat/outbox checks pass. See docs/evidence/2026-09-14-approval-engine-deployment.json.

Installed the read-only checker in the owner-private versioned local directory, using pinned /usr/bin/python3.12 -I -B <script>, fixed environment and private runtime cwd. docs/proposals/openrouter-key-check.yaml now has a configured recipient; it remains outside the active catalog and does not admit key use. Runtime trust is the system-owned Python standard library plus pinned executable and script. The install receipt and finalized apply/verify/exec request JSONs are under docs/evidence. No provider request or credential read was made.

Operator input received, 2026-09-14: the user explicitly selected net-kingdom-admins for CCR-2026-0019. The platform source now records that binding and the approved metadata apply. The guarded applier requires role secrets-engine-approval-client-workload-kv-read; its dry run passes. Attended apply/readback passed: exact group, policy and 900-second TTL verified. Warden completed its contained session successfully. Platform receipt: docs/evidence/2026-09-14-ccr0019-operator-binding.json. Native scoped delivery proof remains pending; no credential was read and the front door stays disabled. A separately admitted approval:create requester and real human approver flow also remain necessary: the withdrawn approval-engine-operator convenience client must not be restored or used to create and approve its own requests. Informed Decision's native review flow and requester admission are dependencies, not replaced by a service token or a seeded live approval. T03 remains open until real approval/consume, attended OpenBao apply, key check, positive/negative native delivery and revocation are evidenced.

Native reader acceptance — 2026-09-14

The scoped Warden login lane secrets-engine-approval-client-login now routes to the applied OIDC reader and the platform's silent preflight. The installed Warden package still carries an older catalog; use the explicit source catalog WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml until its next normal installation refresh. This lane authenticates the reader; it is not a raw secret fetch or retained-file delivery interface.

Live effective-policy and capability checks passed: only exact data/metadata read, no sibling secret, parent listing, write or control-plane authority. A second contained session read existing version 1 into an operator-owned 0600 file in a private 0700 runtime tmpfs directory. The native consumer exchanged separate read and consume scopes; Approval Engine verified the read token before returning 404 for a fresh nonexistent approval, and refused the consume-only token's read request with 403. No approval was created, bound or consumed. Both Warden sessions exited 0 after self-revocation/helper cleanup; temporary credential file and directory were removed. Four refusal/path/redirect tests pass. Receipts are in platform docs/evidence/2026-09-14-ccr0019-{reader-preflight,delivery-check}.json.

Remaining: an actual nonmember login refusal, real approval claim/consume, separate narrow requester admission and deployed Informed Decision review with an explicitly admitted human mandate. The reader group alone grants no review mandate. T03 and CCR delivery activation remain open; no OpenRouter key was read.

T03 scoped review deployment — 2026-09-14

The operator explicitly admitted net-kingdom-admins as the human review group for only the T03 apply, verify and read-only key-check records, separately from its credential-reader membership. The review service is live and ready at https://decisions.coulomb.social with verified KeyCape groups, fresh MFA and a dedicated caller-bound Flex Auth policy. Its mandate does not grant consumption.

The new secrets-engine-requester client has subject secrets-engine, tenant tenant:platform, role secrets-engine-requester, and only approval:create. CCR-2026-0024 and CCR-2026-0025 provide distinct verifier and attended reader custody. Native signature, subject, scope and TTL checks passed; excess scopes and a wrong secret were refused. Existing consumer identity is unchanged. Three real requested approvals were created with human control, required count one, and zero entries. Platform evidence is docs/evidence/2026-09-14-t03-native-approval-requests.json.

Review image: sha256:8f55bcecf37a8d65f96e073510b1ffb4636c0a91d75e1ee7d582ad4bce8b953a. Policy image: sha256:c9f028b49dfcede930a9cc48757ec8371ecc71d20b1bfee2733e55298dffcc7c. Review tests: 339 passed, 39 optional integration tests skipped; 11 container checks and HIGH/CRITICAL image scan passed. Policy checks: 57 local and 6 native caller checks passed, using synthetic subjects, not human binding evidence. Approval Engine CPU request was reduced from 25m to 10m after observing 1m use; review requests 20m and its PDP 5m. Limits are unchanged. Native services ready.

Remaining T03 gate: the operator's exact signed-in account is needed to address three prepared immutable memos, followed by real acknowledgements and acceptance in Informed Decision. No human entry or consume has been generated by an agent. Then execute claim -> validated PDP Check -> CAS consume separately for apply, verify and exec using scoped attended authority, and capture native denial, revocation, workload health and key-check evidence. No OpenRouter credential has been read and no inference or spend was performed. T03 remains waiting; this entry supersedes earlier statements that requester or group admission is missing.

Live browser registration correction — 2026-09-14

The user's login exposed invalid_profile_usage: unknown client_id: the public informed-decision-approver registration existed in the source example but was absent from live KeyCape. Applied exactly the existing admitted registration, with UID/resourceVersion guards and byte-preserving insertion; unrelated clients, configuration, signing key and pinned image were preserved. KeyCape is ready. The actual review-site /auth/start now redirects through KeyCape to auth.coulomb.social. Wrong redirect, consume scope and absent PKCE are refused. Receipt: key-cape/docs/evidence/2026-09-14-informed-decision-browser-registration.json. Repeatable contained helper: key-cape/tools/register-informed-decision.py (default preflight; --apply mutates only a missing exact registration). Human callback/MFA/token proof and T03 approval entries remain pending. The previous ready check established service health, not browser login acceptance.

