anthropic-bed: prove model-access refreshes on the manager node

A lab bed for Phase C of model-access (ADR 0050), OAuth endpoint stubbed.
It drives the real runtime images through the whole flow: the manager
seals a refresh token at rest and opens it on the manager node alone,
mesh-control is handed only the access token and an opaque re-sealed
envelope via licence submit-refresh, and the consumer writes an
access-token-only credential. Asserts the refresh token -- original and
rotated -- is nowhere on the consuming node and only ciphertext in the
control plane's database.

build-module-runtime.sh also compiles adopt/refresh/apply/usage
entrypoints. Stubbed and flagged: the vendor endpoint, the manager node's
private key (mounted; a host capability to deliver it does not exist
today), and the submit transport (the test invokes the CLI on the
manager's output).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-07 01:00:37 +02:00
parent 0a132aa00e
commit 6be5072565
3 changed files with 446 additions and 2 deletions
+10 -2
View File
@@ -20,8 +20,16 @@ BASE="${RUNTIME_BASE:-node:22-bookworm-slim}"
( cd "$MESH_SDK" && npm run build >/dev/null )
( cd "$MESH_TOOLS" && npm run build >/dev/null )
# Compile whichever of the module's entrypoints exist.
SRCS=(); for f in client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts; do [ -f "$MOD/$f" ] && SRCS+=("$f"); done
# Compile whichever of the module's entrypoints exist. Besides the serve-time entrypoints (tools,
# events, provisioner) and the run-once bootstrap, a module may carry scheduled/one-shot entrypoints
# it names in a `schedule`/`run-once` container's args (novox/hq ADR 0052/0053) — refresh/apply/usage
# for the anthropic model-access modules. tsc pulls in their imports, so leaf files they use are
# compiled with them.
SRCS=(); for f in \
client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
adopt/index.ts refresh/index.ts apply/index.ts usage/index.ts; do
[ -f "$MOD/$f" ] && SRCS+=("$f")
done
TSC="$MESH_SDK/node_modules/.bin/tsc"; ( cd "$MOD" && "$TSC" "${SRCS[@]}" --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist >/dev/null )
STAGE="$(mktemp -d)"; trap 'rm -rf "$STAGE"' EXIT