Prove the host and the people before root sees a single argv.
Cut 81 turns target discovery, a signed 18-field dedicated-host claim, two exact source commits, eight artifact digests, four distinct approvals and an independent ≤60-second stopped-state preflight into one fail-closed admission transaction. The current production Portal host is denied; no live permit exists.
Discovery is an evidence source, not an assumption
The workspace cannot enumerate the AWS account because the inventory client is unavailable. One reachable host was observed independently; it is not promoted into the candidate pool.
The reachable Portal host fails four independent gates
Reachability and sudo are operational facts, never qualification evidence.
Eighteen fields make “dedicated” independently testable
A valid claim binds cloud identity, workload class, collision state, prior absence, observation time, nonce and a verify-only key.
Host truth expires in five minutes
The independent preflight is stricter: sixty seconds. Both must be fresh inside the same maintenance window.
Two commits and eight content addresses define the only installable set
Cut 80 supplies authorization logic; Cut 79 supplies the root manifest, identity and six client modules. Unit files, secrets and production values are excluded.
| # | Artifact | Target | Binding | Live |
|---|---|---|---|---|
| 01 | Dedicated identity | /var/lib/reits-runner-factory | descriptor digest | ABSENT |
| 02 | Root manifest | /etc/reits-runner-factory/controller-runtime.json | canonical byte digest | ABSENT |
| 03–08 | Six read / verify clients | /opt/reits-runner-factory/client-modules/cut79 | six SHA-256 digests | ABSENT |
| — | systemd / secrets / values | outside transaction | explicit false | DENIED |
One ticket binds target, source, artifacts, time and rollback
Changing any bound field invalidates all approval signatures instead of silently widening authority.
TARGET runner-controller-staging-01.internal · i-0abc1234def567890
RELEASE 3513be5a528b8a1796d11c1a564c33e8ca46d3e3
INSTALL 9214f9f46bafd5cd75276a44bbbe441a4449c177
ARTIFACTS 8 · WINDOW 1800s · ROLLBACK REQUIRED
START false · LISTENER false · DATA ACCESS false
No single operator can qualify, approve, execute and witness
Roles, principals and P-256 keys are all distinct. The auditor participates in authorization but still cannot mutate the target.
Six verified envelopes; zero signing authority in the broker
The admission broker receives only public verify capability. Host claim, four approvals and independent preflight remain separately attributable.
Thirty minutes is a cryptographic boundary
Approvals may precede the window by no more than fifteen minutes. Claims or preflights outside their expiry are denied before any capability is projected.
The final read is separate, target-bound and ≤ 60 seconds old
It repeats the dangerous checks immediately before authorization, using a key distinct from host qualification and all four approvers.
Authorization must preserve a host with nothing running
Even a valid authorization may install only eight artifacts in Cut 82. It never includes a unit, process, listener, resolved ConfigRef or secret.
Discovery enters first; live execution never enters
Every projection is derived from verified evidence and ends at a no-permit hold while live inputs remain absent.
The repository receipt is deliberately not an installation permit
It contains no hostname capability, shell, argv, transport or executor. Its production authorization fields are fixed false.
livePermitIssued=false
Qualify once, project once, then destroy the handle
Nonces prevent cross-envelope substitution. WeakMap ownership prevents JSON forgery. Receipt digests prevent terminal-field inflation.
The earliest invalid boundary wins
A failure never falls through to the Cut 80 executor. All host and runtime effect counters remain zero.
| Failure | Decision | Executor | Live effect |
|---|---|---|---|
| Inventory unavailable | show incomplete discovery | not constructed | 0 |
| Shared / marked host | deny claim | not constructed | 0 |
| Approval drift | deny signature set | not constructed | 0 |
| Stale preflight | deny freshness | not constructed | 0 |
| Receipt tamper | deny digest | not constructed | 0 |
Six new repository gates close the authorization design
All six are exercised with signed fixtures. None is reported as live production evidence.
Repository, shared EC2 and future staging never share a verdict
The matrix keeps “verified logic” separate from “observed live authorization.”
| Boundary | Repository | Current EC2 | Future dedicated host |
|---|---|---|---|
| Discovery | contract bound | one reachable | account inventory required |
| Host claim | P-256 fixture | four denials | live signed claim |
| Change | 4 fixture approvals | 0 production | 4 live approvals |
| Preflight | ≤60s fixture | not eligible | independent live reread |
| Permit | verify-only receipt | 0 | one-time Cut 82 permit |
| Activation | denied | 0 process / 8110 | still denied |
Interrogate the authorization failure model
Filter signed rehearsals, host fences, authority drift, stale windows, stopped-state failures and capability attacks. Select a case for its exact zero-effect verdict.
The only red gate is live signed evidence
Logic, schemas, real P-256 verification, source binding, freshness, replay and zero-effect invariants are closed.
Six owned fragments remain before stopped-state installation
Each gap has one owner and one observable close condition. Activation remains outside this chain.
The authorization broker cannot touch a host
Its only injected capability is signature verification. The real shared EC2 remains unchanged.
Consume live evidence; install eight artifacts; remain stopped.
Cut 82 may execute only after account-scoped inventory, a live signed dedicated-host claim, four live approvals and a fresh independent preflight close the red gate. It must then use the Cut 80 argv-only executor, obtain eight independent readbacks, roll back within the window, and still leave systemd, service start and 8110 outside scope.