Commit graph

30 commits

Author SHA1 Message Date
custodian-sync
ea8dc12cbc chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-11:
  - update .custodian-brief.md for coulomb-social
2026-08-11 02:32:49 +02:00
422cd613f6 Add app home Spaces shell and session diagnostics profile menu
Post-login lands on Spaces empty state instead of a principal dump.
Profile menu exposes Session details with identity, tenant, roles/groups,
and authz diagnostics for operator refinement (CSOC-WP-0004 T01/T07).
2026-08-11 02:31:55 +02:00
custodian-sync
8169102866 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-10:
  - update .custodian-brief.md for coulomb-social
2026-08-10 09:40:52 +02:00
d36795faa6 Plan product path: app shell and Forgejo markdown spaces
Mark CSOC-WP-0002 identity done on app.coulomb.social. Defer bulk Bubble
migration until product foundation exists. Open CSOC-WP-0004 for post-login
entry and space content as markdown bound to Forgejo.
2026-08-10 09:40:25 +02:00
f5537d8365 Serve the rebuild on app.coulomb.social; defer apex Bubble cutover
Document parallel-host strategy: Railiance on app.*, Bubble remains on
coulomb.social until data and self-registration are ready.
2026-08-09 23:20:30 +02:00
custodian-sync
fe8b96a388 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 22:44:35 +02:00
29a9ff735e Complete identity smoke path: id_token claims, registration entry, cutover docs
Prefer verified KeyCape id_token claims when /userinfo returns 401; soft-fail
userinfo. Add CSOC-WP-0003 registration entry (disabled until NetKingdom URL),
AAL step-up hooks, smoke/cutover evidence for tegwick OIDC without MFA.
2026-08-09 22:42:51 +02:00
custodian-sync
3bc16b581b chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 21:55:48 +02:00
b1c5c1bdfb Mark CSOC-WP-0002-T08 packaging done after first cluster deploy
Image 7067145 on Forgejo; Helm release ready; migrations on apps-pg.
Public DNS/TLS cutover remains residual.
2026-08-09 02:33:02 +02:00
custodian-sync
40b05e4c05 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 02:33:01 +02:00
7067145bb0 Disable SECURE_SSL_REDIRECT by default behind ingress TLS
Kubelet probes hit the pod over HTTP; redirect-on-all-requests breaks
readiness. TLS remains terminated at Traefik/ingress.
2026-08-09 02:24:02 +02:00
c71fb0fda9 Document and wrap coulomb-social-env secret script
Point operators at railiance-apps create-coulomb-social-env-secret.sh
via scripts/create-env-secret.sh for production Secret assembly.
2026-08-09 02:04:33 +02:00
44439f8d8d Complete flex-auth PEP and document railiance packaging path
Local + HTTP POST /v1/check PEP with fail-closed transport errors;
shell:view enforced on /app/. Vocabulary docs for T07. Helm chart lives
in railiance-apps; Dockerfile already present for T08.
2026-08-09 02:00:12 +02:00
custodian-sync
0e973a91aa chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 02:00:11 +02:00
e80fdced13 Add Dockerfile for coulomb-social delivery-lane packaging
Non-root gunicorn image with /healthz check; railiance-apps values still open.
2026-08-09 01:57:02 +02:00
d88767f05b Wire user-engine HTTP /me for member provisioning (CSOC-WP-0002-T04)
HttpUserEngineClient uses trusted-proxy claims against live user-engine.
Offline stub when URL/secret unset. Align default tenant with KeyCape
tenant:coulomb; map OIDC tenant/principal_type/groups into the envelope.
2026-08-09 01:56:44 +02:00
custodian-sync
a6a380b19f chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 01:56:43 +02:00
76ec8cfe41 Register coulomb-social OIDC client on live KeyCape (CSOC-WP-0002-T03)
Public PKCE client on kc.coulomb.social with local and production redirect
URIs. Add register-keycape-client.sh, document env, and harden public-client
token exchange (no secret). Authorize probe verified registered vs reject.
2026-08-09 01:50:51 +02:00
custodian-sync
179b20ceed chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 01:50:33 +02:00
01da195c13 Implement NetKingdom identity shell for coulomb.social (CSOC-WP-0002)
Django scaffold aligned with the business delivery lane: tenant-keyed
Member model without passwords, identity app as sole OIDC/session
boundary, dev-claims login, authenticated /app/ shell, ADR-0001, and
tests. T01/T02/T05/T06 done; OIDC registration, real user-engine HTTP,
flex-auth, and packaging remain open.
2026-08-09 01:45:05 +02:00
custodian-sync
2ec7761504 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 01:44:50 +02:00
0ca0a9b4d4 Point intent/scope at NetKingdom user-management path (CSOC-WP-0002)
Register CSOC-WP-0002 for identity-first reestablish; defer Bubble content
claim behind the authenticated shell. CSOC-WP-0001 notes the priority shift.
2026-08-09 01:36:28 +02:00
custodian-sync
31186b4b61 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 01:36:08 +02:00
6fe263444a Extract authenticated coulomb.social design language via designlang
Session probe lands on /vw_pages (Research). Use main designlang extract
with --cookie-file — pack ignores auth. 39 artifacts under
docs/design-extract; tolerate designlang late summary crash when cores exist.
2026-08-09 01:31:00 +02:00
319dd00465 Add designlang public-shell pack; tighten auth capture checks
Ran authenticated extract against coulomb.social; session metadata
matched anonymous Bubble defaults, so treat docs/design-extract as a
public shell baseline (PROVENANCE.md). Capture script now refuses to
overwrite storage-state.json with thin anonymous sessions.
2026-08-09 01:22:15 +02:00
0bf740017e Add authenticated designlang extract path for coulomb.social
Interactive Playwright session capture (XDG storageState, mode 0600)
plus a designlang pack wrapper that never prints secrets. Document the
intended OpenBao lane tenants/binky/coulomb-social/bubble-member for
later password custody; interactive capture is the default for Bubble.
2026-08-09 01:15:06 +02:00
0da8d36a73 Bootstrap coulomb-social: INTENT, SCOPE, TRSL, agent files, State Hub
Prepare the greenfield rebuild of coulomb.social (bubble.io exit) with
orientation docs, TRSL license, Claude/Codex agent integration, and repo
classification under domain communication / topic coulomb-social. Workplan
CSOC-WP-0001 (exit assessment) is already registered via fix-consistency.
2026-08-09 00:35:12 +02:00
custodian-sync
c0189118b4 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-08-09:
  - workplan status: ready → active
2026-08-09 00:34:39 +02:00
custodian-sync
ca9c7a88e9 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-09:
  - update .custodian-brief.md for coulomb-social
2026-08-09 00:34:22 +02:00
2af7752723 Initial commit 2026-08-08 22:24:08 +00:00