Prepare the access-engine repository coordinate without applying the rename.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 1m16s

FLEX-WP-0020 T01-T03: fresh preflight is zero-blocker, repository-only
scope is FLEX-DEC-2026-013, concurrent work is FLEX-DEC-2026-014.
T04 handoff requests are posted; owner work-records are still required.
T06 stays behind the exact human confirm string and a post-commit preflight.

Assistant: grok
Assistant-Session: 01a0a6cb-0334-72c0-83b0-2df57474a0f6
This commit is contained in:
tegwick 2026-09-15 23:38:48 +02:00
parent 0e020b2d8c
commit dcda1e603f
5 changed files with 166 additions and 7 deletions

View file

@ -3,6 +3,14 @@
Policy-as-code authorization registry and control plane for NetKingdom-aligned Policy-as-code authorization registry and control plane for NetKingdom-aligned
systems. systems.
The live Forge and State Hub coordinate is still `flex-auth` (repository UUID
`fda8ad85-a7d7-4055-8f21-902a533e59df`, Forge ID `42`). `FLEX-WP-0020` will
rename that coordinate to `access-engine` and keep the Go module, binary,
`FLEX_AUTH_*` variables, Helm releases, container package
`coulomb/flex-auth`, and policy/API vocabulary unchanged. Work-record
frontmatter stays `repo: flex-auth` until State Hub rebind. Planned clone:
`https://forgejo.coulomb.social/coulomb/access-engine.git`.
Start with [INTENT.md](INTENT.md) for the project boundary and direction. Start with [INTENT.md](INTENT.md) for the project boundary and direction.
Research notes and ADRs live in [docs/](docs/) and [docs/adr/](docs/adr/). Research notes and ADRs live in [docs/](docs/) and [docs/adr/](docs/adr/).

View file

@ -1797,3 +1797,39 @@ review of the assertions.
- Bears on `FLEX-DEC-2026-011` F1. A PEP cannot verify who answered; it now at - Bears on `FLEX-DEC-2026-011` F1. A PEP cannot verify who answered; it now at
least can verify that the answer is about the request it sent. Those are least can verify that the answer is about the request it sent. Those are
different properties and neither substitutes for the other. different properties and neither substitutes for the other.
---
## FLEX-DEC-2026-013 — Repository-only scope for the access-engine coordinate
**Date:** 2026-09-15
**Status:** accepted
**Workplan:** `FLEX-WP-0020-T03`
**Hub:** `9f2dd7a4-6437-4e59-8403-ae56d9cc1d09`
Rename the Forge/State Hub repository coordinate to `access-engine`. Retain
the Go module `github.com/netkingdom/flex-auth`, binary/CLI, `FLEX_AUTH_*`
variables, Kubernetes namespace/Services/Helm, container package
`coulomb/flex-auth`, policy/API vocabulary, audiences, and telemetry labels.
Keep the `FLEX-WP-` prefix and every existing State Hub UUID. A broader
product/runtime rebrand needs a later workplan after soak.
This is the reviewed table already written in `FLEX-WP-0020`. Changing a
`retain` row returns that plan to `proposed`.
---
## FLEX-DEC-2026-014 — Concurrent work may remain open during FLEX-WP-0020 cutover
**Date:** 2026-09-15
**Status:** accepted
**Workplan:** `FLEX-WP-0020-T01` / `T05`
`FLEX-WP-0027-T03` stays `wait` (operator human review of three T03 memos).
`FLEX-WP-0022` T01/T02 stay open (tenant-engine must name the CheckRequest
tenant relation; T03 fixtures landed without a policy change). Neither
changes repository identity, Forge ID, or the source UUID. They do not have
to finish before a repository-coordinate rename, and they must not be
cancelled or rewritten by it. Live Forge apply (`T06`) still needs the exact
human confirmation string and a fresh zero-blocker preflight of the commit
being renamed.

