flex-auth/workplans/FLEX-WP-0009-user-engine-production-policy-service.md
tegwick 9e6de5a50d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record production gap for FLEX-WP-0010 and re-probe FLEX-WP-0009
FLEX-WP-0010-T04: the deployed flex-auth-tenant-engine Deployment bakes
the policy package into its image, so production still serves the
four-action policy -- probed live, tenant.retire returns deny
unknown_action there while tenant.create allows. TEN-WP-0005-T05 is
unblocked in source but needs an image build from 8e127e5 and a rollout,
which this workplan does not scope. Stated in the workplan and in
examples/tenant-engine/README.md rather than left implied.

FLEX-WP-0009-T04: replayed all six user-engine fixtures against the
deployed flex-auth-user-engine service; all six matched expected effect
and reason, confirming the deployed failure matrix is still fail-closed.
T04 stays in progress -- the criterion also requires user-engine to
retire its local bridge, which is not flex-auth's to close.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 20:55:41 +02:00

4.9 KiB

id type title domain repo status owner topic_slug created updated depends_on state_hub_workstream_id
FLEX-WP-0009 workplan Provide production authorization for user-engine infotech flex-auth active codex netkingdom 2026-08-08 2026-08-08
NK-WP-0024
45756b89-feba-45f5-a24a-63a1119254bf

FLEX-WP-0009 - user-engine production authorization

Provide the cluster-local flex-auth policy-decision service required by the user-engine portal. The consumer contract is net-kingdom/docs/user-engine-platform-expansion-contract.md.

T01 - Pin the protected-system vocabulary

id: FLEX-WP-0009-T01
status: done
priority: high
state_hub_task_id: "e940c5a3-ecb4-43d3-9554-2bfb422ec56d"

Add a user-engine protected-system manifest, resource manifests, subject fixtures, and check-request fixtures. Cover self, tenant-admin, and platform-admin actions over user, membership, invitation, tenant, recovery, and outbox resources. Unknown resources/actions and cross-tenant requests must deny.

Done when all manifests validate and the vocabulary matches the action and resource strings emitted by user-engine.

Done 2026-08-09: examples/user-engine defines the dynamic protected-system registry and verified-claim request vocabulary for platform, tenant-admin, self-service, cross-tenant, missing-role, and wrong-system cases.

T02 - Implement and verify the policy package

id: FLEX-WP-0009-T02
status: done
priority: high
state_hub_task_id: "6e0fe708-d7ff-411f-a64d-84a1692a6e11"

Implement policy-as-code for self-only mutations, tenant-admin authority within one tenant, and platform-admin authority for tenant creation, recovery, outbox delivery, and replay. Include allow, deny, missing-role, target-user mismatch, cross-tenant, malformed-context, and stale-policy fixtures.

Done when fixture evaluation is deterministic, default deny is proven, and decision envelopes contain stable decision IDs and policy provenance.

Done 2026-08-09: all six embedded Rego tests and all six request fixtures pass; the package validates under CARING 0.4.0-rc2 and the registry loads cleanly.

T03 - Deploy the cluster-local service

id: FLEX-WP-0009-T03
status: done
priority: high
state_hub_task_id: "f8293230-136d-4f2d-8d3f-bb9840ea7e63"

Publish an immutable flex-auth image and deploy a namespaced Service at http://flex-auth.flex-auth.svc.cluster.local:8080. Apply least-privilege security context, readiness/liveness probes, resource limits, default-deny NetworkPolicy, and ingress restricted to approved protected systems.

Done when user-engine can reach POST /v1/check, an unrelated namespace cannot, and restart/rollback procedures are documented.

Done 2026-08-09: immutable digest sha256:a31961c45215aa6baf3bc748c6741ab703c2c8325e61aa7983a355026195e51b is deployed as flex-auth-user-engine.flex-auth.svc.cluster.local:8080, Ready behind ingress restricted to the user-engine workload and with no egress.

T04 - Hand back production evidence

id: FLEX-WP-0009-T04
status: progress
priority: high
state_hub_task_id: "97b931e9-ac5b-46c7-a462-e23c0c18c4f4"

Run live allow, deny, service-unavailable, and cross-tenant probes from the user-engine namespace. Record only non-secret decision IDs, effects, reasons, policy version, and correlation IDs. Send completion evidence to NK-WP-0024.

Done when user-engine can replace its local authorization bridge without an availability bypass and the deployed failure matrix remains fail closed.

2026-08-09 live evidence: from the user-engine pod, live-self returned allow with decision decision:4bf95ebb989ac628; the cross-tenant variant returned deny/cross_tenant with decision decision:bab072ce3ee72d98. Runtime activation remains gated on the separately owned event and mail receivers.

2026-08-10 re-probe: all six policy fixtures were replayed against the deployed flex-auth-user-engine.flex-auth.svc.cluster.local:8080 and every one matched its expected effect and reason — self-allow decision:27cbab2e5533508a allow/self_service; tenant-admin-allow decision:350b46fb42989606 allow/tenant_admin; platform-allow decision:79334537419466bd allow/platform_operator; cross-tenant-deny decision:b3cc0b7e819aecde deny/cross_tenant; missing-role-deny decision:818e2249491ef09f deny/no_matching_role_or_context; wrong-system-deny decision:5e20697e202aa7c6 deny/wrong_system. The deployed failure matrix is therefore confirmed still fail-closed 42h into the current rollout.

Still open, and not flex-auth's to close: the done-criterion is that user-engine replaces its local authorization bridge without an availability bypass. That cutover is user-engine's decision and remains gated on the separately owned event and mail receivers. flex-auth has delivered and re-verified the service side; T04 stays progress rather than being marked done on evidence that only covers half the criterion.