From 1182b637c7289047883373a02bca790e0c6fb20b Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 28 Sep 2026 10:52:57 +0200 Subject: [PATCH] docs: inventory Hub and platform access boundaries for root integration Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e715-b802-70f0-a8fa-590d9ee673a5 --- WORK-RECORDS.md | 4 +- docs/platform-access-inventory.json | 7790 +++++++++++++++++ docs/platform-access-inventory.md | 339 + tools/build_access_inventory.py | 131 + ...WP-0012-netkingdom-platform-root-access.md | 16 +- 5 files changed, 8275 insertions(+), 5 deletions(-) create mode 100644 docs/platform-access-inventory.json create mode 100644 docs/platform-access-inventory.md create mode 100644 tools/build_access_inventory.py diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 0c0b83e..37b4a7d 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -17,7 +17,7 @@ | workplan | HUB-WP-0007 | finished | — | workplans/HUB-WP-0007-workload-projection-transport.md | | workplan | HUB-WP-0008 | finished | — | workplans/HUB-WP-0008-legacy-message-identity-reconciliation.md | | workplan | HUB-WP-0009 | proposed | — | workplans/HUB-WP-0009-extension-conformance-gaps.md | -| workplan | HUB-WP-0012 | proposed | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | +| workplan | HUB-WP-0012 | active | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | | task | HUB-WP-0001-T01 | done | — | workplans/HUB-WP-0001-statehub-bootstrap.md | | task | HUB-WP-0001-T02 | done | — | workplans/HUB-WP-0001-statehub-bootstrap.md | | task | HUB-WP-0001-T03 | done | — | workplans/HUB-WP-0001-statehub-bootstrap.md | @@ -62,7 +62,7 @@ | task | HUB-WP-0009-T02 | todo | — | workplans/HUB-WP-0009-extension-conformance-gaps.md | | task | HUB-WP-0009-T03 | todo | — | workplans/HUB-WP-0009-extension-conformance-gaps.md | | task | HUB-WP-0009-T04 | todo | — | workplans/HUB-WP-0009-extension-conformance-gaps.md | -| task | HUB-WP-0012-T01 | todo | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | +| task | HUB-WP-0012-T01 | progress | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | | task | HUB-WP-0012-T02 | todo | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | | task | HUB-WP-0012-T03 | todo | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | | task | HUB-WP-0012-T04 | todo | — | workplans/HUB-WP-0012-netkingdom-platform-root-access.md | diff --git a/docs/platform-access-inventory.json b/docs/platform-access-inventory.json new file mode 100644 index 0000000..5cc0199 --- /dev/null +++ b/docs/platform-access-inventory.json @@ -0,0 +1,7790 @@ +{ + "schema_version": "hub-access-inventory/0.1-draft", + "observed_on": "2026-09-28", + "source_commit": "e5b67b391d306c2b76d3b6e8c73449d51571561c", + "cluster": "railiance01", + "purpose": "T01 coverage specification; not an authorization grant or passing security receipt", + "profiles": { + "hub-api": { + "actor_tenant": "tenant:platform for root; named workload tenant otherwise", + "target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited", + "action_resource_rule": "HTTP method + canonical route/tool + target resource; normalize aliases to same action; final owner action IDs pending T01 review", + "cases": [ + "ROOT", + "OTHER", + "INVALID", + "REVOKE", + "OUTAGE", + "BYPASS", + "CALLER" + ], + "audience": "hub-core (proposed; issuer registration not proven)", + "test_owner": "hub-core", + "enforcement": "Hub Core API dependency; all aliases/direct Service paths; healthz alone uses HEALTH" + }, + "embedded-host": { + "actor_tenant": "tenant:platform for root; named workload tenant otherwise", + "target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited", + "action_resource_rule": "HTTP method + canonical route/tool + target resource; normalize aliases to same action; final owner action IDs pending T01 review", + "cases": [ + "ROOT", + "OTHER", + "INVALID", + "REVOKE", + "OUTAGE", + "BYPASS", + "CALLER" + ], + "audience": "host service audience, never implicitly hub-core", + "test_owner": "hub-core + embedding host", + "enforcement": "Host-injected authentication/policy seam; listed default paths may be remounted or disabled" + }, + "mcp-client": { + "actor_tenant": "tenant:platform for root; named workload tenant otherwise", + "target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited", + "action_resource_rule": "HTTP method + canonical route/tool + target resource; normalize aliases to same action; final owner action IDs pending T01 review", + "cases": [ + "ROOT", + "OTHER", + "INVALID", + "REVOKE", + "OUTAGE", + "BYPASS", + "CALLER" + ], + "audience": "MCP audience plus explicit downstream API audience", + "test_owner": "hub-core + MCP host", + "enforcement": "Authenticate MCP session; bind tool actor; downstream API independently enforces; no universal server token" + }, + "platform-owner": { + "actor_tenant": "tenant:platform for root; named workload tenant otherwise", + "target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited", + "action_resource_rule": "HTTP method + canonical route/tool + target resource; normalize aliases to same action; final owner action IDs pending T01 review", + "cases": [ + "ROOT", + "OTHER", + "INVALID", + "REVOKE", + "OUTAGE", + "BYPASS", + "CALLER" + ], + "audience": "per-row owner-native audience/realm; pending owner confirmation", + "test_owner": "row.owner", + "enforcement": "Owner API/session, Kubernetes RBAC or native management gate; hub login is insufficient" + }, + "extension": { + "actor_tenant": "tenant:platform for root; named workload tenant otherwise", + "target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited", + "action_resource_rule": "HTTP method + canonical route/tool + target resource; normalize aliases to same action; final owner action IDs pending T01 review", + "cases": [ + "ROOT", + "OTHER", + "INVALID", + "REVOKE", + "OUTAGE", + "BYPASS", + "CALLER" + ], + "audience": "per-extension audience; pending registration", + "test_owner": "row.owner", + "enforcement": "Extension API and downstream owner both enforce signed identity/delegation" + }, + "native-control": { + "actor_tenant": "tenant:platform for root; named workload tenant otherwise", + "target_tenant": "resolved server-side from resource; root cross-tenant action explicitly audited", + "action_resource_rule": "HTTP method + canonical route/tool + target resource; normalize aliases to same action; final owner action IDs pending T01 review", + "cases": [ + "ROOT", + "OTHER", + "INVALID", + "REVOKE", + "OUTAGE", + "BYPASS", + "CALLER", + "APPROVAL" + ], + "audience": "per-row native realm; do not use hub-core bearer", + "test_owner": "row.owner", + "enforcement": "Native RBAC, SSH certificate/principal, GitOps, secrets or approval policy" + }, + "minimal-health": { + "actor_tenant": "none", + "target_tenant": "none", + "action_resource_rule": "GET /healthz: process liveness only", + "cases": [ + "HEALTH" + ], + "audience": "none: minimal process liveness", + "test_owner": "hub-core", + "enforcement": "No identity required; no sensitive details" + } + }, + "acceptance_cases": { + "ROOT": { + "actor": "verified platform-root (iss,sub), current entitlement, AAL2", + "expected": "allow registered action through normal owner boundary; independent readback and actor audit", + "execution": "not-run" + }, + "OTHER": { + "actor": "ordinary authenticated user and tenant administrator", + "expected": "deny platform action before side effect; no cross-tenant data or existence leak", + "execution": "not-run" + }, + "INVALID": { + "actor": "anonymous, expired, wrong issuer/audience, forged username/headers", + "expected": "reject authentication; no side effect", + "execution": "not-run" + }, + "REVOKE": { + "actor": "formerly privileged subject after grant removal/suspension/logout", + "expected": "deny within documented bound; privileged mutation checks current authority", + "execution": "not-run" + }, + "OUTAGE": { + "actor": "root with unavailable/untrusted policy or required audit dependency", + "expected": "fail closed before privileged mutation", + "execution": "not-run" + }, + "BYPASS": { + "actor": "direct Service caller, alias client, MCP/embedded client", + "expected": "same decision as canonical route; no shared-token or network-origin bypass", + "execution": "not-run" + }, + "CALLER": { + "actor": "named workload and spoofed producer/delegated subject", + "expected": "allow only registered audience/action/address; reject root inheritance and spoofed delegation", + "execution": "not-run" + }, + "APPROVAL": { + "actor": "root invoking an action with confirmation/approval obligation", + "expected": "root entitlement preserved but missing obligation denies execution; use isolated/reversible target", + "execution": "not-run" + }, + "HEALTH": { + "actor": "unauthenticated health probe", + "expected": "minimal liveness only; no identity, tenant, dependency or business data", + "execution": "not-run" + } + }, + "hub_surfaces": [ + { + "id": "http:GET:/annotation-categories:hub_core.runtime.compat.annotation_categories", + "kind": "runtime-http", + "method": "GET", + "path": "/annotation-categories", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "annotation_categories" + }, + { + "id": "http:GET:/annotations:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/annotations", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/api-consumers:hub_core.runtime.compat.list_consumers", + "kind": "runtime-http", + "method": "GET", + "path": "/api-consumers", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_consumers" + }, + { + "id": "http:GET:/api/v2/annotation-categories:hub_core.runtime.compat.annotation_categories", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/annotation-categories", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "annotation_categories" + }, + { + "id": "http:GET:/api/v2/annotations:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/annotations", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/api/v2/api-consumers:hub_core.runtime.compat.list_consumers", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/api-consumers", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_consumers" + }, + { + "id": "http:GET:/api/v2/decision-records:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/decision-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/api/v2/deployment-records:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/deployment-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/api/v2/docs:hub_core.runtime.compat.docs", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/docs", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "docs" + }, + { + "id": "http:GET:/api/v2/event-types:hub_core.runtime.compat.event_types", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/event-types", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "event_types" + }, + { + "id": "http:GET:/api/v2/hub-capability-manifests:hub_core.runtime.compat.list_manifests", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/hub-capability-manifests", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_manifests" + }, + { + "id": "http:GET:/api/v2/hub-registry:hub_core.runtime.compat.hub_registry", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/hub-registry", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "hub_registry" + }, + { + "id": "http:GET:/api/v2/hubs:hub_core.runtime.compat.list_hubs", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/hubs", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_hubs" + }, + { + "id": "http:GET:/api/v2/interaction-events:hub_core.runtime.compat.list_interactions", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/interaction-events", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_interactions" + }, + { + "id": "http:GET:/api/v2/openapi.json:hub_core.runtime.compat.openapi_json", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/openapi.json", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "openapi_json" + }, + { + "id": "http:GET:/api/v2/openapi.yaml:hub_core.runtime.compat.openapi_yaml", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/openapi.yaml", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "openapi_yaml" + }, + { + "id": "http:GET:/api/v2/outcome-signals:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/outcome-signals", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/api/v2/policy-scopes:hub_core.runtime.compat.policy_scopes", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/policy-scopes", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "policy_scopes" + }, + { + "id": "http:GET:/api/v2/requirement-candidates:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/requirement-candidates", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/api/v2/widget-types:hub_core.runtime.compat.widget_types", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/widget-types", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "widget_types" + }, + { + "id": "http:GET:/api/v2/widgets:hub_core.runtime.compat.list_widgets", + "kind": "runtime-http", + "method": "GET", + "path": "/api/v2/widgets", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_widgets" + }, + { + "id": "http:GET:/console:hub_core.runtime.compat.console", + "kind": "runtime-http", + "method": "GET", + "path": "/console", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "console" + }, + { + "id": "http:GET:/decision-records:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/decision-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/deployment-records:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/deployment-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/docs/oauth2-redirect:fastapi.applications.swagger_ui_redirect", + "kind": "runtime-http", + "method": "GET", + "path": "/docs/oauth2-redirect", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "swagger_ui_redirect" + }, + { + "id": "http:GET:/docs:fastapi.applications.swagger_ui_html", + "kind": "runtime-http", + "method": "GET", + "path": "/docs", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "swagger_ui_html" + }, + { + "id": "http:GET:/docs:hub_core.runtime.compat.docs", + "kind": "runtime-http", + "method": "GET", + "path": "/docs", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "docs" + }, + { + "id": "http:GET:/event-types:hub_core.runtime.compat.event_types", + "kind": "runtime-http", + "method": "GET", + "path": "/event-types", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "event_types" + }, + { + "id": "http:GET:/healthz:hub_core.runtime.app.healthz", + "kind": "runtime-http", + "method": "GET", + "path": "/healthz", + "profile": "minimal-health", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.app", + "conditional": false, + "handler": "healthz" + }, + { + "id": "http:GET:/hub-capability-manifests:hub_core.runtime.compat.list_manifests", + "kind": "runtime-http", + "method": "GET", + "path": "/hub-capability-manifests", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_manifests" + }, + { + "id": "http:GET:/hub-registry:hub_core.runtime.compat.hub_registry", + "kind": "runtime-http", + "method": "GET", + "path": "/hub-registry", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "hub_registry" + }, + { + "id": "http:GET:/hubs:hub_core.runtime.compat.list_hubs", + "kind": "runtime-http", + "method": "GET", + "path": "/hubs", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_hubs" + }, + { + "id": "http:GET:/interaction-events:hub_core.runtime.compat.list_interactions", + "kind": "runtime-http", + "method": "GET", + "path": "/interaction-events", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_interactions" + }, + { + "id": "http:GET:/openapi.json:fastapi.applications.openapi", + "kind": "runtime-http", + "method": "GET", + "path": "/openapi.json", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "openapi" + }, + { + "id": "http:GET:/openapi.json:hub_core.runtime.compat.openapi_json", + "kind": "runtime-http", + "method": "GET", + "path": "/openapi.json", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "openapi_json" + }, + { + "id": "http:GET:/openapi.yaml:hub_core.runtime.compat.openapi_yaml", + "kind": "runtime-http", + "method": "GET", + "path": "/openapi.yaml", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "openapi_yaml" + }, + { + "id": "http:GET:/outcome-signals:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/outcome-signals", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/policy-scopes:hub_core.runtime.compat.policy_scopes", + "kind": "runtime-http", + "method": "GET", + "path": "/policy-scopes", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "policy_scopes" + }, + { + "id": "http:GET:/ports/messaging/messages:hub_core.runtime.ports.list_messages", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/messaging/messages", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "list_messages" + }, + { + "id": "http:GET:/ports/projections/repository-navigation/facets/{facet_kind}/{facet_value}:hub_core.runtime.repository_navigation_routes.query_facet", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/projections/repository-navigation/facets/{facet_kind}/{facet_value}", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.repository_navigation_routes", + "conditional": false, + "handler": "query_facet" + }, + { + "id": "http