flex-auth/examples/user-engine
tegwick 4dcc69b41b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 53s
Close FLEX-WP-0009 with live user-engine policy evidence
T04 is done: nine fixtures including registration-applicant match the
deployed /v1/check, user-engine is on the fail-closed HTTP adapter, and
the deploy manifest now pins the live digest.
2026-08-16 01:16:23 +02:00
..
policy_fixtures.yaml Authorize scoped public registration applicants 2026-08-14 09:26:12 +02:00
policy_package.md Authorize scoped public registration applicants 2026-08-14 09:26:12 +02:00
README.md Close FLEX-WP-0009 with live user-engine policy evidence 2026-08-16 01:16:23 +02:00
registry_snapshot.json Authorize scoped public registration applicants 2026-08-14 09:26:12 +02:00

user-engine policy service

Dynamic human subjects arrive as verified KeyCape claims, so the registry defines the protected system while the policy evaluates tenant, roles, and self context from each request. Platform operators may cross tenants; tenant administrators and self-service users may not.

Validate with:

flex-auth test-policy -file examples/user-engine/policy_package.md
flex-auth load-registry -file examples/user-engine/registry_snapshot.json

Live production (FLEX-WP-0009-T04, 2026-08-16)

Service: flex-auth-user-engine.flex-auth.svc.cluster.local:8080 Image: forgejo.coulomb.social/coulomb/flex-auth@sha256:1f5290376dc5fcf456dc7a785e394d8b90949dabecd1d3e856f38557149bb5f4

test-policy reports 9/9 Rego tests and 9/9 fixtures. The same nine fixtures were replayed against the deployed /v1/check and all matched:

Fixture Effect / reason Decision id
self-allow allow / self_service decision:27cbab2e5533508a
tenant-admin-allow allow / tenant_admin decision:350b46fb42989606
platform-allow allow / platform_operator decision:79334537419466bd
cross-tenant-deny deny / cross_tenant decision:b3cc0b7e819aecde
missing-role-deny deny / no_matching_role_or_context decision:818e2249491ef09f
wrong-system-deny deny / wrong_system decision:5e20697e202aa7c6
registration-applicant-allow allow / registration_applicant decision:d83fc413afebf2f6
registration-applicant-membership-deny deny / no_matching_role_or_context decision:4ca487126987f89c
registration-applicant-wrong-issuer-deny deny / no_matching_role_or_context decision:138c574dee279d23

From the user-engine namespace the Service /healthz is HTTP 200. Unavailability is connection-refused / NXDOMAIN; the consumer adapter denies with authorization service unavailable.