Commit graph

6 commits

Author SHA1 Message Date
e80fdced13 Add Dockerfile for coulomb-social delivery-lane packaging
Non-root gunicorn image with /healthz check; railiance-apps values still open.
2026-08-09 01:57:02 +02:00
d88767f05b Wire user-engine HTTP /me for member provisioning (CSOC-WP-0002-T04)
HttpUserEngineClient uses trusted-proxy claims against live user-engine.
Offline stub when URL/secret unset. Align default tenant with KeyCape
tenant:coulomb; map OIDC tenant/principal_type/groups into the envelope.
2026-08-09 01:56:44 +02:00
76ec8cfe41 Register coulomb-social OIDC client on live KeyCape (CSOC-WP-0002-T03)
Public PKCE client on kc.coulomb.social with local and production redirect
URIs. Add register-keycape-client.sh, document env, and harden public-client
token exchange (no secret). Authorize probe verified registered vs reject.
2026-08-09 01:50:51 +02:00
01da195c13 Implement NetKingdom identity shell for coulomb.social (CSOC-WP-0002)
Django scaffold aligned with the business delivery lane: tenant-keyed
Member model without passwords, identity app as sole OIDC/session
boundary, dev-claims login, authenticated /app/ shell, ADR-0001, and
tests. T01/T02/T05/T06 done; OIDC registration, real user-engine HTTP,
flex-auth, and packaging remain open.
2026-08-09 01:45:05 +02:00
0ca0a9b4d4 Point intent/scope at NetKingdom user-management path (CSOC-WP-0002)
Register CSOC-WP-0002 for identity-first reestablish; defer Bubble content
claim behind the authenticated shell. CSOC-WP-0001 notes the priority shift.
2026-08-09 01:36:28 +02:00
custodian-sync
c0189118b4 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-08-09:
  - workplan status: ready → active
2026-08-09 00:34:39 +02:00