docs(readme): microVM guests no longer hold provider keys
Proven on tank: claude backend (01a0cfc1, MET, pushed) and kimi backend (01a0cfd5: 0 direct connections to api.kimi.com, down from 4; work delivered; judge unavailable only because GLM is out of quota and Kimi cannot judge Kimi). Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
eb1137ed68
commit
0cfaca94e7
@@ -229,7 +229,6 @@ source file. It is **not currently run in CI**, and 12 files exceed the hard lim
|
|||||||
|
|
||||||
**Next**
|
**Next**
|
||||||
- Enforce task permission and argument provenance (both still in shadow, gathering evidence).
|
- Enforce task permission and argument provenance (both still in shadow, gathering evidence).
|
||||||
- Route microVM missions' model calls through the LLM proxy too, so no guest holds a provider key.
|
|
||||||
- Evidence the remaining team templates (4 of 12 still need a target stack: mobile, gpu, threejs, and
|
- Evidence the remaining team templates (4 of 12 still need a target stack: mobile, gpu, threejs, and
|
||||||
`insight_research`).
|
`insight_research`).
|
||||||
- A dedicated judge key, so no other consumer of a shared provider plan can starve the judge.
|
- A dedicated judge key, so no other consumer of a shared provider plan can starve the judge.
|
||||||
@@ -260,9 +259,10 @@ structures, never gives an agent more reach than its sandbox. What that means to
|
|||||||
container holds a per-mission token, Claude Code's base URL points at the server's proxy on an
|
container holds a per-mission token, Claude Code's base URL points at the server's proxy on an
|
||||||
unpublished port, and the proxy adds the real credential — honouring the token only while its mission
|
unpublished port, and the proxy adds the real credential — honouring the token only while its mission
|
||||||
is running. Behind that, delivery refuses to push any change containing a server key, and every
|
is running. Behind that, delivery refuses to push any change containing a server key, and every
|
||||||
recorded event, judge verdict and judge input is redacted. MicroVM missions still receive their
|
recorded event, judge verdict and judge input is redacted. **MicroVM guests hold no provider key
|
||||||
backend's key in the guest, behind the egress allow-list. The server reaches Docker through an
|
either** (node daemon 0.5.0+): the guest's CLI talks to its own loopback, fcagent pipes that to the
|
||||||
allow-listed socket proxy.
|
node, and the node relays it to the proxy on the server's tailnet-only port — no key on the node or in
|
||||||
|
the guest. The server reaches Docker through an allow-listed socket proxy.
|
||||||
- The gate is a guardrail against accidents and obvious exfiltration, not a boundary against a
|
- The gate is a guardrail against accidents and obvious exfiltration, not a boundary against a
|
||||||
determined agent (indirection defeats string matching). The boundaries are the VM, the network policy
|
determined agent (indirection defeats string matching). The boundaries are the VM, the network policy
|
||||||
and the broker.
|
and the broker.
|
||||||
|
|||||||
Reference in New Issue
Block a user