2026-09-28 12:40:10 +02:00
# NetKingdom Kubernetes integration guidance
This directory holds bootstrap tooling, integration references and migration
history. Current managed deployment belongs to the service/package owners
under [ADR-0015 ](../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md ).
The [original foundation procedure ](FOUNDATIONS-HISTORICAL.md ) is retained as
historical material, including its old prerequisites and apply commands.
## Operating baseline
The [September 28 review ](../../history/2026-09-28-open-workplan-infrastructure-review.md )
observed one Ready Railiance01 node at `92.205.62.239` , healthy lightweight
identity components and single-instance CNPG databases. This is a dated
inventory, not an HA, recovery or user-login acceptance claim.
| Surface | Current role and owner |
| --- | --- |
| KeyCape / Authelia / LLDAP (`sso` ) and privacyIDEA (`mfa` ) | Lightweight identity composition; issuer implementation in `key-cape` , integration contracts here |
| User Engine | [rapp-user-engine ](../../../rapp-user-engine/README.md ) owns managed manifests, rollout and rollback |
| Tenant Engine | [rapp-tenant-engine ](../../../rapp-tenant-engine/README.md ) owns managed runtime and database-consumption configuration |
| flex-auth consumer services | [Owner values and chart pointers ](tenant-engine/README.md ); caller authentication is enforced by the owner declarations |
| OpenBao and database custody | `railiance-platform` , with managed packages and consumer declarations in their owning repositories |
| Kubernetes and host substrate | [railiance-cluster operator runbook ](../../../railiance-cluster/docs/operator-runbook.md ) and `railiance-infra` |
OpenBao's public browser endpoint `bao.coulomb.social` is retired. Operators
use the named `openbao-ui-railiance01` tunnel at `http://127.0.0.1:18200` ;
workloads use the internal Service. Follow the platform's
[operator-only cutover record ](../../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md )
and credential routing in [AGENTS.md ](../../AGENTS.md ). Route access before
requesting credentials; never copy tokens or Secret values into evidence.
## Read-only orientation
Check the context before interpreting these results. All commands below read
resource metadata and readiness; none applies manifests or initiates login.
2026-03-02 09:49:39 +01:00
```bash
2026-09-28 12:40:10 +02:00
kubectl config current-context
kubectl get nodes -o wide
kubectl -n sso get deployments
kubectl -n mfa get deployments
kubectl -n user-engine get deployments
kubectl -n tenant-engine get deployments
kubectl -n flex-auth get deployments
kubectl -n openbao get statefulsets,deployments,services,ingresses
kubectl get clusters.postgresql.cnpg.io -A
2026-03-02 09:49:39 +01:00
```
2026-09-28 12:40:10 +02:00
Ready replicas do not prove negative authorization, actual-user MFA, successful
backup restoration or independent failure domains. Use the relevant owner's
verification and recovery procedure for those claims.
## Deployment and recovery
Start with the owning package's current declaration, immutable image and
reviewed rollout/rollback procedure. Do not recursively apply this tree.
`tenant-engine/runtime.yaml` remains **REFERENCE ONLY — DO NOT APPLY** while
its owner decides the disposition of the five retained historical objects.
Its obsolete flex-auth objects have been replaced with owner pointers.
The scripts and manifests elsewhere in this directory have individual scopes;
their presence here does not make them current production repair commands.
The [attended procedure inventory ](../../docs/attended-procedure-inventory.md )
records their exercise limits. Use the [custody model ](../../docs/openbao-unseal-custody-models.md )
and current owner runbooks to prepare recovery. A database-only drill does not
prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption
material, or all identity database state.
CoulombCore identity cutover is complete; final retained-resource deletion
remains gated by [NK-WP-0022 ](../../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md ).
Expiration of the retention minimum does not authorize deletion.