flex-auth/examples/tenant-engine/README.md
tegwick 87f114f036
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 32s
Restore flex-auth-tenant-engine to the seven-action policy image
FLEX-WP-0013. Production had been rolled back to sha256:c25fc34a
(four actions), so tenant.update / tenant.retire / tenant.reactivate
denied unknown_action. Re-pin and apply the previously-live
sha256:9320df39 image (e9911eb). Live probe after restore: all seven
actions allow; misspelled action and unknown subject still deny.
user-engine pin unchanged. TEN-WP-0006 guardrail actions not added.
2026-08-16 02:36:56 +02:00

5.1 KiB

tenant-engine Consumer Integration Fixtures

FLEX-WP-0008-T01/T02. Registers tenant-engine as a flex-auth protected-system consumer, gating its own write API (TEN-WP-0003's authz.FlexAuthWriteAuthorizer).

Files

File Purpose
protected_system_manifest.yaml Resource types (tenant, role-grant, plan-assignment) and the seven actions: tenant.create, tenant.role.grant, tenant.role.revoke, tenant.plan.assign, plus the FLEX-WP-0010 lifecycle actions tenant.update, tenant.retire, tenant.reactivate
subject_manifest.yaml The one registered caller: tenant-engine's own service identity
policy_package.md Rego rules + embedded tests gating the write API
policy_fixtures.yaml Allow/deny request/decision pairs, referenced by policy_package.md's frontmatter
registry_snapshot.json Merged systems/subjects/groups snapshot assembled from the two manifests above, loadable by flex-auth serve/check/load-registry
check_request_allow_create.json, check_request_deny_unknown_subject.json, check_request_allow_retire.json, check_request_deny_misspelled_lifecycle.json Standalone example requests for flex-auth check

No resource_manifest.yaml — unlike ops-warden's fixed SSH-certificate inventory, tenant-engine's resources (tenants) are created dynamically. See docs/tenant-engine-resource-namespace.md for why that's a deliberate omission, not an oversight.

Verified

go build -o bin/flex-auth ./cmd/flex-auth

# Rego rules + embedded tests + fixtures, all pass:
bin/flex-auth test-policy -file examples/tenant-engine/policy_package.md

# Registry loads cleanly:
bin/flex-auth load-registry -file examples/tenant-engine/registry_snapshot.json

# Individual requests via the CLI:
bin/flex-auth check \
  -registry examples/tenant-engine/registry_snapshot.json \
  -policy examples/tenant-engine/policy_package.md \
  -request examples/tenant-engine/check_request_allow_create.json

# End-to-end over real HTTP: a live `flex-auth serve` loaded with this
# exact registry+policy, hit by tenant-engine's actual
# FlexAuthCheckClient/FlexAuthWriteAuthorizer (not a mock) --
# POST /tenants with actor="ops" -> 403 (unknown_subject);
# actor="tenant-engine" -> 201 (write_api_policy_matched).
bin/flex-auth serve -addr 127.0.0.1:9098 \
  -registry examples/tenant-engine/registry_snapshot.json \
  -policy examples/tenant-engine/policy_package.md
# (from tenant-engine's own checkout)
TENANT_ENGINE_FLEX_AUTH_URL=http://127.0.0.1:9098 make run

Verified — lifecycle actions (FLEX-WP-0010-T03, 2026-08-10)

test-policy reports 11/11 Rego tests and 16/16 fixtures passing, the registry loads, and go test ./... / gofmt / go vet are clean.

End-to-end over real HTTP: a live flex-auth serve on 127.0.0.1:9098 loaded with this registry and policy, and a real tenant-engine (TENANT_ENGINE_FLEX_AUTH_URL=http://127.0.0.1:9098) driven through its unmodified FlexAuthWriteAuthorizer with Idempotency-Key and an If-Match echoed from a prior GET:

Call tenant-engine flex-auth decision
POST /tenants 201 decision:174dc9ecb03ed9e5 allow write_api_policy_matched
PATCH /tenants/t-e2e-1 200 active decision:6176c39c2f4d7b15 allow write_api_policy_matched
POST /tenants/t-e2e-1/retire 200 retired decision:8a801b8ee8455080 allow write_api_policy_matched
POST /tenants/t-e2e-1/reactivate 200 active decision:c64cf3713cecd970 allow write_api_policy_matched
POST .../retire as actor: ops 403 write_denied decision:59d3e99c6416be89 deny unknown_subject

The misspelled-action guard (tenant.retired → deny unknown_action) is covered by fixture and by check -request check_request_deny_misspelled_lifecycle.json; it cannot be driven through the client, which only ever emits the seven registered strings — which is the property the guard exists to protect.

In production as of FLEX-WP-0013 (2026-08-16). The live flex-auth-tenant-engine Deployment on railiance01 runs sha256:9320df394a642eff24da8af4a0ee8886a7bb78b0f14d8ee1deeb30ea8eeeaba7 (CI-built from e9911eb). Probed against the Service after restore:

Action Effect Decision
tenant.create allow write_api_policy_matched decision:2a94b9ee0dcb4050
tenant.update allow write_api_policy_matched decision:422fe875467610fb
tenant.retire allow write_api_policy_matched decision:799301d3443fd6a4
tenant.reactivate allow write_api_policy_matched decision:4160478ca5499457
tenant.retired (typo) deny unknown_action decision:30946c43cbe80bfc
unregistered subject deny unknown_subject decision:7b107e73cf16fab9

Rollback target is sha256:c25fc34a… (four-action). TEN-WP-0006 guardrail actions are not in this image.

  • docs/tenant-engine-resource-namespace.md
  • docs/tenant-engine-action-vocabulary.md
  • tenant-engine/docs/flex-auth-integration.md — the client side of this integration
  • net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md