Commit graph

12 commits

Author SHA1 Message Date
bc78cd27fc Adopt stage-1 capability cut and product capability model
Persist capability/feature vocabulary, v0 model, and founder stage-1 must set
(onboarding, spaces/pages with Title/Abstract/Visual, page copy and transfer).
Mark CSOC-WP-0001-T03 done; add CSOC-WP-0006 for implementation.
2026-08-12 13:09:09 +02:00
3a74d004f0 Inventory Bubble surface and sketch migration mapping (CSOC-WP-0001)
Record public meta, Research/vw_pages routes, integrations, and content
hypothesis. Provisional Postgres+Forgejo mapping awaits Bubble export.
2026-08-12 11:10:14 +02:00
c521adc2f9 Publish CSOC-WP-0005 resource demand and cost evidence
Add low/base/high demand forecasts, service objectives with timestamped
observations, and workload operations labor for resource:tenant:coulomb:coulomb-social.
2026-08-12 11:07:03 +02:00
edfdd79208 Finish CSOC-WP-0003 and CSOC-WP-0004; residual intakes for Case B
Close self-registration workplan with Case A proven and Create account
entry implemented; park public registration enablement and identity
negatives as CSOC-IN-0001/0002. Complete app-shell workplan with T06
operator runbook (seed, bind, webhook, smoke) and smoke doc updates.
2026-08-12 10:59:25 +02:00
29a9ff735e Complete identity smoke path: id_token claims, registration entry, cutover docs
Prefer verified KeyCape id_token claims when /userinfo returns 401; soft-fail
userinfo. Add CSOC-WP-0003 registration entry (disabled until NetKingdom URL),
AAL step-up hooks, smoke/cutover evidence for tegwick OIDC without MFA.
2026-08-09 22:42:51 +02:00
b1c5c1bdfb Mark CSOC-WP-0002-T08 packaging done after first cluster deploy
Image 7067145 on Forgejo; Helm release ready; migrations on apps-pg.
Public DNS/TLS cutover remains residual.
2026-08-09 02:33:02 +02:00
44439f8d8d Complete flex-auth PEP and document railiance packaging path
Local + HTTP POST /v1/check PEP with fail-closed transport errors;
shell:view enforced on /app/. Vocabulary docs for T07. Helm chart lives
in railiance-apps; Dockerfile already present for T08.
2026-08-09 02:00:12 +02:00
d88767f05b Wire user-engine HTTP /me for member provisioning (CSOC-WP-0002-T04)
HttpUserEngineClient uses trusted-proxy claims against live user-engine.
Offline stub when URL/secret unset. Align default tenant with KeyCape
tenant:coulomb; map OIDC tenant/principal_type/groups into the envelope.
2026-08-09 01:56:44 +02:00
76ec8cfe41 Register coulomb-social OIDC client on live KeyCape (CSOC-WP-0002-T03)
Public PKCE client on kc.coulomb.social with local and production redirect
URIs. Add register-keycape-client.sh, document env, and harden public-client
token exchange (no secret). Authorize probe verified registered vs reject.
2026-08-09 01:50:51 +02:00
01da195c13 Implement NetKingdom identity shell for coulomb.social (CSOC-WP-0002)
Django scaffold aligned with the business delivery lane: tenant-keyed
Member model without passwords, identity app as sole OIDC/session
boundary, dev-claims login, authenticated /app/ shell, ADR-0001, and
tests. T01/T02/T05/T06 done; OIDC registration, real user-engine HTTP,
flex-auth, and packaging remain open.
2026-08-09 01:45:05 +02:00
0ca0a9b4d4 Point intent/scope at NetKingdom user-management path (CSOC-WP-0002)
Register CSOC-WP-0002 for identity-first reestablish; defer Bubble content
claim behind the authenticated shell. CSOC-WP-0001 notes the priority shift.
2026-08-09 01:36:28 +02:00
0da8d36a73 Bootstrap coulomb-social: INTENT, SCOPE, TRSL, agent files, State Hub
Prepare the greenfield rebuild of coulomb.social (bubble.io exit) with
orientation docs, TRSL license, Claude/Codex agent integration, and repo
classification under domain communication / topic coulomb-social. Workplan
CSOC-WP-0001 (exit assessment) is already registered via fix-consistency.
2026-08-09 00:35:12 +02:00