:GET:/ports/projections/repository-navigation/repositories:hub_core.runtime.repository_navigation_routes.query_repositories", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/projections/repository-navigation/repositories", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.repository_navigation_routes", + "conditional": false, + "handler": "query_repositories" + }, + { + "id": "http:GET:/ports/projections/statehub-inbox:hub_core.runtime.inbox_projection.inbox", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/projections/statehub-inbox", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.inbox_projection", + "conditional": true, + "handler": "inbox" + }, + { + "id": "http:GET:/ports/projections/workloads/resolve:hub_core.runtime.workload_projection_routes.resolve_workload", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/projections/workloads/resolve", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.workload_projection_routes", + "conditional": false, + "handler": "resolve_workload" + }, + { + "id": "http:GET:/ports/projections/workloads:hub_core.runtime.workload_projection_routes.query_workloads", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/projections/workloads", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.workload_projection_routes", + "conditional": false, + "handler": "query_workloads" + }, + { + "id": "http:GET:/ports/projections/{projection_id}:hub_core.runtime.ports.query_projection", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/projections/{projection_id}", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "query_projection" + }, + { + "id": "http:GET:/ports/registry/registrations/{hub_slug}/audit:hub_core.runtime.ports.registration_audit", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/registry/registrations/{hub_slug}/audit", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "registration_audit" + }, + { + "id": "http:GET:/ports/registry/registrations/{hub_slug}:hub_core.runtime.ports.resolve_registration", + "kind": "runtime-http", + "method": "GET", + "path": "/ports/registry/registrations/{hub_slug}", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "resolve_registration" + }, + { + "id": "http:GET:/readyz:hub_core.runtime.app.readyz", + "kind": "runtime-http", + "method": "GET", + "path": "/readyz", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.app", + "conditional": false, + "handler": "readyz" + }, + { + "id": "http:GET:/redoc:fastapi.applications.redoc_html", + "kind": "runtime-http", + "method": "GET", + "path": "/redoc", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "redoc_html" + }, + { + "id": "http:GET:/requirement-candidates:hub_core.runtime.compat.empty_collection", + "kind": "runtime-http", + "method": "GET", + "path": "/requirement-candidates", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "empty_collection" + }, + { + "id": "http:GET:/widget-types:hub_core.runtime.compat.widget_types", + "kind": "runtime-http", + "method": "GET", + "path": "/widget-types", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "widget_types" + }, + { + "id": "http:GET:/widgets:hub_core.runtime.compat.list_widgets", + "kind": "runtime-http", + "method": "GET", + "path": "/widgets", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "list_widgets" + }, + { + "id": "http:HEAD:/docs/oauth2-redirect:fastapi.applications.swagger_ui_redirect", + "kind": "runtime-http", + "method": "HEAD", + "path": "/docs/oauth2-redirect", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "swagger_ui_redirect" + }, + { + "id": "http:HEAD:/docs:fastapi.applications.swagger_ui_html", + "kind": "runtime-http", + "method": "HEAD", + "path": "/docs", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "swagger_ui_html" + }, + { + "id": "http:HEAD:/openapi.json:fastapi.applications.openapi", + "kind": "runtime-http", + "method": "HEAD", + "path": "/openapi.json", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "openapi" + }, + { + "id": "http:HEAD:/redoc:fastapi.applications.redoc_html", + "kind": "runtime-http", + "method": "HEAD", + "path": "/redoc", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "fastapi.applications", + "conditional": false, + "handler": "redoc_html" + }, + { + "id": "http:PATCH:/api/v2/hub-capability-manifests/{manifest_id}:hub_core.runtime.compat.patch_manifest", + "kind": "runtime-http", + "method": "PATCH", + "path": "/api/v2/hub-capability-manifests/{manifest_id}", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "patch_manifest" + }, + { + "id": "http:PATCH:/hub-capability-manifests/{manifest_id}:hub_core.runtime.compat.patch_manifest", + "kind": "runtime-http", + "method": "PATCH", + "path": "/hub-capability-manifests/{manifest_id}", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "patch_manifest" + }, + { + "id": "http:POST:/annotations:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/annotations", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/api-consumers/{consumer_id}/api-keys:hub_core.runtime.compat.create_key", + "kind": "runtime-http", + "method": "POST", + "path": "/api-consumers/{consumer_id}/api-keys", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_key" + }, + { + "id": "http:POST:/api-consumers:hub_core.runtime.compat.create_consumer", + "kind": "runtime-http", + "method": "POST", + "path": "/api-consumers", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_consumer" + }, + { + "id": "http:POST:/api/v2/annotations:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/annotations", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/api/v2/api-consumers/{consumer_id}/api-keys:hub_core.runtime.compat.create_key", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/api-consumers/{consumer_id}/api-keys", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_key" + }, + { + "id": "http:POST:/api/v2/api-consumers:hub_core.runtime.compat.create_consumer", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/api-consumers", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_consumer" + }, + { + "id": "http:POST:/api/v2/decision-records:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/decision-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/api/v2/deployment-records:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/deployment-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/api/v2/hub-capability-manifests/{manifest_id}/activate:hub_core.runtime.compat.activate_manifest", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/hub-capability-manifests/{manifest_id}/activate", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "activate_manifest" + }, + { + "id": "http:POST:/api/v2/hub-capability-manifests:hub_core.runtime.compat.create_manifest", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/hub-capability-manifests", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_manifest" + }, + { + "id": "http:POST:/api/v2/hubs:hub_core.runtime.compat.create_hub", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/hubs", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_hub" + }, + { + "id": "http:POST:/api/v2/interaction-events:hub_core.runtime.compat.create_interaction", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/interaction-events", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_interaction" + }, + { + "id": "http:POST:/api/v2/outcome-signals:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/outcome-signals", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/api/v2/requirement-candidates:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/requirement-candidates", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/api/v2/token:hub_core.runtime.compat.token", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/token", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "token" + }, + { + "id": "http:POST:/api/v2/widgets:hub_core.runtime.compat.create_widget", + "kind": "runtime-http", + "method": "POST", + "path": "/api/v2/widgets", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_widget" + }, + { + "id": "http:POST:/decision-records:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/decision-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/deployment-records:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/deployment-records", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/hub-capability-manifests/{manifest_id}/activate:hub_core.runtime.compat.activate_manifest", + "kind": "runtime-http", + "method": "POST", + "path": "/hub-capability-manifests/{manifest_id}/activate", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "activate_manifest" + }, + { + "id": "http:POST:/hub-capability-manifests:hub_core.runtime.compat.create_manifest", + "kind": "runtime-http", + "method": "POST", + "path": "/hub-capability-manifests", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_manifest" + }, + { + "id": "http:POST:/hubs:hub_core.runtime.compat.create_hub", + "kind": "runtime-http", + "method": "POST", + "path": "/hubs", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_hub" + }, + { + "id": "http:POST:/interaction-events:hub_core.runtime.compat.create_interaction", + "kind": "runtime-http", + "method": "POST", + "path": "/interaction-events", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_interaction" + }, + { + "id": "http:POST:/outcome-signals:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/outcome-signals", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/ports/events/interaction:hub_core.runtime.ports.append_interaction", + "kind": "runtime-http", + "method": "POST", + "path": "/ports/events/interaction", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "append_interaction" + }, + { + "id": "http:POST:/ports/events/progress:hub_core.runtime.ports.append_progress", + "kind": "runtime-http", + "method": "POST", + "path": "/ports/events/progress", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "append_progress" + }, + { + "id": "http:POST:/ports/messaging/messages:hub_core.runtime.ports.send_message", + "kind": "runtime-http", + "method": "POST", + "path": "/ports/messaging/messages", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "send_message" + }, + { + "id": "http:POST:/ports/registry/registrations:hub_core.runtime.ports.register_extension", + "kind": "runtime-http", + "method": "POST", + "path": "/ports/registry/registrations", + "profile": "hub-api", + "current_gate": "no-identity-check-in-handler", + "source": "hub_core.runtime.ports", + "conditional": false, + "handler": "register_extension" + }, + { + "id": "http:POST:/requirement-candidates:hub_core.runtime.compat.accept_deferred", + "kind": "runtime-http", + "method": "POST", + "path": "/requirement-candidates", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "accept_deferred" + }, + { + "id": "http:POST:/token:hub_core.runtime.compat.token", + "kind": "runtime-http", + "method": "POST", + "path": "/token", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "token" + }, + { + "id": "http:POST:/widgets:hub_core.runtime.compat.create_widget", + "kind": "runtime-http", + "method": "POST", + "path": "/widgets", + "profile": "hub-api", + "current_gate": "shared-bearer", + "source": "hub_core.runtime.compat", + "conditional": false, + "handler": "create_widget" + }, + { + "id": "mcp:accept_capability_request", + "kind": "mcp", + "tool": "accept_capability_request", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 225, + "target_calls": [ + { + "method": "POST", + "path_expression": "f'/capability-requests/{request_id}/accept/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:append_progress", + "kind": "mcp", + "tool": "append_progress", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 480, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/progress/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:check_repo_doi", + "kind": "mcp", + "tool": "check_repo_doi", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 386, + "target_calls": [ + { + "method": "GET", + "path_expression": "f'/repos/{repo_slug}/doi/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_alerts", + "kind": "mcp", + "tool": "get_alerts", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 467, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/progress/alerts/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_capability_request", + "kind": "mcp", + "tool": "get_capability_request", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 267, + "target_calls": [ + { + "method": "GET", + "path_expression": "f'/capability-requests/{request_id}/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_doi_summary", + "kind": "mcp", + "tool": "get_doi_summary", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 395, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/repos/doi/summary/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_domain", + "kind": "mcp", + "tool": "get_domain", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 105, + "target_calls": [ + { + "method": "GET", + "path_expression": "f'/domains/{domain_slug}/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_domain_summary", + "kind": "mcp", + "tool": "get_domain_summary", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 101, + "target_calls": [ + { + "method": "GET", + "path_expression": "f'/domains/{domain_slug}/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_gdpr_report", + "kind": "mcp", + "tool": "get_gdpr_report", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 450, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/tpsc/report/gdpr/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_messages", + "kind": "mcp", + "tool": "get_messages", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 130, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/messages/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_repository_navigation_facet", + "kind": "mcp", + "tool": "get_repository_navigation_facet", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 334, + "target_calls": [ + { + "method": "GET", + "path_expression": "f'/ports/projections/repository-navigation/facets/{facet_kind}/{facet_value}'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_risks", + "kind": "mcp", + "tool": "get_risks", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 454, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/progress/risks/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:get_state_summary", + "kind": "mcp", + "tool": "get_state_summary", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 93, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/state/summary/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:ingest_tpsc_tool", + "kind": "mcp", + "tool": "ingest_tpsc_tool", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 441, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/tpsc/ingest/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:list_capabilities", + "kind": "mcp", + "tool": "list_capabilities", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 185, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/capability-catalog/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:list_capability_requests", + "kind": "mcp", + "tool": "list_capability_requests", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 254, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/capability-requests/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:list_domain_repos", + "kind": "mcp", + "tool": "list_domain_repos", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 302, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/repos/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:list_domains", + "kind": "mcp", + "tool": "list_domains", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 97, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/domains/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:list_services", + "kind": "mcp", + "tool": "list_services", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 424, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/tpsc/catalog/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:mark_message_read", + "kind": "mcp", + "tool": "mark_message_read", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 149, + "target_calls": [ + { + "method": "PATCH", + "path_expression": "f'/messages/{message_id}/read/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:query_repository_navigation", + "kind": "mcp", + "tool": "query_repository_navigation", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 306, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/ports/projections/repository-navigation/repositories'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:query_workloads", + "kind": "mcp", + "tool": "query_workloads", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 350, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/ports/projections/workloads'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:register_capability", + "kind": "mcp", + "tool": "register_capability", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 162, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/capability-catalog/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:register_repo", + "kind": "mcp", + "tool": "register_repo", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 271, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/repos/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:register_service", + "kind": "mcp", + "tool": "register_service", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 399, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/tpsc/catalog/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:reply_to_message", + "kind": "mcp", + "tool": "reply_to_message", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 153, + "target_calls": [ + { + "method": "POST", + "path_expression": "f'/messages/{message_id}/reply/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:request_capability", + "kind": "mcp", + "tool": "request_capability", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 198, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/capability-requests/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:resolve_workload_reference", + "kind": "mcp", + "tool": "resolve_workload_reference", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 372, + "target_calls": [ + { + "method": "GET", + "path_expression": "'/ports/projections/workloads/resolve'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:send_message", + "kind": "mcp", + "tool": "send_message", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 109, + "target_calls": [ + { + "method": "POST", + "path_expression": "'/messages/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:update_capability_request_status", + "kind": "mcp", + "tool": "update_capability_request_status", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 241, + "target_calls": [ + { + "method": "PATCH", + "path_expression": "f'/capability-requests/{request_id}/status/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "mcp:update_repo_path", + "kind": "mcp", + "tool": "update_repo_path", + "profile": "mcp-client", + "source": "hub_core/mcp/server.py", + "line": 296, + "target_calls": [ + { + "method": "POST", + "path_expression": "f'/repos/{repo_slug}/paths/'" + } + ], + "current_gate": "no per-user credential forwarding in base wrapper" + }, + { + "id": "sdk:create_capability_catalog_router:GET:/capability-catalog/", + "kind": "embedded-http", + "method": "GET", + "path": "/capability-catalog/", + "profile": "embedded-host", + "factory": "create_capability_catalog_router", + "source": "hub_core/routers/capabilities.py", + "line": 91, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_catalog_router:PATCH:/capability-catalog/{entry_id}", + "kind": "embedded-http", + "method": "PATCH", + "path": "/capability-catalog/{entry_id}", + "profile": "embedded-host", + "factory": "create_capability_catalog_router", + "source": "hub_core/routers/capabilities.py", + "line": 111, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_catalog_router:POST:/capability-catalog/", + "kind": "embedded-http", + "method": "POST", + "path": "/capability-catalog/", + "profile": "embedded-host", + "factory": "create_capability_catalog_router", + "source": "hub_core/routers/capabilities.py", + "line": 58, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_read_router:GET:/capability-requests/", + "kind": "embedded-http", + "method": "GET", + "path": "/capability-requests/", + "profile": "embedded-host", + "factory": "create_capability_request_read_router", + "source": "hub_core/routers/capabilities.py", + "line": 146, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_read_router:GET:/capability-requests/{request_id}", + "kind": "embedded-http", + "method": "GET", + "path": "/capability-requests/{request_id}", + "profile": "embedded-host", + "factory": "create_capability_request_read_router", + "source": "hub_core/routers/capabilities.py", + "line": 170, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_write_router:PATCH:/capability-requests/{request_id}", + "kind": "embedded-http", + "method": "PATCH", + "path": "/capability-requests/{request_id}", + "profile": "embedded-host", + "factory": "create_capability_request_write_router", + "source": "hub_core/routers/capabilities.py", + "line": 308, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_write_router:PATCH:/capability-requests/{request_id}/status", + "kind": "embedded-http", + "method": "PATCH", + "path": "/capability-requests/{request_id}/status", + "profile": "embedded-host", + "factory": "create_capability_request_write_router", + "source": "hub_core/routers/capabilities.py", + "line": 283, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_write_router:POST:/capability-requests/", + "kind": "embedded-http", + "method": "POST", + "path": "/capability-requests/", + "profile": "embedded-host", + "factory": "create_capability_request_write_router", + "source": "hub_core/routers/capabilities.py", + "line": 214, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_write_router:POST:/capability-requests/{request_id}/accept", + "kind": "embedded-http", + "method": "POST", + "path": "/capability-requests/{request_id}/accept", + "profile": "embedded-host", + "factory": "create_capability_request_write_router", + "source": "hub_core/routers/capabilities.py", + "line": 258, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_write_router:POST:/capability-requests/{request_id}/dispute", + "kind": "embedded-http", + "method": "POST", + "path": "/capability-requests/{request_id}/dispute", + "profile": "embedded-host", + "factory": "create_capability_request_write_router", + "source": "hub_core/routers/capabilities.py", + "line": 335, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_capability_request_write_router:POST:/capability-requests/{request_id}/reroute", + "kind": "embedded-http", + "method": "POST", + "path": "/capability-requests/{request_id}/reroute", + "profile": "embedded-host", + "factory": "create_capability_request_write_router", + "source": "hub_core/routers/capabilities.py", + "line": 361, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_domains_router:GET:/domains/", + "kind": "embedded-http", + "method": "GET", + "path": "/domains/", + "profile": "embedded-host", + "factory": "create_domains_router", + "source": "hub_core/routers/domains.py", + "line": 38, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_domains_router:GET:/domains/{slug}", + "kind": "embedded-http", + "method": "GET", + "path": "/domains/{slug}", + "profile": "embedded-host", + "factory": "create_domains_router", + "source": "hub_core/routers/domains.py", + "line": 73, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_domains_router:PATCH:/domains/{slug}", + "kind": "embedded-http", + "method": "PATCH", + "path": "/domains/{slug}", + "profile": "embedded-host", + "factory": "create_domains_router", + "source": "hub_core/routers/domains.py", + "line": 90, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_domains_router:PATCH:/domains/{slug}/archive", + "kind": "embedded-http", + "method": "PATCH", + "path": "/domains/{slug}/archive", + "profile": "embedded-host", + "factory": "create_domains_router", + "source": "hub_core/routers/domains.py", + "line": 120, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_domains_router:PATCH:/domains/{slug}/rename", + "kind": "embedded-http", + "method": "PATCH", + "path": "/domains/{slug}/rename", + "profile": "embedded-host", + "factory": "create_domains_router", + "source": "hub_core/routers/domains.py", + "line": 103, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_domains_router:POST:/domains/", + "kind": "embedded-http", + "method": "POST", + "path": "/domains/", + "profile": "embedded-host", + "factory": "create_domains_router", + "source": "hub_core/routers/domains.py", + "line": 59, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_messages_router:GET:/messages/", + "kind": "embedded-http", + "method": "GET", + "path": "/messages/", + "profile": "embedded-host", + "factory": "create_messages_router", + "source": "hub_core/routers/messages.py", + "line": 58, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_messages_router:GET:/messages/thread/{thread_id}", + "kind": "embedded-http", + "method": "GET", + "path": "/messages/thread/{thread_id}", + "profile": "embedded-host", + "factory": "create_messages_router", + "source": "hub_core/routers/messages.py", + "line": 79, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_messages_router:PATCH:/messages/{message_id}/archive", + "kind": "embedded-http", + "method": "PATCH", + "path": "/messages/{message_id}/archive", + "profile": "embedded-host", + "factory": "create_messages_router", + "source": "hub_core/routers/messages.py", + "line": 113, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_messages_router:PATCH:/messages/{message_id}/read", + "kind": "embedded-http", + "method": "PATCH", + "path": "/messages/{message_id}/read", + "profile": "embedded-host", + "factory": "create_messages_router", + "source": "hub_core/routers/messages.py", + "line": 101, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_messages_router:POST:/messages/", + "kind": "embedded-http", + "method": "POST", + "path": "/messages/", + "profile": "embedded-host", + "factory": "create_messages_router", + "source": "hub_core/routers/messages.py", + "line": 43, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_messages_router:POST:/messages/{message_id}/reply", + "kind": "embedded-http", + "method": "POST", + "path": "/messages/{message_id}/reply", + "profile": "embedded-host", + "factory": "create_messages_router", + "source": "hub_core/routers/messages.py", + "line": 126, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_policy_router:GET:/policy/{name}", + "kind": "embedded-http", + "method": "GET", + "path": "/policy/{name}", + "profile": "embedded-host", + "factory": "create_policy_router", + "source": "hub_core/routers/policy.py", + "line": 18, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_policy_router:PUT:/policy/{name}", + "kind": "embedded-http", + "method": "PUT", + "path": "/policy/{name}", + "profile": "embedded-host", + "factory": "create_policy_router", + "source": "hub_core/routers/policy.py", + "line": 27, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_progress_router:GET:/progress/", + "kind": "embedded-http", + "method": "GET", + "path": "/progress/", + "profile": "embedded-host", + "factory": "create_progress_router", + "source": "hub_core/routers/progress.py", + "line": 91, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_progress_router:GET:/progress/alerts", + "kind": "embedded-http", + "method": "GET", + "path": "/progress/alerts", + "profile": "embedded-host", + "factory": "create_progress_router", + "source": "hub_core/routers/progress.py", + "line": 140, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_progress_router:GET:/progress/risks", + "kind": "embedded-http", + "method": "GET", + "path": "/progress/risks", + "profile": "embedded-host", + "factory": "create_progress_router", + "source": "hub_core/routers/progress.py", + "line": 125, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_progress_router:POST:/progress/", + "kind": "embedded-http", + "method": "POST", + "path": "/progress/", + "profile": "embedded-host", + "factory": "create_progress_router", + "source": "hub_core/routers/progress.py", + "line": 155, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:GET:/repos/", + "kind": "embedded-http", + "method": "GET", + "path": "/repos/", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 39, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:GET:/repos/by-fingerprint", + "kind": "embedded-http", + "method": "GET", + "path": "/repos/by-fingerprint", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 92, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:GET:/repos/by-remote", + "kind": "embedded-http", + "method": "GET", + "path": "/repos/by-remote", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 104, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:GET:/repos/{slug}", + "kind": "embedded-http", + "method": "GET", + "path": "/repos/{slug}", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 116, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:PATCH:/repos/{slug}", + "kind": "embedded-http", + "method": "PATCH", + "path": "/repos/{slug}", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 123, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:POST:/repos/", + "kind": "embedded-http", + "method": "POST", + "path": "/repos/", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 59, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_repos_router:POST:/repos/{slug}/paths", + "kind": "embedded-http", + "method": "POST", + "path": "/repos/{slug}/paths", + "profile": "embedded-host", + "factory": "create_repos_router", + "source": "hub_core/routers/repos.py", + "line": 136, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_tpsc_router:GET:/tpsc/catalog/", + "kind": "embedded-http", + "method": "GET", + "path": "/tpsc/catalog/", + "profile": "embedded-host", + "factory": "create_tpsc_router", + "source": "hub_core/routers/tpsc.py", + "line": 35, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_tpsc_router:GET:/tpsc/catalog/{slug}", + "kind": "embedded-http", + "method": "GET", + "path": "/tpsc/catalog/{slug}", + "profile": "embedded-host", + "factory": "create_tpsc_router", + "source": "hub_core/routers/tpsc.py", + "line": 53, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_tpsc_router:GET:/tpsc/report/gdpr", + "kind": "embedded-http", + "method": "GET", + "path": "/tpsc/report/gdpr", + "profile": "embedded-host", + "factory": "create_tpsc_router", + "source": "hub_core/routers/tpsc.py", + "line": 157, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_tpsc_router:GET:/tpsc/snapshots/", + "kind": "embedded-http", + "method": "GET", + "path": "/tpsc/snapshots/", + "profile": "embedded-host", + "factory": "create_tpsc_router", + "source": "hub_core/routers/tpsc.py", + "line": 138, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_tpsc_router:POST:/tpsc/catalog/", + "kind": "embedded-http", + "method": "POST", + "path": "/tpsc/catalog/", + "profile": "embedded-host", + "factory": "create_tpsc_router", + "source": "hub_core/routers/tpsc.py", + "line": 65, + "current_gate": "host-injected; not established by inventory", + "conditional": true + }, + { + "id": "sdk:create_tpsc_router:POST:/tpsc/ingest/", + "kind": "embedded-http", + "method": "POST", + "path": "/tpsc/ingest/", + "profile": "embedded-host", + "factory": "create_tpsc_router", + "source": "hub_core/routers/tpsc.py", + "line": 86, + "current_gate": "host-injected; not established by inventory", + "conditional": true + } + ], + "platform_surfaces": [ + { + "id": "namespace:activity-core", + "owner": "activity-core", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "activity-core or native owner realm (not verified)", + "resource_scope": "platform administration of namespace activity-core; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-api", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-event-router", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-statehub-edge-relay", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-temporal", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-temporal-ui", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-worker", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "llm-connect", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "activity-core", + "name": "actcore-app-db", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "activity-core", + "name": "actcore-nats", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "activity-core", + "name": "actcore-temporal-db", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-api", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-app-db", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-nats", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-statehub-edge-relay", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-temporal", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-temporal-db", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-temporal-ui", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-worker-metrics", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "cm-acme-http-solver-2vrbs", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "NodePort" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "llm-connect", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "activity-core", + "name": "actcore-ops", + "hosts": [ + "activity.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "activity-core", + "name": "actcore-temporal-ui", + "hosts": [ + "temporal.