Technical report / Version 1
Receipt-Gated Model Serving: Routing to a confidential model host only after a signed admission receipt
OPAQUE Systems
Abstract
A confidential model host has to exist before it can attest, so the Pod comes first. The open question is when clients may reach it. This report describes a mechanism that answers it with evidence. A planner produces a bootstrap Pod that holds only encrypted model material, and produces the Kubernetes Service that routes to it only after it has verified a signed admission receipt for that exact hosting session: pinned signer key, first position in the receipt chain, and equality with six application bindings (tenant, model, encrypted artifact, workload, policy, transport). A signed, terminal lifecycle receipt for the same session removes the route. Because the planner keeps no state, a controller carries a durable, monotonic per-session ledger, so a session that has been revoked can never be routed again from its old admission. We evaluated the planner in an internal repository at two commits, and a reference implementation published with this report. The planner passed its 6 selected tests, rejected six correctly signed receipts that each carried one wrong binding, and, as expected for a stateless component, still accepted an old admission after revocation. The controller, run against a fake Kubernetes API in which every action is a fresh process, kept every revoked session unroutable across all 12 cases of its test matrix. Removing the ledger check, or keeping the ledger in memory, failed 7 of 12 cases. Restoring an old copy of the ledger reopened a revoked session, so the ledger itself needs rollback protection. The evidence is software only; no cluster, confidential GPU or model inference was used.
What this report contributes
A routing gate for confidential model hosts: the Kubernetes Service exists only from a verified first admission receipt for one session, and a durable per-session ledger keeps revoked sessions unroutable.
Evidence and limits
- Software-only. No cluster, Service proxy, confidential GPU or model inference was used; the controller ran against a fake Kubernetes API, and no revocation latency was measured.
- The evaluated planner is internal and its source is not published; the public reference implementation reproduces every result. Restoring an old ledger copy reopened a revoked session.
- Deleting a Service does not close open connections or other paths to the Pod, and the selector label can be set by anyone with Pod write access.
The source package preserves the recorded inputs and results. Every experiment was rerun on October 1, 2026 in a fresh environment against both evaluated commits and the reference implementation. No independent replication is claimed.
No separate specification exists for this mechanism. The reference implementation in the source package is the implementation guidance.
Cite this report
Imran Siddique. Receipt-Gated Model Serving: Routing to a confidential model host only after a signed admission receipt. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026receiptgatedmodelserving,
title = {Receipt-Gated Model Serving: Routing to a confidential model host only after a signed admission receipt},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23091307},
url = {https://agentrust-io.com/research/receipt-gated-model-serving/v1/}
}
Version history
Version 1, October 1, 2026: First public edition. Evaluates an internal planner at two commits and a published reference implementation, rerun on October 1, 2026, and fixes a revocation-chaining defect found after the September 27 draft.
Based on an internal study drafted September 23, 2026; an internal draft followed on September 27, 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the AgenTrust public issue tracker and identify the report version and section.