P45 authorization admission · verify-only

Prove the host and the people before root sees a single argv.

Cut 81 turns target discovery, a signed 18-field dedicated-host claim, two exact source commits, eight artifact digests, four distinct approvals and an independent ≤60-second stopped-state preflight into one fail-closed admission transaction. The current production Portal host is denied; no live permit exists.

81 / 104global cut
23cuts remaining
0qualified live hosts
4required approvals
272P-256 verifies
70 / 71quality gates
Host inventory

Discovery is an evidence source, not an assumption

The workspace cannot enumerate the AWS account because the inventory client is unavailable. One reachable host was observed independently; it is not promoted into the candidate pool.

01
INVENTORY PROVIDERAWS CLIUNAVAILABLE IN WORKSPACE
CANDIDATE POOL0 qualified / 1 reachableFAIL CLOSED
ACCOUNT SCOPEUnverified
REGION SCOPEap-southeast-2 observed
PAID RESOURCES0 created
Current EC2 denial

The reachable Portal host fails four independent gates

Reachability and sudo are operational facts, never qualification evidence.

02
/etc/reits-production-hostpresentDENY
127.0.0.1:8100one Portal listenerDENY
UID 991 = redis6identity collisionDENY
GID 991 = nginxgroup collisionDENY
Controller filesmanifest + modules absentOBSERVED
Port 8110zero listenersSTOPPED
Signed host claim anatomy

Eighteen fields make “dedicated” independently testable

A valid claim binds cloud identity, workload class, collision state, prior absence, observation time, nonce and a verify-only key.

03
Claim freshness

Host truth expires in five minutes

The independent preflight is stricter: sixty seconds. Both must be fresh inside the same maintenance window.

04
T−15mapproval floor
T−10mreview freeze
T−5mhost claim
T−60spreflight
T0qualify
+1 useproject
+0 exechold
T+30mwindow close
Artifact binding

Two commits and eight content addresses define the only installable set

Cut 80 supplies authorization logic; Cut 79 supplies the root manifest, identity and six client modules. Unit files, secrets and production values are excluded.

05
#ArtifactTargetBindingLive
01Dedicated identity/var/lib/reits-runner-factorydescriptor digestABSENT
02Root manifest/etc/reits-runner-factory/controller-runtime.jsoncanonical byte digestABSENT
03–08Six read / verify clients/opt/reits-runner-factory/client-modules/cut79six SHA-256 digestsABSENT
—systemd / secrets / valuesoutside transactionexplicit falseDENIED
Change scope

One ticket binds target, source, artifacts, time and rollback

Changing any bound field invalidates all approval signatures instead of silently widening authority.

06
CHANGE chg-cut81-p45-staging-fixture
TARGET runner-controller-staging-01.internal · i-0abc1234def567890
RELEASE 3513be5a528b8a1796d11c1a564c33e8ca46d3e3
INSTALL 9214f9f46bafd5cd75276a44bbbe441a4449c177
ARTIFACTS 8 · WINDOW 1800s · ROLLBACK REQUIRED
START false · LISTENER false · DATA ACCESS false
Four-party approvals

No single operator can qualify, approve, execute and witness

Roles, principals and P-256 keys are all distinct. The auditor participates in authorization but still cannot mutate the target.

07
✓Platform SREwindow · rollback
✓Release Authoritysource · artifacts
✓Security Reviewerroot boundary
✓Independent Auditorpreflight · readback
Signature topology

Six verified envelopes; zero signing authority in the broker

The admission broker receives only public verify capability. Host claim, four approvals and independent preflight remain separately attributable.

08
HOST QUALIFIERclaim signature
→
FOUR AUTHORITIES4 scope signatures
→
PREFLIGHT WITNESSfresh state signature
Window control

Thirty minutes is a cryptographic boundary

Approvals may precede the window by no more than fifteen minutes. Claims or preflights outside their expiry are denied before any capability is projected.

09
06:00:00Zwindow opens
06:09:00Zhost observed
06:09:30Zpreflight observed
06:10:00Zfixture qualification
06:10:30Zpreflight expires
06:30:00Zwindow closes
Independent preflight

The final read is separate, target-bound and ≤ 60 seconds old

It repeats the dangerous checks immediately before authorization, using a key distinct from host qualification and all four approvers.

10
Stopped-state proof

Authorization must preserve a host with nothing running

Even a valid authorization may install only eight artifacts in Cut 82. It never includes a unit, process, listener, resolved ConfigRef or secret.

