flex-auth/docs/evidence/2026-09-11-user-portal-tenant-policy.md
tegwick 25712f2aad
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
deploy: promote verified portal onboarding policy
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-11 21:07:48 +02:00

1.5 KiB

Native User Engine tenant onboarding policy

Owner coordination: NK-WP-0036-T03. Source dd8dd51743, CI smoke run 159 and image publication run 160 succeeded. Tenant Engine PDP image: forgejo.coulomb.social/coulomb/flex-auth@sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd. Only values/tenant-engine.yaml was promoted, Helm revision 3, readiness passed. Caller auth remains enforce, bound to the Tenant Engine ServiceAccount. Resources remain 25m CPU/32Mi requests. User Engine and other PDP releases did not move.

Runtime checks used the deployed Tenant Engine client and its existing projected ServiceAccount token, kept inside its container. Requests named user-engine, the portal's actual service actor; no actor impersonation or human claims were used. Tenant create/read for tenant:trial:demo-company allow; platform tenant create/read, role grant, plan assign, retirement and guardrail set deny. Without a caller token the PDP returns 401. Policy checks perform no tenant mutations. Subsequent native User Engine adapter readback reports demo-company not found.

Local checks: make test including Go race suite; 27 Rego tests and 35 fixtures; actual registry-enriched create matches v2. Rollback image remains sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b. Rollback denies portal onboarding again; owner and guardrail-reader grants retain their prior semantics. Real operator onboarding is tracked by RAPPS-WP-0014.