Board minutes #62 Decision 2 (server-26#64), due 2026-08-31. CTO draft #60
finding 1 and CISO draft #61 finding 3 reached this independently.
GET/PUT /admin/features accepted only a Firebase admin token, so the unattended
runbook had no headless path and SSHed into the c2-core container to write
config/ai_features with the admin SDK. Moving a platform-wide AI cost switch
required a full container shell, and set_flags() wrote no audit entry either
way, so a flag flip was unattributable however it happened.
- New agent_service_key (AGENT_SERVICE_KEY), deliberately separate from the
Discord bot's service_key. Sharing one key would collapse two principals into
a single unattributable identity in every log line, and the bot has no
business flipping AI flags regardless.
- require_agent_key_or_admin accepts the agent key or a Firebase admin, and
rejects the Discord key. The "key is configured" guard is load-bearing:
compare_digest("", "") is a match, so a deployment that never set the key
would otherwise accept an empty credential.
- set_flags() writes an audit_log entry with before/after values and the actor,
wrapped so an audit failure cannot lose the flag write or 500 the route.
- Cascade helper sets the global doc and every system carrying an ai_flags
override in one call. A global False already beats everything, but a system
False beats a global True, so turning AI *on* could half-apply and leave a
radio system hot after shutoff. It scans for the override rather than
hardcoding the two known system IDs, so a new system cannot silently defeat
it.
- cascade defaults to False. PUT /systems/{id}/ai-flags and the AiFlagsPanel
toggle mean a per-system override is deliberate operator intent; cascading by
default would erase it on any unrelated global flip. The runbook opts in.
Issue items 5 and 6 (retiring the SSH path from drb-worksession.md) are NOT
done here and the runbook is untouched. The credential does not exist in
production yet, so the SSH path is still the only one that works; retiring it
now would break the next unattended run. Owner activation is recorded on #64.
Tests 273 -> 289.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>