View file

@ -0,0 +1,47 @@
# FLEX-WP-0020-T01 — identity baseline (2026-09-15)
Private preflight file is `/tmp/flex-auth-rename-preflight-0020.json` (mode 0600).
It is not committed. Token material stays there.
| Field | Value |
| --- | --- |
| State Hub UUID | `fda8ad85-a7d7-4055-8f21-902a533e59df` |
| Forge repository ID | `42` |
| Forge full name | `coulomb/flex-auth` |
| Default branch | `main` |
| Local path | `/home/worsch/flex-auth` |
| Remote | `forgejo-remote:coulomb/flex-auth.git` |
| Clone URL | `https://forgejo.coulomb.social/coulomb/flex-auth.git` |
| Host paths | railiance01 `/home/tegwick/flex-auth`; `bnt-lap001` `/home/worsch/flex-auth` |
| Protected/current aliases | `flex-auth` (canonical) |
| Target slug | `access-engine` (Forge reports none yet; available) |
| Preflight `safe_to_apply` | `true` |
| Blockers | none |
| Queued edge writes | none |
| Warning | `active_work_present` (15 tasks / 8 workplans) |
| Report checksum (this capture) | `4b930464e0b92137902481d39cd89b1b2458a8ea88ad08c7ac0c86f2427e7c76` |
| Signing | no longer the August 29 `preflight_signing_unavailable` blocker |
Captured `HEAD` at inspection was `6fd3a0cbc400b9128132497fca69d0096259800c`.
A later commit on this workplan requires a fresh T05 preflight before
`forge-renamed`.
## Active-work disposition (FLEX-DEC-2026-014)
- `FLEX-WP-0017` and `FLEX-WP-0019` are finished (the August 29 snapshot is stale).
- `FLEX-WP-0027-T03` remains `wait` — human review, not a source-identity change.
- `FLEX-WP-0022` T01/T02 remain open; T03 is fixture-only. Coordinate rename
must not cancel them.
- `FLEX-WP-0020` itself is the cutover plan.
Working tree at inspection: branch `main`, tracking `origin/main`, clean
before this workplan's source edits.
## Proposed mutations (from preflight)
1. Forgejo `name`: `flex-auth``access-engine` (`forge-renamed`)
2. State Hub `managed_repos.slug`: `flex-auth``access-engine` (`statehub-rebound`)
3. State Hub `managed_repos.remote_url`: `forgejo-remote:coulomb/flex-auth.git``https://forgejo.coulomb.social/coulomb/access-engine.git`
4. Slug registry: `flex-auth:canonical``flex-auth:alias, access-engine:canonical`
No runtime Deployment, image, or policy-package mutation is in this list.