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:approval-engine", + "owner": "approval-engine", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "approval-engine or native owner realm (not verified)", + "resource_scope": "platform administration of namespace approval-engine; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "StatefulSet", + "namespace": "approval-engine", + "name": "approval-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "approval-engine", + "name": "approval-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:argocd", + "owner": "railiance-platform / railiance-enablement", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "argocd or native owner realm (not verified)", + "resource_scope": "platform administration of namespace argocd; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "argocd", + "name": "argocd-applicationset-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "argocd", + "name": "argocd-redis", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "argocd", + "name": "argocd-repo-server", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "argocd", + "name": "argocd-application-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-applicationset-controller", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-metrics", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-redis", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-repo-server", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:audit-core", + "owner": "audit-core", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "audit-core or native owner realm (not verified)", + "resource_scope": "platform administration of namespace audit-core; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "audit-core", + "name": "audit-core", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "audit-core", + "name": "audit-core-attest-chain", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "Service", + "namespace": "audit-core", + "name": "audit-core", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:bao-notice", + "owner": "railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "bao-notice or native owner realm (not verified)", + "resource_scope": "platform administration of namespace bao-notice; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "bao-notice", + "name": "bao-notice", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "bao-notice", + "name": "bao-notice", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "bao-notice", + "name": "bao-notice", + "hosts": [ + "bao.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "bao-notice", + "name": "bao-notice-http-redirect", + "hosts": [ + "bao.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:canned-prompts", + "owner": "rapp-canned-prompts", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "canned-prompts or native owner realm (not verified)", + "resource_scope": "platform administration of namespace canned-prompts; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "canned-prompts", + "name": "canned-prompts", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "canned-prompts", + "name": "canned-prompts", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:cert-manager", + "owner": "railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "cert-manager or native owner realm (not verified)", + "resource_scope": "platform administration of namespace cert-manager; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "cert-manager", + "name": "cert-manager", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "cert-manager", + "name": "cert-manager-cainjector", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "cert-manager", + "name": "cert-manager-webhook", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "cert-manager", + "name": "cert-manager", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "cert-manager", + "name": "cert-manager-cainjector", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "cert-manager", + "name": "cert-manager-webhook", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:cnpg-system", + "owner": "rapp-postgres", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "cnpg-system or native owner realm (not verified)", + "resource_scope": "platform administration of namespace cnpg-system; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "cnpg-system", + "name": "cnpg-controller-manager", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "cnpg-system", + "name": "cnpg-webhook-service", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:core-hub", + "owner": "hub-core / rapp-core-hub / repo-manager", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "core-hub or native owner realm (not verified)", + "resource_scope": "platform administration of namespace core-hub; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "core-hub", + "name": "core-hub-api", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "core-hub", + "name": "core-hub-api-candidate", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "core-hub", + "name": "core-hub-api-repository-publisher", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "core-hub", + "name": "core-hub-api", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "core-hub", + "name": "core-hub-api-candidate", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "core-hub", + "name": "core-hub-api-repository-publisher", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:coulomb", + "owner": "railiance-platform (probe owner to confirm)", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "coulomb or native owner realm (not verified)", + "resource_scope": "platform administration of namespace coulomb; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "coulomb", + "name": "ihp-railiance-probe", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "coulomb", + "name": "ihp-railiance-probe", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "coulomb", + "name": "ihp-railiance-probe", + "hosts": [ + "probe.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:coulomb-social", + "owner": "coulomb-social", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "coulomb-social or native owner realm (not verified)", + "resource_scope": "platform administration of namespace coulomb-social; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "coulomb-social", + "name": "coulomb-social", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "coulomb-social", + "name": "coulomb-social", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "coulomb-social", + "name": "coulomb-social", + "hosts": [ + "app.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:databases", + "owner": "rapp-postgres / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "databases or native owner realm (not verified)", + "resource_scope": "platform administration of namespace databases; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Service", + "namespace": "databases", + "name": "apps-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "apps-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "apps-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "forgejo-db-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "forgejo-db-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "forgejo-db-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "net-kingdom-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "net-kingdom-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "net-kingdom-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-2-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-2-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-2-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "state-hub-db-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "state-hub-db-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "state-hub-db-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:default", + "owner": "railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "default or native owner realm (not verified)", + "resource_scope": "platform administration of namespace default; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Service", + "namespace": "default", + "name": "kubernetes", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:email-connect", + "owner": "email-connect", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "email-connect or native owner realm (not verified)", + "resource_scope": "platform administration of namespace email-connect; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "email-connect", + "name": "email-connect", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "email-connect", + "name": "email-connect", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:external-secrets", + "owner": "railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "external-secrets or native owner realm (not verified)", + "resource_scope": "platform administration of namespace external-secrets; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "external-secrets", + "name": "external-secrets", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "external-secrets", + "name": "external-secrets-cert-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "external-secrets", + "name": "external-secrets-webhook", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "external-secrets", + "name": "eso-token-renewer", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "Service", + "namespace": "external-secrets", + "name": "external-secrets-webhook", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:flex-auth", + "owner": "flex-auth", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "flex-auth or native owner realm (not verified)", + "resource_scope": "platform administration of namespace flex-auth; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-sitting", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-t03", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-ops-warden", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-secrets-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-tenant-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-user-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-sitting", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-t03", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-ops-warden", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-secrets-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-tenant-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-user-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:forgejo", + "owner": "railiance-forge / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "forgejo or native owner realm (not verified)", + "resource_scope": "platform administration of namespace forgejo; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "forgejo", + "name": "forgejo-gitea", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "forgejo", + "name": "forgejo-runner", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "forgejo", + "name": "forgejo-gitea-http", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "forgejo", + "name": "forgejo-gitea-ssh", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "forgejo", + "name": "forgejo-ssh-nodeport", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "NodePort" + }, + { + "kind": "Ingress", + "namespace": "forgejo", + "name": "forgejo", + "hosts": [ + "forgejo.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:informed-decision", + "owner": "informed-decision", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "informed-decision or native owner realm (not verified)", + "resource_scope": "platform administration of namespace informed-decision; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "informed-decision", + "name": "informed-decision", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "informed-decision", + "name": "informed-decision", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "informed-decision", + "name": "informed-decision", + "hosts": [ + "decisions.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "informed-decision", + "name": "informed-decision-http-redirect", + "hosts": [ + "decisions.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:inter-hub", + "owner": "prj-state-hub-retirement / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "inter-hub or native owner realm (not verified)", + "resource_scope": "platform administration of namespace inter-hub; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "inter-hub", + "name": "inter-hub", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "inter-hub", + "name": "inter-hub", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:issue-core", + "owner": "issue-core", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "issue-core or native owner realm (not verified)", + "resource_scope": "platform administration of namespace issue-core; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "issue-core", + "name": "issue-core", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "issue-core", + "name": "issue-core", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:knative-serving", + "owner": "rail-knative / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "knative-serving or native owner realm (not verified)", + "resource_scope": "platform administration of namespace knative-serving; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "activator", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "autoscaler", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "net-kourier-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "webhook", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "activator-service", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "autoscaler", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "autoscaler-bucket-00-of-01", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "controller", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "net-kourier-controller", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "webhook", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:kourier-system", + "owner": "rail-knative / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "kourier-system or native owner realm (not verified)", + "resource_scope": "platform administration of namespace kourier-system; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "kourier-system", + "name": "3scale-kourier-gateway", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "kourier-system", + "name": "kourier", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kourier-system", + "name": "kourier-internal", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:kube-system", + "owner": "rail-kubernetes / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "kube-system or native owner realm (not verified)", + "resource_scope": "platform administration of namespace kube-system; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "coredns", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "local-path-provisioner", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "metrics-server", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "traefik", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "DaemonSet", + "namespace": "kube-system", + "name": "svclb-traefik-0c8aecaf", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "kube-dns", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "metrics-server", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "telemetry-coredns", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "telemetry-kubelet", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "traefik", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "LoadBalancer" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:mfa", + "owner": "net-kingdom / key-cape", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "mfa or native owner realm (not verified)", + "resource_scope": "platform administration of namespace mfa; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "mfa", + "name": "privacyidea", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "mfa", + "name": "privacyidea-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "Service", + "namespace": "mfa", + "name": "factor-recovery", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "mfa", + "name": "privacyidea", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "mfa", + "name": "privacyidea", + "hosts": [ + "pink.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "mfa", + "name": "privacyidea-account", + "hosts": [ + "pink-account.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "mfa", + "name": "privacyidea-admin", + "hosts": [ + "pink.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:openbao", + "owner": "rapp-openbao / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "openbao or native owner realm (not verified)", + "resource_scope": "platform administration of namespace openbao; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "openbao", + "name": "openbao-ui-gateway", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "openbao", + "name": "openbao", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-active", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-internal", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-standby", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-ui", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-ui-gateway", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:platform-pg-drill", + "owner": "rapp-postgres", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "platform-pg-drill or native owner realm (not verified)", + "resource_scope": "platform administration of namespace platform-pg-drill; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "platform-pg-drill", + "name": "drill-minio", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "platform-pg-drill", + "name": "minio", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:policy-nexus", + "owner": "policy-nexus", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "policy-nexus or native owner realm (not verified)", + "resource_scope": "platform administration of namespace policy-nexus; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "policy-nexus", + "name": "policy-nexus", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "policy-nexus", + "name": "policy-nexus", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "policy-nexus", + "name": "policy-nexus-http", + "hosts": [ + "policy.