From 652e79996929d54ecec7b7dcc8e84762ddc62e2b Mon Sep 17 00:00:00 2001 From: tegwick Date: Wed, 22 Jul 2026 10:47:25 +0200 Subject: [PATCH] Link WP-0025 T06 residual to net-kingdom intakes NK-IN-0001/0002. Point residual and ops-sso-access design at the file-backed work records in net-kingdom rather than informal coordination notes. --- docs/ops-sso-access.md | 11 +++++++++-- workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md | 12 ++++++++++++ 2 files changed, 21 insertions(+), 2 deletions(-) diff --git a/docs/ops-sso-access.md b/docs/ops-sso-access.md index 9a6f7a2..c69af46 100644 --- a/docs/ops-sso-access.md +++ b/docs/ops-sso-access.md @@ -48,8 +48,15 @@ Response headers trusted into the app: ### Access control policy Authelia global `default_policy: one_factor` currently applies. MVP accepts any -authenticated Authelia user. Follow-up (T06): LLDAP group -`activity-core-operators` + Authelia domain rules (net-kingdom config change). +authenticated Authelia user. Follow-up (T06) is filed as work-record intakes +in **net-kingdom** (not hub-only notes): + +| Intake | Scope | +| --- | --- | +| `NK-IN-0001` | LLDAP group `activity-core-operators` + membership runbook | +| `NK-IN-0002` | Authelia domain rules for `activity` + `temporal` hosts | + +See `net-kingdom/docs/intakes/activity-core-ops-sso-operators.md`. ## Mutation identity diff --git a/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md b/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md index 1657eca..70614be 100644 --- a/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md +++ b/workplans/ACTIVITY-WP-0025-ops-ui-sso-access.md @@ -281,5 +281,17 @@ state_hub_task_id: "f73eafbf-ad11-4d7d-b89e-e910c662ce86" (net-kingdom Authelia access_control rules). Until then any authenticated Authelia user can reach the UIs (org-wide SSO, not least-privilege). +**Work-record handoff (implementer = net-kingdom):** + +| Intake | Owner repo | Scope | +| --- | --- | --- | +| `NK-IN-0001` | net-kingdom | LLDAP group `activity-core-operators` + membership runbook | +| `NK-IN-0002` | net-kingdom | Authelia `access_control` domain rules for both public hosts | + +Source file (canonical): +`net-kingdom/docs/intakes/activity-core-ops-sso-operators.md` + +When both intakes are promoted/done, mark **T06** `done` and finish this WP. + **Operator:** open https://activity.coulomb.social/ops/ui once, confirm inventory loads and a safe mutation (or dry path) shows `sso:` in `/ops/audits`.