View file

@ -0,0 +1,49 @@
# FLEX-WP-0020-T04 — consumer inventory and handoff requests
Status: requests sent. Owner work-record IDs are not invented here.
Handoff JSON cannot be schema-valid until each owner creates a live
workplan/task; those IDs fill `handoff_id` / `owning_work_record`.
Do not mark external work done from this repository.
Shared identity for every request:
- renamed_repository_id: `fda8ad85-a7d7-4055-8f21-902a533e59df`
- old_slug: `flex-auth`
- new_slug: `access-engine`
- Forge ID stays `42`
- runtime/product names stay `flex-auth` (FLEX-DEC-2026-013)
| Owner | Surface | Required change / verification | Owner work-record |
| --- | --- | --- | --- |
| `railiance-fabric` | fabric-projection | Update `registry/local-repos.yaml`, `registry/railiance-repos.yaml`, live `fabric/**` `repo: flex-auth`; re-ingest; keep `flex-auth.*` runtime graph IDs | pending |
| `ops-warden` | credential-route | Review `registry/routing/catalog.yaml` owner repository field; routing must still resolve; no secret in the reply | pending |
| `reuse-surface` | other | Update federation source URL/path, re-ingest, verify capability continuity | pending |
| `policy-nexus` | other | Update `source-inventory.config.json` remote URL; re-ingest same publication lineage | pending |
| `user-engine` | documentation | Update `wiki/ArchitectureBlueprint.md` absolute source path; adapter/runtime vocabulary stays `flex-auth` | pending |
| `net-kingdom` | deployment | Verify three live `flex-auth-*` Deployments and `sso-mfa/k8s/**`; no runtime rename | pending |
| `tenant-engine` | consumer | Verify docs/client config keep the retained product/runtime contract | pending |
| `sbom-nexus` | sbom | Re-ingest new canonical checkout; snapshots remain related to the UUID above | pending |
| `repo-manager` | other | Reconcile new canonical path; do not rewrite archived UUID-migration evidence | pending |
| `railiance-platform`, `markitect-tool`, `gate-house`, `approval-engine`, `secrets-engine`, `zone-engine` | consumer | Confirm no live repository URL/path remains; retain product/runtime terminology | pending |
| `flex-auth` + Forgejo operator | ci / package | `.forgejo/workflows/image.yaml`, charts, deploy, releases, packages, hooks, Actions, deploy keys, branch protection, redirects, clone URLs. Only repository coordinates change. Image name stays `coulomb/flex-auth`. | this plan |
Request message IDs (not owner work-records):
| Owner | Message ID |
| --- | --- |
| tenant-engine (T01 question) | `e8ba6a53-0093-4dc0-ad70-01f6b8c8e76b` |
| tenant-engine (0020 verify) | `08b3edfa-c478-45c9-9b2f-4c0fcdf471e7` |
| railiance-fabric | `10d4b1a2-8976-42a5-8d76-6fc1ce54fe87` |
| ops-warden | `0a1956c5-9fd2-4e52-837e-5bfa8e47e83d` |
| reuse-surface | `08919217-1d82-4600-a2e8-e3d9949fabab` |
| policy-nexus | `d861dc4f-11b5-4c73-a98c-8d261e65d65e` |
| user-engine | `94fd6ef0-28b5-4481-a207-2adabab93893` |
| net-kingdom | `3bc95c76-abac-4f20-95ff-a74dcc1d6fd9` |
| sbom-nexus | `08540a29-ecd4-47bc-a87c-7eecf80f166a` |
| repo-manager | `0a4b1825-99b1-4e1e-a4a0-448b0347b744` |
| railiance-platform | `b55a40cb-eb03-4972-a9bc-aac6e131a63e` |
| markitect-tool | `0dd0d6af-12fd-4b3e-af4e-1f294d615039` |
| gate-house | `231460c6-0235-4c22-9f7d-cff3959496ed` |
| approval-engine | `2523510b-79d6-4123-b550-6386dae4d464` |
| secrets-engine | `15cf351a-bad8-4259-9b6f-b21d183a20ab` |
| zone-engine | `40adbd61-0155-44f8-b6a7-621ff1629c46` |