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "policy-nexus", + "name": "policy-nexus-https", + "hosts": [ + "policy.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:rapp-qonto", + "owner": "rapp-qonto", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "rapp-qonto or native owner realm (not verified)", + "resource_scope": "platform administration of namespace rapp-qonto; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00001-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00002-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00003-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00004-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00005-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00006-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00007-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00008-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00009-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ExternalName" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00001", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00001-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00002", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00002-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00003", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00003-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00004", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00004-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00005", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00005-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00006", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00006-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00007", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00007-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00008", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00008-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00009", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00009-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:rapp-qonto-egress", + "owner": "rapp-qonto", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "rapp-qonto-egress or native owner realm (not verified)", + "resource_scope": "platform administration of namespace rapp-qonto-egress; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "rapp-qonto-egress", + "name": "qonto-egress-proxy", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "rapp-qonto-egress", + "name": "qonto-egress-proxy", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:rein-aharness", + "owner": "rein-aharness", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "rein-aharness or native owner realm (not verified)", + "resource_scope": "platform administration of namespace rein-aharness; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "rein-aharness", + "name": "rein-aharness", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:reuse", + "owner": "reuse-surface", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "reuse or native owner realm (not verified)", + "resource_scope": "platform administration of namespace reuse; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "reuse", + "name": "reuse-surface", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "reuse", + "name": "reuse-surface-landing", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "reuse", + "name": "reuse-surface", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "reuse", + "name": "reuse-surface-landing", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "reuse", + "name": "reuse-surface", + "hosts": [ + "reuse.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "reuse", + "name": "reuse-surface-http-redirect", + "hosts": [ + "reuse.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "reuse", + "name": "reuse-surface-landing", + "hosts": [ + "reuse.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:sbom-nexus", + "owner": "sbom-nexus", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "sbom-nexus or native owner realm (not verified)", + "resource_scope": "platform administration of namespace sbom-nexus; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "sbom-nexus", + "name": "sbom-nexus", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "sbom-nexus", + "name": "sbom-nexus", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:sso", + "owner": "net-kingdom / key-cape", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "sso or native owner realm (not verified)", + "resource_scope": "platform administration of namespace sso; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "sso", + "name": "authelia", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "identity-provisioner", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "keycape", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "lldap", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "sso", + "name": "authelia-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "sso", + "name": "keycape-factor-renewer", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "sso", + "name": "lldap-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "Service", + "namespace": "sso", + "name": "authelia", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "identity-provisioner", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "keycape", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "lldap", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "authelia", + "hosts": [ + "auth.coulomb.social", + "login.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "identity-password-setup", + "hosts": [ + "kc.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "keycape", + "hosts": [ + "kc.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "lldap", + "hosts": [ + "lldap.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:state-hub", + "owner": "state-hub", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "state-hub or native owner realm (not verified)", + "resource_scope": "platform administration of namespace state-hub; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "state-hub", + "name": "state-hub", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "state-hub", + "name": "state-hub-mcp", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "state-hub", + "name": "state-hub", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "state-hub", + "name": "state-hub-mcp", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:target-revenue", + "owner": "target-revenue", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "target-revenue or native owner realm (not verified)", + "resource_scope": "platform administration of namespace target-revenue; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "target-revenue", + "name": "target-revenue", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "target-revenue", + "name": "target-revenue", + "hosts": [ + "revenue.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:telemetry", + "owner": "rapp-telemetry / railiance-platform", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "telemetry or native owner realm (not verified)", + "resource_scope": "platform administration of namespace telemetry; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "telemetry", + "name": "telemetry-grafana", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "telemetry", + "name": "telemetry-kube-state-metrics", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "telemetry", + "name": "telemetry-operator", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "telemetry", + "name": "alertmanager-telemetry-alertmanager", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "telemetry", + "name": "prometheus-telemetry-prometheus", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "alertmanager-operated", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "prometheus-operated", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-alertmanager", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-grafana", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-kube-state-metrics", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-operator", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-prometheus", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:tenant-engine", + "owner": "tenant-engine", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "tenant-engine or native owner realm (not verified)", + "resource_scope": "platform administration of namespace tenant-engine; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "tenant-engine", + "name": "tenant-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "tenant-engine", + "name": "tenant-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:user-engine", + "owner": "user-engine", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "user-engine or native owner realm (not verified)", + "resource_scope": "platform administration of namespace user-engine; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "user-engine", + "name": "user-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "user-engine", + "name": "user-engine-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "user-engine", + "name": "user-engine", + "hosts": [ + "users.92-205-62-239.nip.io" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "user-engine", + "name": "user-engine-canonical", + "hosts": [ + "users.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "user-engine", + "name": "user-engine-canonical-http", + "hosts": [ + "users.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "namespace:vergabe-demo-company", + "owner": "vergabe-demo-company", + "profile": "platform-owner", + "review_status": "owner attribution inferred; owner confirmation and root acceptance pending", + "audience_candidate": "vergabe-demo-company or native owner realm (not verified)", + "resource_scope": "platform administration of namespace vergabe-demo-company; tenant business-data access requires explicit target grant", + "objects": [ + { + "kind": "Deployment", + "namespace": "vergabe-demo-company", + "name": "vergabe-teilnahme", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Service", + "namespace": "vergabe-demo-company", + "name": "vergabe-teilnahme", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "vergabe-demo-company", + "name": "vergabe-demo-company", + "hosts": [ + "vergabe-teilnahme.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "vergabe-demo-company", + "name": "vergabe-demo-company-http", + "hosts": [ + "vergabe-teilnahme.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ], + "current_gate": "not assessed by discovery; workload readiness does not prove authorization", + "evidence": "read-only Kubernetes metadata snapshot 2026-09-28" + }, + { + "id": "management:ops-hub", + "owner": "ops-hub", + "profile": "extension", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "service.ops-hub.http, framework /api/v2, ops-console, ops-bootstrap", + "evidence": "registry/hub-extension/v0.1.0/ops-hub.extension.json; standalone live service unresolved", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:financial-fabric", + "owner": "fin-hub / railiance-fabric", + "profile": "extension", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "financial graph owner API and projection/export", + "evidence": "FIN-WP-0003; RAIL-FAB-WP-0028 hosted authority blocked", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:repo-manager", + "owner": "repo-manager", + "profile": "platform-owner", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "registry/work projections, governed CLI/Git mutations, Forgejo-backed publisher", + "evidence": "RMGR workplans; publisher is grouped under core-hub; standalone service coverage unverified", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:kubernetes", + "owner": "rail-kubernetes / railiance-platform", + "profile": "native-control", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "realm:kubernetes/railiance01; API, RBAC, nodes, workload lifecycle", + "evidence": "explicit kubeconfig target 92.205.62.239; root OIDC/native identity mapping unverified", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:ssh-tunnels", + "owner": "ops-warden / ops-bridge", + "profile": "native-control", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "railiance01 SSH certificate/principal and named tunnels", + "evidence": "credential routing and bridge owner contracts; root identity mapping unverified", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:gitops-deploy", + "owner": "railiance-platform / railiance-enablement", + "profile": "native-control", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "ArgoCD Core CLI, repo authorization, per-workload release/rollback", + "evidence": "RPF-WP-0044 and owner deployment contracts; no public ArgoCD requirement", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:secrets-engine", + "owner": "secrets-engine / railiance-platform", + "profile": "native-control", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "credential issue/rotate/revoke and approval-bound OpenBao operations", + "evidence": "owner CLI/API plus flex-auth-secrets-engine; no root secret disclosure", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:host-jobs", + "owner": "railiance-platform / activity-core", + "profile": "native-control", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "host systemd timers, cron, backup/restore and DR execution", + "evidence": "not enumerated by Kubernetes snapshot; owner inventory outstanding", + "current_gate": "not proven for platform-root", + "objects": [] + }, + { + "id": "management:external-control", + "owner": "railiance-platform / net-kingdom", + "profile": "native-control", + "review_status": "pending owner review and live acceptance", + "audience_candidate": "owner native audience/realm; unresolved", + "resource_scope": "DNS, registrar, hosting, object storage and off-cluster recovery administration", + "evidence": "provider inventories and entitlement mappings outstanding; no credentials requested", + "current_gate": "not proven for platform-root", + "objects": [] + } + ], + "cluster_snapshot": [ + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-api", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-event-router", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-statehub-edge-relay", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-temporal", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-temporal-ui", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "actcore-worker", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "activity-core", + "name": "llm-connect", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "argocd", + "name": "argocd-applicationset-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "argocd", + "name": "argocd-redis", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "argocd", + "name": "argocd-repo-server", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "audit-core", + "name": "audit-core", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "bao-notice", + "name": "bao-notice", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "canned-prompts", + "name": "canned-prompts", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "cert-manager", + "name": "cert-manager", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "cert-manager", + "name": "cert-manager-cainjector", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "cert-manager", + "name": "cert-manager-webhook", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "cnpg-system", + "name": "cnpg-controller-manager", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "core-hub", + "name": "core-hub-api", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "core-hub", + "name": "core-hub-api-candidate", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "core-hub", + "name": "core-hub-api-repository-publisher", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "coulomb-social", + "name": "coulomb-social", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "coulomb", + "name": "ihp-railiance-probe", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "email-connect", + "name": "email-connect", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "external-secrets", + "name": "external-secrets", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "external-secrets", + "name": "external-secrets-cert-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "external-secrets", + "name": "external-secrets-webhook", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-sitting", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-t03", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-ops-warden", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-secrets-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-tenant-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "flex-auth", + "name": "flex-auth-user-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "forgejo", + "name": "forgejo-gitea", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "forgejo", + "name": "forgejo-runner", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "informed-decision", + "name": "informed-decision", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "inter-hub", + "name": "inter-hub", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "issue-core", + "name": "issue-core", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "activator", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "autoscaler", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "net-kourier-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "knative-serving", + "name": "webhook", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kourier-system", + "name": "3scale-kourier-gateway", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "coredns", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "local-path-provisioner", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "metrics-server", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "kube-system", + "name": "traefik", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "mfa", + "name": "privacyidea", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "openbao", + "name": "openbao-ui-gateway", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "platform-pg-drill", + "name": "drill-minio", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "policy-nexus", + "name": "policy-nexus", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto-egress", + "name": "qonto-egress-proxy", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00001-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00002-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00003-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00004-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00005-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00006-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00007-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00008-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00009-deployment", + "hosts": [], + "desired_replicas": 0, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "rein-aharness", + "name": "rein-aharness", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "reuse", + "name": "reuse-surface", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "reuse", + "name": "reuse-surface-landing", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sbom-nexus", + "name": "sbom-nexus", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "authelia", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "identity-provisioner", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "keycape", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "sso", + "name": "lldap", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "state-hub", + "name": "state-hub", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "state-hub", + "name": "state-hub-mcp", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "target-revenue", + "name": "target-revenue", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "telemetry", + "name": "telemetry-grafana", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "telemetry", + "name": "telemetry-kube-state-metrics", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "telemetry", + "name": "telemetry-operator", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "tenant-engine", + "name": "tenant-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "user-engine", + "name": "user-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "Deployment", + "namespace": "vergabe-demo-company", + "name": "vergabe-teilnahme", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "activity-core", + "name": "actcore-app-db", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "activity-core", + "name": "actcore-nats", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "activity-core", + "name": "actcore-temporal-db", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "approval-engine", + "name": "approval-engine", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "argocd", + "name": "argocd-application-controller", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "openbao", + "name": "openbao", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "telemetry", + "name": "alertmanager-telemetry-alertmanager", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "StatefulSet", + "namespace": "telemetry", + "name": "prometheus-telemetry-prometheus", + "hosts": [], + "desired_replicas": 1, + "ready_replicas": 1, + "suspended": null, + "service_type": null + }, + { + "kind": "DaemonSet", + "namespace": "kube-system", + "name": "svclb-traefik-0c8aecaf", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "audit-core", + "name": "audit-core-attest-chain", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "external-secrets", + "name": "eso-token-renewer", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "mfa", + "name": "privacyidea-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "sso", + "name": "authelia-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "sso", + "name": "keycape-factor-renewer", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "sso", + "name": "lldap-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "CronJob", + "namespace": "user-engine", + "name": "user-engine-backup", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": false, + "service_type": null + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-api", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-app-db", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-nats", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-statehub-edge-relay", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-temporal", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-temporal-db", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-temporal-ui", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "actcore-worker-metrics", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "cm-acme-http-solver-2vrbs", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "NodePort" + }, + { + "kind": "Service", + "namespace": "activity-core", + "name": "llm-connect", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "approval-engine", + "name": "approval-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-applicationset-controller", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-metrics", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-redis", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "argocd", + "name": "argocd-repo-server", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "audit-core", + "name": "audit-core", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "bao-notice", + "name": "bao-notice", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "canned-prompts", + "name": "canned-prompts", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "cert-manager", + "name": "cert-manager", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "cert-manager", + "name": "cert-manager-cainjector", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "cert-manager", + "name": "cert-manager-webhook", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "cnpg-system", + "name": "cnpg-webhook-service", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "core-hub", + "name": "core-hub-api", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "core-hub", + "name": "core-hub-api-candidate", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "core-hub", + "name": "core-hub-api-repository-publisher", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "coulomb-social", + "name": "coulomb-social", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "coulomb", + "name": "ihp-railiance-probe", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "apps-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "apps-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "apps-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "forgejo-db-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "forgejo-db-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "forgejo-db-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "net-kingdom-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "net-kingdom-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "net-kingdom-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-2-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-2-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-2-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "platform-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "state-hub-db-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "state-hub-db-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "databases", + "name": "state-hub-db-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "default", + "name": "kubernetes", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "email-connect", + "name": "email-connect", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "external-secrets", + "name": "external-secrets-webhook", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-sitting", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-informed-decision-t03", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-ops-warden", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-secrets-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-tenant-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "flex-auth", + "name": "flex-auth-user-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "forgejo", + "name": "forgejo-gitea-http", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "forgejo", + "name": "forgejo-gitea-ssh", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "forgejo", + "name": "forgejo-ssh-nodeport", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "NodePort" + }, + { + "kind": "Service", + "namespace": "informed-decision", + "name": "informed-decision", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "inter-hub", + "name": "inter-hub", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "issue-core", + "name": "issue-core", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "activator-service", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "autoscaler", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "autoscaler-bucket-00-of-01", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "controller", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "net-kourier-controller", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "knative-serving", + "name": "webhook", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kourier-system", + "name": "kourier", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kourier-system", + "name": "kourier-internal", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "kube-dns", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "metrics-server", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "telemetry-coredns", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "telemetry-kubelet", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "kube-system", + "name": "traefik", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "LoadBalancer" + }, + { + "kind": "Service", + "namespace": "mfa", + "name": "factor-recovery", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "mfa", + "name": "privacyidea", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-active", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-internal", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-standby", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-ui", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "openbao", + "name": "openbao-ui-gateway", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "platform-pg-drill", + "name": "minio", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "policy-nexus", + "name": "policy-nexus", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto-egress", + "name": "qonto-egress-proxy", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ExternalName" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00001", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00001-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00002", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00002-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00003", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00003-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00004", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00004-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00005", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00005-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00006", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00006-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00007", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00007-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00008", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00008-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00009", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "rapp-qonto", + "name": "rapp-qonto-00009-private", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "reuse", + "name": "reuse-surface", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "reuse", + "name": "reuse-surface-landing", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sbom-nexus", + "name": "sbom-nexus", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "authelia", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "identity-provisioner", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "keycape", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "sso", + "name": "lldap", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "state-hub", + "name": "state-hub", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "state-hub", + "name": "state-hub-mcp", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "target-revenue", + "name": "target-revenue-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "alertmanager-operated", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "prometheus-operated", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-alertmanager", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-grafana", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-kube-state-metrics", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-operator", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "telemetry", + "name": "telemetry-prometheus", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "tenant-engine", + "name": "tenant-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine-pg-r", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine-pg-ro", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "user-engine", + "name": "user-engine-pg-rw", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Service", + "namespace": "vergabe-demo-company", + "name": "vergabe-teilnahme", + "hosts": [], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": "ClusterIP" + }, + { + "kind": "Ingress", + "namespace": "activity-core", + "name": "actcore-ops", + "hosts": [ + "activity.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "activity-core", + "name": "actcore-temporal-ui", + "hosts": [ + "temporal.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "bao-notice", + "name": "bao-notice", + "hosts": [ + "bao.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "bao-notice", + "name": "bao-notice-http-redirect", + "hosts": [ + "bao.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "coulomb-social", + "name": "coulomb-social", + "hosts": [ + "app.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "coulomb", + "name": "ihp-railiance-probe", + "hosts": [ + "probe.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "forgejo", + "name": "forgejo", + "hosts": [ + "forgejo.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "informed-decision", + "name": "informed-decision", + "hosts": [ + "decisions.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "informed-decision", + "name": "informed-decision-http-redirect", + "hosts": [ + "decisions.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "mfa", + "name": "privacyidea", + "hosts": [ + "pink.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "mfa", + "name": "privacyidea-account", + "hosts": [ + "pink-account.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "mfa", + "name": "privacyidea-admin", + "hosts": [ + "pink.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "policy-nexus", + "name": "policy-nexus-http", + "hosts": [ + "policy.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "policy-nexus", + "name": "policy-nexus-https", + "hosts": [ + "policy.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "reuse", + "name": "reuse-surface", + "hosts": [ + "reuse.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "reuse", + "name": "reuse-surface-http-redirect", + "hosts": [ + "reuse.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "reuse", + "name": "reuse-surface-landing", + "hosts": [ + "reuse.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "authelia", + "hosts": [ + "auth.coulomb.social", + "login.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "identity-password-setup", + "hosts": [ + "kc.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "keycape", + "hosts": [ + "kc.