diff --git a/docs/ops-sso-access.md b/docs/ops-sso-access.md index 9a6f7a2..c69af46 100644 --- a/docs/ops-sso-access.md +++ b/docs/ops-sso-access.md @@ -48,8 +48,15 @@ Response headers trusted into the app: ### Access control policy Authelia global `default_policy: one_factor` currently applies. MVP accepts any -authenticated Authelia user. Follow-up (T06): LLDAP group -`activity-core-operators` + Authelia domain rules (net-kingdom config change). +authenticated Authelia user. Follow-up (T06) is filed as work-record intakes +in **net-kingdom** (not hub-only notes): + +| Intake | Scope | +| --- | --- | +| `NK-IN-0001` | LLDAP group `activity-core-operators` + membership runbook | +| `NK-IN-0002` | Authelia domain rules for `activity` + `temporal` hosts | + +See `net-kingdom/docs/intakes/activity-core-ops-sso-operators.md`. ## Mutation identity diff --git a/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md b/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md index 1657eca..70614be 100644 --- a/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md +++ b/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md @@ -281,5 +281,17 @@ state_hub_task_id: "f73eafbf-ad11-4d7d-b89e-e910c662ce86" (net-kingdom Authelia access_control rules). Until then any authenticated Authelia user can reach the UIs (org-wide SSO, not least-privilege). +**Work-record handoff (implementer = net-kingdom):** + +| Intake | Owner repo | Scope | +| --- | --- | --- | +| `NK-IN-0001` | net-kingdom | LLDAP group `activity-core-operators` + membership runbook | +| `NK-IN-0002` | net-kingdom | Authelia `access_control` domain rules for both public hosts | + +Source file (canonical): +`net-kingdom/docs/intakes/activity-core-ops-sso-operators.md` + +When both intakes are promoted/done, mark **T06** `done` and finish this WP. + **Operator:** open https://activity.coulomb.social/ops/ui once, confirm inventory loads and a safe mutation (or dry path) shows `sso:` in `/ops/audits`.