View file

@ -4,12 +4,12 @@ type: workplan
title: "Repository identity migration from flex-auth to access-engine" title: "Repository identity migration from flex-auth to access-engine"
domain: "infotech" domain: "infotech"
repo: "flex-auth" repo: "flex-auth"
status: proposed status: active
flavor: planning flavor: planning
owner: "codex" owner: "codex"
topic_slug: "netkingdom" topic_slug: "netkingdom"
created: "2026-08-29" created: "2026-08-29"
updated: "2026-08-29" updated: "2026-09-15"
reviewed_at: "2026-08-29" reviewed_at: "2026-08-29"
reviewed_by: codex reviewed_by: codex
reviewed_against_commit: "7d7b4531d15a2dde7aaa28b9360a13e77b28b2a9" reviewed_against_commit: "7d7b4531d15a2dde7aaa28b9360a13e77b28b2a9"
@ -137,7 +137,7 @@ the two live workplans; it must not silently cancel or rewrite them.
```task ```task
id: FLEX-WP-0020-T01 id: FLEX-WP-0020-T01
status: todo status: done
priority: high priority: high
state_hub_task_id: "bb989019-50a7-5273-ba09-b2df2e2602a4" state_hub_task_id: "bb989019-50a7-5273-ba09-b2df2e2602a4"
``` ```
@ -156,11 +156,16 @@ Owner: `flex-auth`.
Gate: repository UUID, Forge ID, branch, commit, and clean-state evidence are Gate: repository UUID, Forge ID, branch, commit, and clean-state evidence are
recorded and match a fresh State Hub preflight. recorded and match a fresh State Hub preflight.
2026-09-15: captured in `docs/evidence/2026-09-15-repository-rename-baseline.md`.
Signing is no longer a blocker. `safe_to_apply=true`, zero blockers, warning
`active_work_present` disposed by `FLEX-DEC-2026-014`. A later commit still
needs a T05 preflight before `forge-renamed`.
## 2. Prepare repository metadata and work-record frontmatter ## 2. Prepare repository metadata and work-record frontmatter
```task ```task
id: FLEX-WP-0020-T02 id: FLEX-WP-0020-T02
status: todo status: done
priority: high priority: high
state_hub_task_id: "102e9dc7-4724-5e80-84c4-092e6ecfbb2b" state_hub_task_id: "102e9dc7-4724-5e80-84c4-092e6ecfbb2b"
``` ```
@ -179,11 +184,14 @@ Owner: `flex-auth`.
Gate: work-record parsing succeeds and no existing UUID field was removed, Gate: work-record parsing succeeds and no existing UUID field was removed,
replaced, or invented. replaced, or invented.
2026-09-15: README states the planned `access-engine` clone URL and that
frontmatter stays `repo: flex-auth` until rebind. No UUID fields rewritten.
## 3. Decide product and runtime naming separately ## 3. Decide product and runtime naming separately
```task ```task
id: FLEX-WP-0020-T03 id: FLEX-WP-0020-T03
status: todo status: done
priority: high priority: high
state_hub_task_id: "5095ddbc-b69c-5a52-b97f-08fca9b610c3" state_hub_task_id: "5095ddbc-b69c-5a52-b97f-08fca9b610c3"
``` ```
@ -209,11 +217,13 @@ rollback limits are reviewed.
Gate: every item has a decision record and independently deployable changes Gate: every item has a decision record and independently deployable changes
have their own workplan or residual handoff. have their own workplan or residual handoff.
2026-09-15: accepted as `FLEX-DEC-2026-013` / hub `9f2dd7a4-6437-4e59-8403-ae56d9cc1d09`.
## 4. Inventory consumers and create owned handoffs ## 4. Inventory consumers and create owned handoffs
```task ```task
id: FLEX-WP-0020-T04 id: FLEX-WP-0020-T04
status: todo status: progress
priority: high priority: high
state_hub_task_id: "9bb138e1-5edb-5714-8d89-3b1b7039a7ce" state_hub_task_id: "9bb138e1-5edb-5714-8d89-3b1b7039a7ce"
``` ```
@ -239,6 +249,10 @@ Owner: `flex-auth` for inventory and handoff creation only.
Gate: every discovered external change has one named owning repository and Gate: every discovered external change has one named owning repository and
durable handoff ID; unknown ownership blocks the live rename. durable handoff ID; unknown ownership blocks the live rename.
2026-09-15: inventory in `docs/evidence/2026-09-15-repository-rename-handoffs.md`.
Owner work-record IDs are requested, not invented. T06 stays blocked on those
IDs plus the human confirm string.
Reviewed inventory baseline: Reviewed inventory baseline:
| Owner | Required source/verification surface | | Owner | Required source/verification surface |
@ -259,7 +273,7 @@ Reviewed inventory baseline:
```task ```task
id: FLEX-WP-0020-T05 id: FLEX-WP-0020-T05
status: todo status: wait
priority: high priority: high
state_hub_task_id: "86fecbb6-b008-5354-8d70-0f4ba5077a58" state_hub_task_id: "86fecbb6-b008-5354-8d70-0f4ba5077a58"
``` ```
@ -280,6 +294,11 @@ window, rollback limits, and confirmation `rename:fda8ad85-a7d7-4055-8f21-902a53
Gate: a current private preflight and explicit human approval exist. Never Gate: a current private preflight and explicit human approval exist. Never
commit the private preflight file or its token. commit the private preflight file or its token.
2026-09-15: signing is provisioned; a private preflight of `6fd3a0c` was
zero-blocker. Re-run after this source commit. Human confirmation of
`rename:fda8ad85-a7d7-4055-8f21-902a533e59df:flex-auth:access-engine` is still
required before T06. Do not start the journal from this session.
## 6. Execute the Forgejo repository rename ## 6. Execute the Forgejo repository rename
```task ```task