Human approval and execution preparation — 2026-09-14

The three native Approval Engine records are approved by the actual signed-in human uid=platform-root,ou=people,dc=netkingdom,dc=local, with one human entry each and no consumption at inspection. The exact action/memo IDs remain unchanged. Execution preflight found and corrected two CLI gaps: missing explicit policy/ role targets, and an unnecessary hub/fixture lookup after an already validated native claim/PDP join. Real claim validation and mandatory CAS remain in place; unserved legacy review paths are unchanged. 414 regression tests passed, including frozen approved-request comparisons and consume-refusal/backend isolation. The attended owner procedure is in platform scripts/t03-native-execution.py and t03-attended-delivery.py. It uses the exact scoped client reader, contained platform administration, named/pinned native pods, private runtime storage, and native CLI handlers. No approval has yet been consumed by this preparation.

Attended reader handoff pending — 2026-09-14

Informed Decision confirms three native submissions and delivered audit records; Approval Engine still records all three actions approved and unconsumed. The attended reader login exited 5 before handing off the command. Warden removed its isolated helper/home; it could not confirm revocation of any possible issued login session. No owner procedure started, no approval was consumed and no provider key was read. Asked the operator whether the browser sign-in window opened before retrying. Do not repeat the human memo approvals. T03 remains wait for the attended credential flow and actual execution. Metadata receipt: docs/evidence/2026-09-14-t03-approved-awaiting-reader.json.

Identity recovery and latest attended attempt — 2026-09-14

KeyCape's expired factor-reader credential recovered after restoring scheduling headroom for its native renewal Job; recurring capacity is handed to CUST-WP-0071-T01. The latest attempt obtained and validated the scoped reader, but its nested administrator handoff failed before the native execution worker started. All three approvals remain approved and unconsumed. Reader revocation was confirmed; helper roots and private runtime directories were removed. Administrator revocation cannot be inferred from the outer receipt.

Native preflight also exposed workstation clock drift. The approved runtime clock source change from tsc to hyperv_clocksource_tsc_page plus restarting systemd-timesyncd briefly established synchronization, but the latest check again reports unsynchronized. No persistent boot configuration was changed. This is not a confirmed clock fix. T03 remains wait and owns stable-time verification, the attended-login diagnosis and actual native execution as live remaining work. Do not repeat the human memo reviews or consume requests until those prerequisites pass. The bounded decision-start wait preserves actual validity boundaries; the complete regression suite passed 420 tests. Receipt: docs/evidence/2026-09-14-t03-login-recovery.json; platform attempt: docs/evidence/2026-09-14-t03-attended-delivery-attempt-02.json.

Renewal after Clock deployment — 2026-09-16

Original native claims report expired (2026-09-15 00:33 UTC); the earlier advice not to repeat reviews is superseded by this expiry. No old approval was extended or copied. The admitted requester created three new 24-hour requests, using Railiance Clock for token validity and request times; Warden completed with self-revocation. Exact action/binding digests and installed recipient are unchanged. New approval IDs: apply 9935335c-8e9a-566e-a48e-6a5b5f4882eb, verify 273d6882-6253-5dc9-ac54-544f92ef5e56, exec 7ba0c13b-68cd-5b3e-9481-42ba9e385e68.

All three existing memo identifiers now have immutable version 2, addressed to uid=platform-root,ou=people,dc=netkingdom,dc=local. They are published with zero human dispositions/approval entries. The shared site's seven existing sitting reviews retain their exact bindings and version-1 mandate in the active policy. 57 local and 20 native caller-policy checks passed; unrelated groups are refused. The exact frozen execution request/recipient preflight also passed.

Execution helper now requires an admitted Clock trust file and uses the private OpenBao relay; its Python environment contains the Clock dependencies. Refresh its 15-minute boot-bound admission immediately before the attended operation. T03 remains wait for the real human acknowledgements/acceptance and then native apply, verify, consume, key check and revocation. No OpenRouter key was read or inference performed. Review expiry is 2026-09-16 22:28 UTC (September 17 00:28 Europe/Berlin). Evidence: docs/evidence/2026-09-16-t03-renewed-review-handoff.json.

T03 completed with native delivery — 2026-09-16

All three renewed version-2 memos received real human acceptance. Native claims/PDP checks and separate CAS consumption preceded apply, verify and exec. The bounded policy/AppRole was applied; positive read and unrelated-reader negative verification passed. The exact pinned recipient authenticated with OpenRouter GET /api/v1/key (HTTP 200). Explicit revoked-token lookup returned 403, unrelated paths were denied, llm-connect and ESO remained ready, private runtime storage was removed, and the final attended Warden procedure exited 0.

The initial procedure stopped after successful verify because a supplemental probe used the admin helper after the scoped client cleared its token. The failure receipt is retained. A guarded continuation revalidated the applied objects and native consumption state, repaired the probe and executed only the remaining approval. No consumed action was replayed. Four focused recovery checks and frozen recipient/request preflight passed.

Canonical receipt: docs/evidence/2026-09-16-t03-completion.json; original attempt and continuation are linked there. No provider key rotation, inference or campaign billing reconciliation occurred. Existing general adoption/routing work remains in SECRETS-WP-0006-T05/T06 and SECRETS-WP-0007-T04/T07 (handoff notes added). IR-WP-0005 owns radar delivery acceptance, IR-WP-0006 the pending USD 0.023712 reservation and USD 10 ceiling. Fresh-login reliability is the live residual INFD-IN-0005. The three consumed approvals cannot authorize a future key check or a different trial recipient. This closes the bounded T03 objective, not those broader work records.