From bcbf92f3d124b0566b20f4b5ae40824b94fb3a8e Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Sat, 5 Sep 2026 07:05:33 -0700 Subject: [PATCH] =?UTF-8?q?memory:=20svos=20Heimdall=20key=20minted=20?= =?UTF-8?q?=E2=80=94=20worldtree-personal,=20ledger=20key=20verified=20sti?= =?UTF-8?q?ll=20live?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit user_id=svos, key_id=eab3cdbe, wt_live_ format, on worldtree-personal (10.250.50.152:8081). Deployment established by locating the ledger key there rather than assumed: created 2026-07-13, last used today, matching ledger-dev's account exactly. Value vaulted at nh3-dev/development/svos/worldtree-api-key and verified against the mint response before the scratch copy was removed. Delivered by vault path rather than over althing — ledger-dev runs on the same box under the same uid, so the bus never carried the credential. The ledger key was read back from /admin/keys AFTER the mint and is untouched, which is what keeps their deletion ordering possible. Plan tier left unset deliberately and disclosed: the API offers no way to read a user's current tier, so matching it would have been a guess. Also records the operator ruling that worldtree-dev owns code only and no ops, which supersedes the global CLAUDE.md routing of Heimdall auth to worldtree-dev. --- persistent-memory.md | 23 ++++++++++++++++++++--- 1 file changed, 20 insertions(+), 3 deletions(-) diff --git a/persistent-memory.md b/persistent-memory.md index 6e9a741..f15c062 100644 --- a/persistent-memory.md +++ b/persistent-memory.md @@ -181,9 +181,26 @@ below is a live commitment or a known-open risk._ b48a11c), so the redirect is no longer load-bearing for any known consumer. Handle `ledger-dev` → `svos-dev` is an operator action at the post office. -- **OPEN, with ledger-dev: mint a `svos` Heimdall user + API key.** Never actually - asked of me until 2026-09-05 (it sat in their runbook as "awaiting infra-ops" - while addressed to worldtree-dev, who hold no key material). Constraints: string +- **DONE 2026-09-05 — `svos` Heimdall user + API key minted** on operator + authorization. `user_id=svos`, `key_id=eab3cdbe`, suffix `d5ec48c2`, `wt_live_` + format, on **worldtree-personal (10.250.50.152:8081)** — established by finding + the `ledger` key there (created 2026-07-13, last used 2026-09-05T13:34, exactly + as ledger-dev described). Value vaulted at + `nh3-dev/development/svos/worldtree-api-key` (sha 23c10c9c7219, verified on + read-back) and delivered by vault path, NOT over althing — ledger-dev runs on + nh3-dev under the same uid, so the bus never carried the secret. The `ledger` + key was read back after the mint and is untouched and live (`disabled=False`). + ⚠ **Plan tier left UNSET, deliberately**: `POST /admin/keys` takes an optional + tier (user|free|pro|admin|readonly-admin) and there is **no way to read a user's + current tier back** — no GET, `/admin/usage` returns an empty users list, and + `/admin/events` is a live SSE stream, not an audit log. Guessing would have + handed over a key that quietly differs; `POST /admin/users/svos/tier` fixes it in + one call if their cutover hits a limit. **OPERATOR RULING 2026-09-05: worldtree-dev + owns code only, no ops — key material is infra-ops's.** Supersedes the global + CLAUDE.md line routing "Heimdall scopes (Worldtree auth) → worldtree-dev". + +- **Original constraints on that mint** (recorded because the deletion ordering is + a permanent trap, not a one-time step): string `svos` verbatim (WT tier 3 admits only `^[a-z][a-z0-9-]{2,63}$`, INV-181-15); **keep the existing `ledger` key LIVE**, do not revoke. Ordering is load-bearing — `DELETE /agents/{agent_id}` refuses any caller that is not the row's owner, so