11
0systemd units
0Controller processes
08110 listeners
0ConfigRef resolves
0Secret reads
0Portal changes
Twelve-stage admission transaction

Discovery enters first; live execution never enters

Every projection is derived from verified evidence and ends at a no-permit hold while live inputs remain absent.

12
01Bind Cut 80P45A–F
02Inventory0 targets
03Host claim18 fields
04Artifacts8 digests
05Change scopeexact
06Approvals4 / 4
07Window1800s
08Preflight12 checks
09Key splitdistinct
10Handleopaque
11Projectone use
12Holdlive permit 0
Opaque permit boundary

The repository receipt is deliberately not an installation permit

It contains no hostname capability, shell, argv, transport or executor. Its production authorization fields are fixed false.

13
INPUT6 signed evidence envelopeshost · 4 approvals · preflight
×
OUTPUTverify-only fixture receiptproductionInstallAuthorized=false
livePermitIssued=false
Replay defense

Qualify once, project once, then destroy the handle

Nonces prevent cross-envelope substitution. WeakMap ownership prevents JSON forgery. Receipt digests prevent terminal-field inflation.

14
Duplicate qualifyRF_G04_P45A_REPLAYDENY
Forged handleRF_G04_P45A_HANDLEDENY
Second projectionhandle already consumedDENY
Receipt inflationdigest mismatchDENY
Nonce reusehost ≠ preflightDENY
Target substitutionhost + instance mismatchDENY
Failure containment

The earliest invalid boundary wins

A failure never falls through to the Cut 80 executor. All host and runtime effect counters remain zero.

15
FailureDecisionExecutorLive effect
Inventory unavailableshow incomplete discoverynot constructed0
Shared / marked hostdeny claimnot constructed0
Approval driftdeny signature setnot constructed0
Stale preflightdeny freshnessnot constructed0
Receipt tamperdeny digestnot constructed0
P45G–L subgates

Six new repository gates close the authorization design

All six are exercised with signed fixtures. None is reported as live production evidence.

16
P45Ginventory + denial
P45Hsigned host claim
P45Ifour approvals
P45Jsource + window
P45Kfresh preflight
P45Lone-time projection
LIVE P45receipts missing
Trust boundary matrix

Repository, shared EC2 and future staging never share a verdict

The matrix keeps “verified logic” separate from “observed live authorization.”

17
BoundaryRepositoryCurrent EC2Future dedicated host
Discoverycontract boundone reachableaccount inventory required
Host claimP-256 fixturefour denialslive signed claim
Change4 fixture approvals0 production4 live approvals
Preflight≤60s fixturenot eligibleindependent live reread
Permitverify-only receipt0one-time Cut 82 permit
Activationdenied0 process / 8110still denied
156-case executable QA lab

Interrogate the authorization failure model

Filter signed rehearsals, host fences, authority drift, stale windows, stopped-state failures and capability attacks. Select a case for its exact zero-effect verdict.

18
156 / 156 cases
70 / 71 quality gates

The only red gate is live signed evidence

Logic, schemas, real P-256 verification, source binding, freshness, replay and zero-effect invariants are closed.

19
Q01–Q25Host claimbound
Q26–Q35Artifactsbound
Q36–Q55Changebound
Q56–Q62Preflightbound
Q63–Q70Receiptbound
LIVE P45Real receiptsnot observed
Visible integration debt

Six owned fragments remain before stopped-state installation

Each gap has one owner and one observable close condition. Activation remains outside this chain.

20
01 · Cloud inventoryAccount-scoped host enumeration.
02 · Dedicated hostSigned live staging claim.
03 · Four live approvalsOne exact change digest.
04 · Live preflightIndependent and ≤60 seconds.
05 · One-time permitIssued only after all live evidence.
06 · Stopped installCut 82; no unit/start/8110.
Zero-effect production firewall

The authorization broker cannot touch a host

Its only injected capability is signature verification. The real shared EC2 remains unchanged.

21
0host contacts
0root processes
0host mutations
0live permits
0service starts
08110 calls
Cut 82 handoff

Consume live evidence; install eight artifacts; remain stopped.

Cut 82 may execute only after account-scoped inventory, a live signed dedicated-host claim, four live approvals and a fresh independent preflight close the red gate. It must then use the Cut 80 argv-only executor, obtain eight independent readbacks, roll back within the window, and still leave systemd, service start and 8110 outside scope.

22
1 · Discoveraccount inventory
2 · Authorize6 signed envelopes
3 · Install8 artifacts only
4 · Witnessreadback + stopped