Link WP-0025 T06 residual to net-kingdom intakes NK-IN-0001/0002.
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 7s

Point residual and ops-sso-access design at the file-backed work records
in net-kingdom rather than informal coordination notes.
This commit is contained in:
tegwick 2026-07-22 10:47:25 +02:00
parent 91353df7d0
commit 652e799969
2 changed files with 21 additions and 2 deletions

View file

@ -48,8 +48,15 @@ Response headers trusted into the app:
### Access control policy
Authelia global `default_policy: one_factor` currently applies. MVP accepts any
authenticated Authelia user. Follow-up (T06): LLDAP group
`activity-core-operators` + Authelia domain rules (net-kingdom config change).
authenticated Authelia user. Follow-up (T06) is filed as work-record intakes
in **net-kingdom** (not hub-only notes):
| Intake | Scope |
| --- | --- |
| `NK-IN-0001` | LLDAP group `activity-core-operators` + membership runbook |
| `NK-IN-0002` | Authelia domain rules for `activity` + `temporal` hosts |
See `net-kingdom/docs/intakes/activity-core-ops-sso-operators.md`.
## Mutation identity

View file

@ -281,5 +281,17 @@ state_hub_task_id: "f73eafbf-ad11-4d7d-b89e-e910c662ce86"
(net-kingdom Authelia access_control rules). Until then any authenticated
Authelia user can reach the UIs (org-wide SSO, not least-privilege).
**Work-record handoff (implementer = net-kingdom):**
| Intake | Owner repo | Scope |
| --- | --- | --- |
| `NK-IN-0001` | net-kingdom | LLDAP group `activity-core-operators` + membership runbook |
| `NK-IN-0002` | net-kingdom | Authelia `access_control` domain rules for both public hosts |
Source file (canonical):
`net-kingdom/docs/intakes/activity-core-ops-sso-operators.md`
When both intakes are promoted/done, mark **T06** `done` and finish this WP.
**Operator:** open https://activity.coulomb.social/ops/ui once, confirm inventory
loads and a safe mutation (or dry path) shows `sso:<you>` in `/ops/audits`.