Authenticated native session resume — 2026-09-13 UTC
Authenticated native session resume — 2026-09-13 UTC
Both imported native sessions passed authenticated continuation on Titan using an OpenBao-backed OpenRouter credential:
| Native client | Model | Result |
|---|---|---|
| Claude Code, pinned Kelos v0.54.0 image | `anthropic/claude-sonnet-4.6` | Two turns PASS |
| Codex, pinned Kelos v0.54.0 image | `openai/gpt-5.5` | Two turns PASS |
Claude evidence and Codex evidence record the immutable images, model identifiers, turn outcomes, preserved session identity, expected-response assertions, and history preservation. Native API requests went through OpenRouter; these are not subscription-sign-in tests.
For each provider, the runner copied the staged workspace and imported native history into a fresh private directory. It resumed the original session ID and asked the model to remember a unique marker. It then removed that container, started a new container over the same copied state, resumed the same session ID, and requested the marker without including it in the second prompt. Both models returned the exact marker. Both original imported transcript prefixes were preserved, and the host source transcript checksums remained unchanged.
The scoped OpenBao reader fetched the cataloged internal OpenRouter field. Its short-lived Vault token was revoked before model execution. The provider key was sent over SSH stdin, then Docker stdin, and exported only inside the running container process. It was not passed in argv, Docker configured environment, repository files, or a Kubernetes Secret. No host sign-in files were copied. All four test containers were confirmed removed after execution. Private copied histories remain on the test host for investigation and later lifecycle checks.
Reproduce with `scripts/kelos/native_resume.py`: select the provider, explicit model, immutable client image, staged workspace and a fresh output directory; provide the runtime key on stdin through the scoped vault resolver. Concrete operational references remain in private operator configuration. Each turn is bounded to 180 seconds; container cleanup targets its recorded container ID. Reports suppress raw client output and provider diagnostics. The second-turn marker equality and original session identity are required for PASS.
All 30 Python fixture tests passed locally and on Titan. Unit checks verify that a replacement identity fails, the second prompt omits the marker, the key is absent from Docker argv, and raw diagnostics are not exported.
This completes the previously pending authenticated native continuation tests. The complete Kelos-managed Session lifecycle remains NOT_RUN for these imports: Kubernetes Session creation, workspace/PVC ownership, history API, Pod replacement, suspend/resume, and controller recovery still require separate qualification. The overall #820 verdict remains INCOMPLETE. The account-source question is resolved by the user's instruction to use vault credentials.