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "sso", + "name": "lldap", + "hosts": [ + "lldap.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "target-revenue", + "name": "target-revenue", + "hosts": [ + "revenue.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "user-engine", + "name": "user-engine", + "hosts": [ + "users.92-205-62-239.nip.io" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "user-engine", + "name": "user-engine-canonical", + "hosts": [ + "users.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "user-engine", + "name": "user-engine-canonical-http", + "hosts": [ + "users.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "vergabe-demo-company", + "name": "vergabe-demo-company", + "hosts": [ + "vergabe-teilnahme.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + }, + { + "kind": "Ingress", + "namespace": "vergabe-demo-company", + "name": "vergabe-demo-company-http", + "hosts": [ + "vergabe-teilnahme.coulomb.social" + ], + "desired_replicas": null, + "ready_replicas": null, + "suspended": null, + "service_type": null + } + ] +} diff --git a/docs/platform-access-inventory.md b/docs/platform-access-inventory.md new file mode 100644 index 0000000..2070608 --- /dev/null +++ b/docs/platform-access-inventory.md @@ -0,0 +1,339 @@ +# Platform-root access inventory — 2026-09-28 + +This is the coverage baseline for HUB-WP-0012-T01, not an access grant or a +passing security test. It enumerates 161 Hub source surfaces (88 runtime route +registrations, 42 embedded router operations, 31 MCP tools), 39 observed cluster +namespaces and nine additional extension/native-management boundaries. All 250 +observed Deployment/StatefulSet/DaemonSet/CronJob/Service/Ingress objects map to +exactly one namespace row. Scaled-down revisions and legacy workloads remain +listed so they cannot become unnoticed rollback bypasses. + +The [machine-readable inventory](platform-access-inventory.json) is authoritative +for this snapshot. Rows inherit audience, actor/target tenant, action/resource +mapping, enforcement point and test owner from their named profile. Platform +rows additionally identify responsible repositories and exact Kubernetes objects. +Audience candidates and ownership inferred from deployment names are explicitly +pending owner confirmation; none establishes an effective platform-root grant. + +## Scope and reproducibility + +Hub source revision is recorded in the JSON. Runtime routes are constructed +locally without running startup, sending requests or connecting to a database. +The optional inbox router is included separately. Compatibility aliases and +FastAPI built-in documentation endpoints are included even when absent from +OpenAPI; disabled compatibility groups still belong in the coverage contract. +Embedded factories are scanned with their default prefixes and include optional +operations: host mounting and feature flags determine effective deployment paths. +MCP extraction asserts coverage against CORE_TOOL_NAMES and records its HTTP calls. + +Cluster collection used the explicit railiance01 kubeconfig and metadata-only +projection of six resource kinds. No Secret, environment value, mounted file, +service-account token or authentication credential was collected. This is not a +scan of every CRD, Pod/Job, host process, external provider or tenant application +endpoint. Native execution and external-control rows keep those inventory gaps +visible. Root administration of tenant infrastructure is distinct from an +unreviewed grant to its business data. + +Run from hub-core: + +```sh +PYTHONDONTWRITEBYTECODE=1 .venv/bin/python tools/build_access_inventory.py \ + --inventory docs/platform-access-inventory.json --check +``` + +Omit `--check` to refresh source rows after intentional changes, then review the +diff. Cluster metadata is a dated reviewed input, not silently refreshed by this +command. The checker detects source drift, missing profile/test references and +missing/duplicate cluster-object mappings. It does not test authorization. Actual +allow/deny cases are all marked `not-run`; implementation tasks must supply the +client fixtures, isolated mutations, independent readbacks and live receipts. + +## Findings that affect implementation + +1. **Documentation routes have overlapping handlers.** GET `/docs` and `/openapi.json` + each register both FastAPI's built-in handler and a compatibility alias. + Protecting only the compatibility handler leaves another dispatch path. + T04 must test effective routing, including HEAD and slash normalization. +2. **MCP is not synonymous with the standalone runtime.** Many tools call + `/messages`, `/domains`, `/state/summary` and other host routes rather than + `/ports/...`. T04/T05 need an explicit backend/migration mapping and per-caller + authentication. A successful native-port test does not cover these tools. +3. **Embedded APIs are independent entry points.** The host owns authentication, + policy injection and any prefix overrides; an Ingress change cannot protect + a host that mounts the SDK elsewhere. Inventory actual consumer mounts before + freezing T01, using the retirement route/caller ledgers. +4. **39 namespaces do not mean 39 login surfaces.** Controllers, backing stores, + scaled-down revisions and the notice page should be managed through their + owner/Kubernetes path, not exposed as new human-facing services. Each owner + must split management and application audiences within its namespace row. +5. **Extensions/native administration still need owner evidence.** Ops Hub's + manifest names `service.ops-hub.http`, a framework API, console and CLI; + standalone live resolution is unproven. Fabric hosting is independently + blocked under RAIL-FAB-WP-0028. SSH, Kubernetes, GitOps, host jobs and provider + control planes need their own root entitlement receipts. + +## Proposed acceptance cases + +Every non-health surface runs ROOT, OTHER, INVALID, REVOKE, OUTAGE, BYPASS and +CALLER from the JSON; native privileged actions additionally run APPROVAL. +`/healthz` gets HEALTH instead of pretending anonymous probes should be denied. +These are test specifications, not completed tests: + +| Case | Required observation | +| --- | --- | +| ROOT | Verified immutable root identity + current entitlement + AAL2 succeeds; independent readback and actor audit | +| OTHER | Ordinary user and tenant administrator cannot perform platform operations or learn unauthorized tenant data | +| INVALID | Anonymous, forged username/header, wrong audience/issuer and expired token rejected without side effect | +| REVOKE | Grant removal, account suspension and logout deny within the specified bound; current authority rechecked for privileged mutation | +| OUTAGE | Untrusted/unavailable policy or required audit cannot authorize mutation | +| BYPASS | Direct Service, aliases, MCP and embedded hosts enforce the same decision | +| CALLER | Named workload receives only its grant; spoofed sender, delegation and inherited root authority fail | +| APPROVAL | Full root entitlement does not skip action-specific confirmation/approval; use reversible or isolated targets | +| HEALTH | Anonymous liveness reveals no subject, tenant, dependency or business details | + +## Hub surface register + +The table lists every discovered source operation. JSON retains factory/handler, +source location, current gate observation and MCP target call expressions. +Duplicate runtime method/path rows are intentional separate registrations. + +| Kind/profile | Operation | Source/handler | +| --- | --- | --- | +| runtime-http / hub-api | `GET /annotation-categories` | `annotation_categories` | +| runtime-http / hub-api | `GET /annotations` | `empty_collection` | +| runtime-http / hub-api | `GET /api-consumers` | `list_consumers` | +| runtime-http / hub-api | `GET /api/v2/annotation-categories` | `annotation_categories` | +| runtime-http / hub-api | `GET /api/v2/annotations` | `empty_collection` | +| runtime-http / hub-api | `GET /api/v2/api-consumers` | `list_consumers` | +| runtime-http / hub-api | `GET /api/v2/decision-records` | `empty_collection` | +| runtime-http / hub-api | `GET /api/v2/deployment-records` | `empty_collection` | +| runtime-http / hub-api | `GET /api/v2/docs` | `docs` | +| runtime-http / hub-api | `GET /api/v2/event-types` | `event_types` | +| runtime-http / hub-api | `GET /api/v2/hub-capability-manifests` | `list_manifests` | +| runtime-http / hub-api | `GET /api/v2/hub-registry` | `hub_registry` | +| runtime-http / hub-api | `GET /api/v2/hubs` | `list_hubs` | +| runtime-http / hub-api | `GET /api/v2/interaction-events` | `list_interactions` | +| runtime-http / hub-api | `GET /api/v2/openapi.json` | `openapi_json` | +| runtime-http / hub-api | `GET /api/v2/openapi.yaml` | `openapi_yaml` | +| runtime-http / hub-api | `GET /api/v2/outcome-signals` | `empty_collection` | +| runtime-http / hub-api | `GET /api/v2/policy-scopes` | `policy_scopes` | +| runtime-http / hub-api | `GET /api/v2/requirement-candidates` | `empty_collection` | +| runtime-http / hub-api | `GET /api/v2/widget-types` | `widget_types` | +| runtime-http / hub-api | `GET /api/v2/widgets` | `list_widgets` | +| runtime-http / hub-api | `GET /console` | `console` | +| runtime-http / hub-api | `GET /decision-records` | `empty_collection` | +| runtime-http / hub-api | `GET /deployment-records` | `empty_collection` | +| runtime-http / hub-api | `GET /docs/oauth2-redirect` | `swagger_ui_redirect` | +| runtime-http / hub-api | `GET /docs` | `swagger_ui_html` | +| runtime-http / hub-api | `GET /docs` | `docs` | +| runtime-http / hub-api | `GET /event-types` | `event_types` | +| runtime-http / minimal-health | `GET /healthz` | `healthz` | +| runtime-http / hub-api | `GET /hub-capability-manifests` | `list_manifests` | +| runtime-http / hub-api | `GET /hub-registry` | `hub_registry` | +| runtime-http / hub-api | `GET /hubs` | `list_hubs` | +| runtime-http / hub-api | `GET /interaction-events` | `list_interactions` | +| runtime-http / hub-api | `GET /openapi.json` | `openapi` | +| runtime-http / hub-api | `GET /openapi.json` | `openapi_json` | +| runtime-http / hub-api | `GET /openapi.yaml` | `openapi_yaml` | +| runtime-http / hub-api | `GET /outcome-signals` | `empty_collection` | +| runtime-http / hub-api | `GET /policy-scopes` | `policy_scopes` | +| runtime-http / hub-api | `GET /ports/messaging/messages` | `list_messages` | +| runtime-http / hub-api | `GET /ports/projections/repository-navigation/facets/{facet_kind}/{facet_value}` | `query_facet` | +| runtime-http / hub-api | `GET /ports/projections/repository-navigation/repositories` | `query_repositories` | +| runtime-http / hub-api | `GET /ports/projections/statehub-inbox` | `inbox` | +| runtime-http / hub-api | `GET /ports/projections/workloads/resolve` | `resolve_workload` | +| runtime-http / hub-api | `GET /ports/projections/workloads` | `query_workloads` | +| runtime-http / hub-api | `GET /ports/projections/{projection_id}` | `query_projection` | +| runtime-http / hub-api | `GET /ports/registry/registrations/{hub_slug}/audit` | `registration_audit` | +| runtime-http / hub-api | `GET /ports/registry/registrations/{hub_slug}` | `resolve_registration` | +| runtime-http / hub-api | `GET /readyz` | `readyz` | +| runtime-http / hub-api | `GET /redoc` | `redoc_html` | +| runtime-http / hub-api | `GET /requirement-candidates` | `empty_collection` | +| runtime-http / hub-api | `GET /widget-types` | `widget_types` | +| runtime-http / hub-api | `GET /widgets` | `list_widgets` | +| runtime-http / hub-api | `HEAD /docs/oauth2-redirect` | `swagger_ui_redirect` | +| runtime-http / hub-api | `HEAD /docs` | `swagger_ui_html` | +| runtime-http / hub-api | `HEAD /openapi.json` | `openapi` | +| runtime-http / hub-api | `HEAD /redoc` | `redoc_html` | +| runtime-http / hub-api | `PATCH /api/v2/hub-capability-manifests/{manifest_id}` | `patch_manifest` | +| runtime-http / hub-api | `PATCH /hub-capability-manifests/{manifest_id}` | `patch_manifest` | +| runtime-http / hub-api | `POST /annotations` | `accept_deferred` | +| runtime-http / hub-api | `POST /api-consumers/{consumer_id}/api-keys` | `create_key` | +| runtime-http / hub-api | `POST /api-consumers` | `create_consumer` | +| runtime-http / hub-api | `POST /api/v2/annotations` | `accept_deferred` | +| runtime-http / hub-api | `POST /api/v2/api-consumers/{consumer_id}/api-keys` | `create_key` | +| runtime-http / hub-api | `POST /api/v2/api-consumers` | `create_consumer` | +| runtime-http / hub-api | `POST /api/v2/decision-records` | `accept_deferred` | +| runtime-http / hub-api | `POST /api/v2/deployment-records` | `accept_deferred` | +| runtime-http / hub-api | `POST /api/v2/hub-capability-manifests/{manifest_id}/activate` | `activate_manifest` | +| runtime-http / hub-api | `POST /api/v2/hub-capability-manifests` | `create_manifest` | +| runtime-http / hub-api | `POST /api/v2/hubs` | `create_hub` | +| runtime-http / hub-api | `POST /api/v2/interaction-events` | `create_interaction` | +| runtime-http / hub-api | `POST /api/v2/outcome-signals` | `accept_deferred` | +| runtime-http / hub-api | `POST /api/v2/requirement-candidates` | `accept_deferred` | +| runtime-http / hub-api | `POST /api/v2/token` | `token` | +| runtime-http / hub-api | `POST /api/v2/widgets` | `create_widget` | +| runtime-http / hub-api | `POST /decision-records` | `accept_deferred` | +| runtime-http / hub-api | `POST /deployment-records` | `accept_deferred` | +| runtime-http / hub-api | `POST /hub-capability-manifests/{manifest_id}/activate` | `activate_manifest` | +| runtime-http / hub-api | `POST /hub-capability-manifests` | `create_manifest` | +| runtime-http / hub-api | `POST /hubs` | `create_hub` | +| runtime-http / hub-api | `POST /interaction-events` | `create_interaction` | +| runtime-http / hub-api | `POST /outcome-signals` | `accept_deferred` | +| runtime-http / hub-api | `POST /ports/events/interaction` | `append_interaction` | +| runtime-http / hub-api | `POST /ports/events/progress` | `append_progress` | +| runtime-http / hub-api | `POST /ports/messaging/messages` | `send_message` | +| runtime-http / hub-api | `POST /ports/registry/registrations` | `register_extension` | +| runtime-http / hub-api | `POST /requirement-candidates` | `accept_deferred` | +| runtime-http / hub-api | `POST /token` | `token` | +| runtime-http / hub-api | `POST /widgets` | `create_widget` | +| mcp / mcp-client | `accept_capability_request` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `append_progress` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `check_repo_doi` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_alerts` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_capability_request` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_doi_summary` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_domain` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_domain_summary` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_gdpr_report` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_messages` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_repository_navigation_facet` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_risks` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `get_state_summary` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `ingest_tpsc_tool` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `list_capabilities` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `list_capability_requests` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `list_domain_repos` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `list_domains` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `list_services` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `mark_message_read` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `query_repository_navigation` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `query_workloads` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `register_capability` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `register_repo` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `register_service` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `reply_to_message` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `request_capability` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `resolve_workload_reference` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `send_message` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `update_capability_request_status` | `hub_core/mcp/server.py` | +| mcp / mcp-client | `update_repo_path` | `hub_core/mcp/server.py` | +| embedded-http / embedded-host | `GET /capability-catalog/` | `create_capability_catalog_router` | +| embedded-http / embedded-host | `PATCH /capability-catalog/{entry_id}` | `create_capability_catalog_router` | +| embedded-http / embedded-host | `POST /capability-catalog/` | `create_capability_catalog_router` | +| embedded-http / embedded-host | `GET /capability-requests/` | `create_capability_request_read_router` | +| embedded-http / embedded-host | `GET /capability-requests/{request_id}` | `create_capability_request_read_router` | +| embedded-http / embedded-host | `PATCH /capability-requests/{request_id}` | `create_capability_request_write_router` | +| embedded-http / embedded-host | `PATCH /capability-requests/{request_id}/status` | `create_capability_request_write_router` | +| embedded-http / embedded-host | `POST /capability-requests/` | `create_capability_request_write_router` | +| embedded-http / embedded-host | `POST /capability-requests/{request_id}/accept` | `create_capability_request_write_router` | +| embedded-http / embedded-host | `POST /capability-requests/{request_id}/dispute` | `create_capability_request_write_router` | +| embedded-http / embedded-host | `POST /capability-requests/{request_id}/reroute` | `create_capability_request_write_router` | +| embedded-http / embedded-host | `GET /domains/` | `create_domains_router` | +| embedded-http / embedded-host | `GET /domains/{slug}` | `create_domains_router` | +| embedded-http / embedded-host | `PATCH /domains/{slug}` | `create_domains_router` | +| embedded-http / embedded-host | `PATCH /domains/{slug}/archive` | `create_domains_router` | +| embedded-http / embedded-host | `PATCH /domains/{slug}/rename` | `create_domains_router` | +| embedded-http / embedded-host | `POST /domains/` | `create_domains_router` | +| embedded-http / embedded-host | `GET /messages/` | `create_messages_router` | +| embedded-http / embedded-host | `GET /messages/thread/{thread_id}` | `create_messages_router` | +| embedded-http / embedded-host | `PATCH /messages/{message_id}/archive` | `create_messages_router` | +| embedded-http / embedded-host | `PATCH /messages/{message_id}/read` | `create_messages_router` | +| embedded-http / embedded-host | `POST /messages/` | `create_messages_router` | +| embedded-http / embedded-host | `POST /messages/{message_id}/reply` | `create_messages_router` | +| embedded-http / embedded-host | `GET /policy/{name}` | `create_policy_router` | +| embedded-http / embedded-host | `PUT /policy/{name}` | `create_policy_router` | +| embedded-http / embedded-host | `GET /progress/` | `create_progress_router` | +| embedded-http / embedded-host | `GET /progress/alerts` | `create_progress_router` | +| embedded-http / embedded-host | `GET /progress/risks` | `create_progress_router` | +| embedded-http / embedded-host | `POST /progress/` | `create_progress_router` | +| embedded-http / embedded-host | `GET /repos/` | `create_repos_router` | +| embedded-http / embedded-host | `GET /repos/by-fingerprint` | `create_repos_router` | +| embedded-http / embedded-host | `GET /repos/by-remote` | `create_repos_router` | +| embedded-http / embedded-host | `GET /repos/{slug}` | `create_repos_router` | +| embedded-http / embedded-host | `PATCH /repos/{slug}` | `create_repos_router` | +| embedded-http / embedded-host | `POST /repos/` | `create_repos_router` | +| embedded-http / embedded-host | `POST /repos/{slug}/paths` | `create_repos_router` | +| embedded-http / embedded-host | `GET /tpsc/catalog/` | `create_tpsc_router` | +| embedded-http / embedded-host | `GET /tpsc/catalog/{slug}` | `create_tpsc_router` | +| embedded-http / embedded-host | `GET /tpsc/report/gdpr` | `create_tpsc_router` | +| embedded-http / embedded-host | `GET /tpsc/snapshots/` | `create_tpsc_router` | +| embedded-http / embedded-host | `POST /tpsc/catalog/` | `create_tpsc_router` | +| embedded-http / embedded-host | `POST /tpsc/ingest/` | `create_tpsc_router` | + +## Platform and extension register + +All rows require owner review and root acceptance. The JSON contains exact +object names, hosts, desired/ready replicas and service types for cluster rows. +This mapping identifies accountable review destinations, not completed review. + +| Boundary | Owner / test owner | Coverage | +| --- | --- | --- | +| `namespace:activity-core` | activity-core | 22 observed objects | +| `namespace:approval-engine` | approval-engine | 2 observed objects | +| `namespace:argocd` | railiance-platform / railiance-enablement | 8 observed objects | +| `namespace:audit-core` | audit-core | 3 observed objects | +| `namespace:bao-notice` | railiance-platform | 4 observed objects | +| `namespace:canned-prompts` | rapp-canned-prompts | 2 observed objects | +| `namespace:cert-manager` | railiance-platform | 6 observed objects | +| `namespace:cnpg-system` | rapp-postgres | 2 observed objects | +| `namespace:core-hub` | hub-core / rapp-core-hub / repo-manager | 6 observed objects | +| `namespace:coulomb` | railiance-platform (probe owner to confirm) | 3 observed objects | +| `namespace:coulomb-social` | coulomb-social | 3 observed objects | +| `namespace:databases` | rapp-postgres / railiance-platform | 18 observed objects | +| `namespace:default` | railiance-platform | 1 observed objects | +| `namespace:email-connect` | email-connect | 2 observed objects | +| `namespace:external-secrets` | railiance-platform | 5 observed objects | +| `namespace:flex-auth` | flex-auth | 12 observed objects | +| `namespace:forgejo` | railiance-forge / railiance-platform | 6 observed objects | +| `namespace:informed-decision` | informed-decision | 4 observed objects | +| `namespace:inter-hub` | prj-state-hub-retirement / railiance-platform | 2 observed objects | +| `namespace:issue-core` | issue-core | 2 observed objects | +| `namespace:knative-serving` | rail-knative / railiance-platform | 11 observed objects | +| `namespace:kourier-system` | rail-knative / railiance-platform | 3 observed objects | +| `namespace:kube-system` | rail-kubernetes / railiance-platform | 10 observed objects | +| `namespace:mfa` | net-kingdom / key-cape | 7 observed objects | +| `namespace:openbao` | rapp-openbao / railiance-platform | 8 observed objects | +| `namespace:platform-pg-drill` | rapp-postgres | 2 observed objects | +| `namespace:policy-nexus` | policy-nexus | 4 observed objects | +| `namespace:rapp-qonto` | rapp-qonto | 28 observed objects | +| `namespace:rapp-qonto-egress` | rapp-qonto | 2 observed objects | +| `namespace:rein-aharness` | rein-aharness | 1 observed objects | +| `namespace:reuse` | reuse-surface | 7 observed objects | +| `namespace:sbom-nexus` | sbom-nexus | 2 observed objects | +| `namespace:sso` | net-kingdom / key-cape | 15 observed objects | +| `namespace:state-hub` | state-hub | 4 observed objects | +| `namespace:target-revenue` | target-revenue | 6 observed objects | +| `namespace:telemetry` | rapp-telemetry / railiance-platform | 12 observed objects | +| `namespace:tenant-engine` | tenant-engine | 2 observed objects | +| `namespace:user-engine` | user-engine | 9 observed objects | +| `namespace:vergabe-demo-company` | vergabe-demo-company | 4 observed objects | +| `management:ops-hub` | ops-hub | service.ops-hub.http, framework /api/v2, ops-console, ops-bootstrap | +| `management:financial-fabric` | fin-hub / railiance-fabric | financial graph owner API and projection/export | +| `management:repo-manager` | repo-manager | registry/work projections, governed CLI/Git mutations, Forgejo-backed publisher | +| `management:kubernetes` | rail-kubernetes / railiance-platform | realm:kubernetes/railiance01; API, RBAC, nodes, workload lifecycle | +| `management:ssh-tunnels` | ops-warden / ops-bridge | railiance01 SSH certificate/principal and named tunnels | +| `management:gitops-deploy` | railiance-platform / railiance-enablement | ArgoCD Core CLI, repo authorization, per-workload release/rollback | +| `management:secrets-engine` | secrets-engine / railiance-platform | credential issue/rotate/revoke and approval-bound OpenBao operations | +| `management:host-jobs` | railiance-platform / activity-core | host systemd timers, cron, backup/restore and DR execution | +| `management:external-control` | railiance-platform / net-kingdom | DNS, registrar, hosting, object storage and off-cluster recovery administration | + +## Remaining T01 decisions + +- NetKingdom/User Engine: verify root `(iss, sub)` and the entitlement mapping; + confirm registered audiences, MFA journey and measurable revocation bounds. +- flex-auth/Tenant Engine: ratify action/resource names, authoritative fact + checks, cross-tenant root administration and decision/audit obligations. +- Hub/extension owners: map effective embedded mounts, legacy MCP destinations, + active extension discovery and public/health exceptions; resolve duplicate docs. +- Railiance owners: confirm namespace ownership, enumerate per-service audiences + and endpoint catalogs, CRD/Job/host/provider management paths, and the native + SSH/Kubernetes/GitOps grants. Unknown surfaces cannot be marked passed. +- All reviewers: approve the versioned profile and supply executable enforcement + fixtures/receipts. Until then T01 remains in progress and public exposure stays + gated. No new workplan or live configuration change was made by this inventory. + +Related evidence: [access blueprint](netkingdom-access-blueprint.md), +[HUB-WP-0012](../workplans/HUB-WP-0012-netkingdom-platform-root-access.md), +`ops-hub/registry/hub-extension/v0.1.0/ops-hub.extension.json`, retirement project +`inventory/routes.yaml` and `inventory/jobs-callers-ops.yaml`. diff --git a/tools/build_access_inventory.py b/tools/build_access_inventory.py new file mode 100644 index 0000000..d5e2e01 --- /dev/null +++ b/tools/build_access_inventory.py @@ -0,0 +1,131 @@ +#!/usr/bin/env python3 +"""Inventory source surfaces without network calls, database access or credentials. + +Run with hub-core's runtime environment. --check detects source-surface drift; +it is not an authorization conformance test. Platform snapshot is reviewed input. +""" +import argparse +import ast +import inspect +import json +from pathlib import Path +import sys + + +def discover(root): + sys.path.insert(0, str(root)) + from hub_core.runtime.app import create_app + from hub_core.runtime.config import RuntimeSettings + from hub_core.runtime.inbox_projection import create_inbox_projection_router + + rows = [] + + def routes(router): + for route in router.routes: + if hasattr(route, 'original_router'): + yield from routes(route.original_router) + elif hasattr(route, 'methods'): + yield route + else: + raise ValueError(f'Uninventoried route type: {type(route).__name__}') + + # Construction only: no lifespan/startup and no requests or DB connection. + app = create_app(settings=RuntimeSettings()) + for route in [*routes(app), *routes(create_inbox_projection_router())]: + endpoint = route.endpoint + source = inspect.getsource(endpoint) + module = endpoint.__module__ + gate = ('shared-bearer' if '_protected(' in source or module.endswith('inbox_projection') + else 'no-identity-check-in-handler') + for method in sorted(route.methods): + rows.append(dict(id=f'http:{method}:{route.path}:{module}.{endpoint.__name__}', kind='runtime-http', + method=method, path=route.path, profile=('minimal-health' if route.path == '/healthz' else 'hub-api'), + current_gate=gate, source=module, + conditional=module.endswith('inbox_projection'), + handler=endpoint.__name__)) + + verbs = {'get', 'post', 'patch', 'put', 'delete', 'head', 'options'} + for path in sorted((root / 'hub_core/routers').glob('*.py')): + tree = ast.parse(path.read_text()) + for factory in tree.body: + if not isinstance(factory, ast.FunctionDef) or not factory.name.startswith('create_'): + continue + prefix = '' + for node in ast.walk(factory): + if isinstance(node, ast.Call) and isinstance(node.func, ast.Name) and node.func.id == 'APIRouter': + for kw in node.keywords: + if kw.arg == 'prefix': + if isinstance(kw.value, ast.Constant): + prefix = kw.value.value + elif isinstance(kw.value, ast.Name): + defaults = dict(zip([a.arg for a in factory.args.kwonlyargs], factory.args.kw_defaults)) + prefix = ast.literal_eval(defaults[kw.value.id]) + else: + raise ValueError('Unresolved SDK prefix') + for node in ast.walk(factory): + if not isinstance(node, (ast.FunctionDef, ast.AsyncFunctionDef)): + continue + for dec in node.decorator_list: + if isinstance(dec, ast.Call) and isinstance(dec.func, ast.Attribute) and dec.func.attr in verbs: + route_path = prefix + ast.literal_eval(dec.args[0]) + method = dec.func.attr.upper() + rows.append(dict(id=f'sdk:{factory.name}:{method}:{route_path}', + kind='embedded-http', method=method, path=route_path, + profile='embedded-host', factory=factory.name, + source=str(path.relative_to(root)), line=node.lineno, + current_gate='host-injected; not established by inventory', + conditional=True)) + + path = root / 'hub_core/mcp/server.py' + tree = ast.parse(path.read_text()) + expected = None + for node in tree.body: + if isinstance(node, ast.Assign) and any(isinstance(t, ast.Name) and t.id == 'CORE_TOOL_NAMES' for t in node.targets): + expected = set(ast.literal_eval(node.value.args[0])) + for node in ast.walk(tree): + if not isinstance(node, (ast.FunctionDef, ast.AsyncFunctionDef)): + continue + for dec in node.decorator_list: + if isinstance(dec, ast.Call) and isinstance(dec.func, ast.Name) and dec.func.id == 'register': + name = ast.literal_eval(dec.args[0]) + calls = [] + for call in ast.walk(node): + if isinstance(call, ast.Call) and isinstance(call.func, ast.Attribute) and call.func.attr in {'_get','_post','_patch','_put','_delete'}: + calls.append(dict(method=call.func.attr[1:].upper(), path_expression=ast.unparse(call.args[0]))) + rows.append(dict(id=f'mcp:{name}', kind='mcp', tool=name, profile='mcp-client', + source=str(path.relative_to(root)), line=node.lineno, + target_calls=calls, current_gate='no per-user credential forwarding in base wrapper')) + assert expected == {r['tool'] for r in rows if r['kind'] == 'mcp'} + assert len(rows) == len({r['id'] for r in rows}), 'Duplicate surface identity' + return sorted(rows, key=lambda r:r['id']) + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument('--root', type=Path, default=Path(__file__).resolve().parents[1]) + parser.add_argument('--inventory', type=Path, required=True) + parser.add_argument('--check', action='store_true') + args = parser.parse_args() + data = json.loads(args.inventory.read_text()) + found = discover(args.root) + if args.check: + assert data['hub_surfaces'] == found, 'Source inventory drift; regenerate and review' + else: + data['hub_surfaces'] = found + args.inventory.write_text(json.dumps(data, indent=2)+'\n') + cases = data['acceptance_cases'] + profiles = data['profiles'] + for row in data['hub_surfaces'] + data['platform_surfaces']: + profile = profiles[row['profile']] + assert all(profile.get(k) for k in ('audience','actor_tenant','target_tenant','action_resource_rule','enforcement','test_owner','cases')) + assert all(c in cases for c in profile['cases']) + objects = data['cluster_snapshot'] + mapped = [x for r in data['platform_surfaces'] for x in r.get('objects',[])] + keys = lambda xs: sorted((x['kind'],x['namespace'],x['name']) for x in xs) + assert keys(mapped) == keys(objects), 'Cluster object coverage mismatch or duplicates' + assert all(r.get('owner') and r.get('review_status') for r in data['platform_surfaces']) + print(f"{len(found)} Hub surfaces; {len(data['platform_surfaces'])} platform rows; {len(objects)} cluster objects; inventory checks pass") + + +if __name__ == '__main__': + main() diff --git a/workplans/HUB-WP-0012-netkingdom-platform-root-access.md b/workplans/HUB-WP-0012-netkingdom-platform-root-access.md index 5df6b7a..b4e7b00 100644 --- a/workplans/HUB-WP-0012-netkingdom-platform-root-access.md +++ b/workplans/HUB-WP-0012-netkingdom-platform-root-access.md @@ -4,7 +4,7 @@ type: workplan title: "NetKingdom identity and tenant integration: platform-root first" domain: infotech repo: hub-core -status: proposed +status: active flavor: implementation owner: codex topic_slug: infotech @@ -43,7 +43,7 @@ existing retirement and rollout plans retain their tasks. Core Hub receives no new product feature work. This planning session does not implement or activate grants, enroll factors, deploy policies, expose services or retire State Hub. -Status is proposed because cross-owner policy, root identity binding and live +Inventory work is active. Cross-owner policy, root identity binding and live acceptance are not yet reviewed. The user has selected the root-first scope; there is no need to reopen that product decision. Dependencies below are per-task sequencing, not a blanket wait for every related workplan to finish. @@ -52,7 +52,7 @@ per-task sequencing, not a blanket wait for every related workplan to finish. ```task id: HUB-WP-0012-T01 -status: todo +status: progress priority: high state_hub_task_id: "204f4fb0-e240-5558-8790-5985517b85e0" ``` @@ -70,6 +70,16 @@ Done when no published route/tool or active platform surface lacks a row and owner, contract reviewers' decisions are recorded, and M1 success/deny cases are executable specifications. Unknown/disputed rows remain visible blockers. +2026-09-28: the [access inventory](../docs/platform-access-inventory.md) now +enumerates 161 Hub source surfaces and 48 platform/extension boundaries, covering +250 observed cluster objects. Its machine-readable profiles specify owners, +audiences, actor/target tenants, enforcement and acceptance cases; the checker +detects source drift and incomplete object mappings. Duplicate docs handlers, +legacy MCP targets and unresolved native/extension paths are explicit findings. +Owner review, effective host/per-service route expansion, policy vocabulary and +authenticated acceptance remain open, so T01 is `progress`, not `done`. No +platform-root login or enforcement test is claimed by inventory validation. + ## T02 — Bind platform-root identity, login, tenant and revocation ```task