Revised: the Anthropic licence manager is a module holding a seat, and the agent's configuration lives in its managed directory
The operator's directions, taken during review: the host is module-agnostic and never writes a vendor's file or anything under a home; the controller has no part; a real licence manager doles out the correct licence in every situation; it talks to the agent module on every node over the bus; the seat is named for the vendor, since the agent is coupled to an Anthropic grant, not to "a model". - ADR 0178 rewritten: `claude-licence-manager` holds the mesh seat `anthropic-licence-manager`, owns the licences, grants (encrypted with a key the vault made for it), bindings per touchpoint, usage and audit; one rotation source under a lease; tokens travel module to module sealed to each node's module key on request/reply, never as an event; the agent module alone writes what the agent reads; the exception to ADR 0113 stated and bounded. Dated mechanism notes on ADR 0050 and 0113. - To-be 37 (new): the manager — its store, the two licence kinds, keeping a grant alive, the hand-over, who gets which licence with the predecessor's fallbacks, adoption with the identity guard, verbs. - To-be 36 rewritten: the mesh's part of the agent's configuration lives in the agent's machine-wide managed directory (settings, tool servers, instruction file), owned whole by the module and written by its code; the home is found except the credentials file; the API-key licence through the key-helper writes nothing under the home; the console as a node-scoped provision; MCP servers as settings with an `mcp_configure` tool; the six predecessor files removed by the operator. - Records 0169–0171 renumbered to 0176–0178 after main gained 0169–0175 today.
This commit is contained in:
@@ -283,3 +283,13 @@ modules in the catalogue require it — so a shared secret is a requirement answ
|
||||
which is what this record asks for. Private keys are still made where they are used and never
|
||||
travel, which is the other half and was never in question.
|
||||
|
||||
|
||||
> **The mechanism changed — 2026-10-02, by [ADR 0178](0178-the-anthropic-licence-manager-is-a-module-and-hands-tokens-to-the-agent-over-the-bus.md).**
|
||||
> What stands: every shared secret the mesh makes is the vault's, a private key is made where it is
|
||||
> used, and a long-lived value a backend issues enters the vault's custody — here as the key the vault
|
||||
> makes for the licence manager, which encrypts the vendor's grants at rest with it. What this record
|
||||
> did not foresee: a credential that lives hours, issued by a vendor to the one module that holds its
|
||||
> grant, and handed by that module to the agent on each node sealed to that node's module key, on
|
||||
> request/reply over the bus, never through the vault and never as a file the host writes. ADR 0178
|
||||
> states that as a bounded exception — one vendor, tokens that live hours, one recipient per message —
|
||||
> and a second such channel is a decision of its own.
|
||||
|
||||
Reference in New Issue
Block a user