A VM e2e that plays out the Anthropic model-access refreshable-grant flow with the vendor OAuth endpoint stubbed (ADR 0050), asserting the one property the carve-out rests on: the refresh token reaches only the manager node (host-unsealed), the control plane is handed only the access token + an opaque box, and the consuming node writes an access-token-only credential — the refresh token is nowhere on the consuming node nor in the control-plane database.
Two harness capabilities this exposed and added: build-module-runtime.sh now installs a module's own non-@novox runtime deps under the module's subtree in the image (first needed by the manager's tweetnacl-sealedbox-js); and grant/token files the adopt/refresh containers write 0600 are relaxed to 0644 on the host before docker cp into the distroless mesh-control (all ciphertext or access token, never a cleartext refresh token).
SUITE_EXIT=0.
A VM e2e that plays out the Anthropic model-access refreshable-grant flow with the vendor OAuth endpoint stubbed (ADR 0050), asserting the one property the carve-out rests on: the refresh token reaches only the manager node (host-unsealed), the control plane is handed only the access token + an opaque box, and the consuming node writes an access-token-only credential — the refresh token is nowhere on the consuming node nor in the control-plane database.
Two harness capabilities this exposed and added: `build-module-runtime.sh` now installs a module's own non-@novox runtime deps under the module's subtree in the image (first needed by the manager's `tweetnacl-sealedbox-js`); and grant/token files the adopt/refresh containers write 0600 are relaxed to 0644 on the host before `docker cp` into the distroless mesh-control (all ciphertext or access token, never a cleartext refresh token).
SUITE_EXIT=0.
A lab bed for Phase C of model-access (ADR 0050), OAuth endpoint stubbed.
It drives the real runtime images through the whole flow: the manager
seals a refresh token at rest and opens it on the manager node alone,
mesh-control is handed only the access token and an opaque re-sealed
envelope via licence submit-refresh, and the consumer writes an
access-token-only credential. Asserts the refresh token -- original and
rotated -- is nowhere on the consuming node and only ciphertext in the
control plane's database.
build-module-runtime.sh also compiles adopt/refresh/apply/usage
entrypoints. Stubbed and flagged: the vendor endpoint, the manager node's
private key (mounted; a host capability to deliver it does not exist
today), and the submit transport (the test invokes the CLI on the
manager's output).
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
The bed follows the reworked flow: the manager module seals the refresh token to the node's
PUBLIC key, the HOST unseals it and mounts the cleartext at the manager's bound path, and the
refresh reads that cleartext -- no fake node key pair is mounted any more, the host uses its
own real sealing key.
- the manager is a model-access holder deployed first, so its bound facts (carrying the node
public key) are delivered; the consumer is added only once an access token exists to seal.
- adopt reads the node public key from the bound facts; the test asserts the host mounts the
cleartext refresh token for the manager, and that it reaches nowhere on the consuming node.
- the refresh_grant assertion reads { sealed, manager_key }.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Two harness fixes the green end-to-end run needed:
- build-module-runtime.sh installs a module's non-@novox runtime deps under
/app/modules/<module>/node_modules, so a module can carry a private dependency
(the anthropic-manager seals with tweetnacl-sealedbox-js). The shared tree still
answers @novox/* and common packages. A no-op for modules that declare none.
- stageIntoControl chmods the manager's 0600 adopt/refresh outputs to 0644 on the
anchor host before docker cp, so the distroless mesh-control (non-root, no chmod)
can read the staged file. What is staged is a sealed box or the access token,
never a cleartext refresh token.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
A VM e2e that plays out the Anthropic model-access refreshable-grant flow with the vendor OAuth endpoint stubbed (ADR 0050), asserting the one property the carve-out rests on: the refresh token reaches only the manager node (host-unsealed), the control plane is handed only the access token + an opaque box, and the consuming node writes an access-token-only credential — the refresh token is nowhere on the consuming node nor in the control-plane database.
Two harness capabilities this exposed and added:
build-module-runtime.shnow installs a module's own non-@novox runtime deps under the module's subtree in the image (first needed by the manager'stweetnacl-sealedbox-js); and grant/token files the adopt/refresh containers write 0600 are relaxed to 0644 on the host beforedocker cpinto the distroless mesh-control (all ciphertext or access token, never a cleartext refresh token).SUITE_EXIT=0.
The bed follows the reworked flow: the manager module seals the refresh token to the node's PUBLIC key, the HOST unseals it and mounts the cleartext at the manager's bound path, and the refresh reads that cleartext -- no fake node key pair is mounted any more, the host uses its own real sealing key. - the manager is a model-access holder deployed first, so its bound facts (carrying the node public key) are delivered; the consumer is added only once an access token exists to seal. - adopt reads the node public key from the bound facts; the test asserts the host mounts the cleartext refresh token for the manager, and that it reaches nowhere on the consuming node. - the refresh_grant assertion reads { sealed, manager_key }. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF