anthropic-bed: prove model-access refreshes on the manager node
A lab bed for Phase C of model-access (ADR 0050), OAuth endpoint stubbed. It drives the real runtime images through the whole flow: the manager seals a refresh token at rest and opens it on the manager node alone, mesh-control is handed only the access token and an opaque re-sealed envelope via licence submit-refresh, and the consumer writes an access-token-only credential. Asserts the refresh token -- original and rotated -- is nowhere on the consuming node and only ciphertext in the control plane's database. build-module-runtime.sh also compiles adopt/refresh/apply/usage entrypoints. Stubbed and flagged: the vendor endpoint, the manager node's private key (mounted; a host capability to deliver it does not exist today), and the submit transport (the test invokes the CLI on the manager's output). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -20,8 +20,16 @@ BASE="${RUNTIME_BASE:-node:22-bookworm-slim}"
|
||||
|
||||
( cd "$MESH_SDK" && npm run build >/dev/null )
|
||||
( cd "$MESH_TOOLS" && npm run build >/dev/null )
|
||||
# Compile whichever of the module's entrypoints exist.
|
||||
SRCS=(); for f in client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts; do [ -f "$MOD/$f" ] && SRCS+=("$f"); done
|
||||
# Compile whichever of the module's entrypoints exist. Besides the serve-time entrypoints (tools,
|
||||
# events, provisioner) and the run-once bootstrap, a module may carry scheduled/one-shot entrypoints
|
||||
# it names in a `schedule`/`run-once` container's args (novox/hq ADR 0052/0053) — refresh/apply/usage
|
||||
# for the anthropic model-access modules. tsc pulls in their imports, so leaf files they use are
|
||||
# compiled with them.
|
||||
SRCS=(); for f in \
|
||||
client.ts index.ts tools/index.ts provisioner/index.ts bootstrap/index.ts \
|
||||
adopt/index.ts refresh/index.ts apply/index.ts usage/index.ts; do
|
||||
[ -f "$MOD/$f" ] && SRCS+=("$f")
|
||||
done
|
||||
TSC="$MESH_SDK/node_modules/.bin/tsc"; ( cd "$MOD" && "$TSC" "${SRCS[@]}" --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist >/dev/null )
|
||||
|
||||
STAGE="$(mktemp -d)"; trap 'rm -rf "$STAGE"' EXIT
|
||||
|
||||
Reference in New Issue
Block a user