32 lines
1.8 KiB
Markdown
32 lines
1.8 KiB
Markdown
|
|
# Tenant Engine integration references
|
||
|
|
|
||
|
|
`runtime.yaml` is **REFERENCE ONLY — DO NOT APPLY**. Its five remaining
|
||
|
|
Tenant Engine objects are historical and differ from the live deployment in
|
||
|
|
image, storage, strategy, environment and egress. Their disposition awaits the
|
||
|
|
Tenant Engine owner under
|
||
|
|
[NK-WP-0039-T04](../../../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md).
|
||
|
|
|
||
|
|
The obsolete flex-auth objects were removed on 2026-09-28 with the owner's
|
||
|
|
agreement. Use the owner's maintained declarations and deployment procedure:
|
||
|
|
|
||
|
|
| Consumer | Authoritative values in the flex-auth repository |
|
||
|
|
| --- | --- |
|
||
|
|
| Tenant Engine | [values/tenant-engine.yaml](../../../../flex-auth/values/tenant-engine.yaml) |
|
||
|
|
| User Engine | [values/user-engine.yaml](../../../../flex-auth/values/user-engine.yaml) |
|
||
|
|
|
||
|
|
The [owner Helm chart](../../../../flex-auth/charts/flex-auth) renders the
|
||
|
|
consumer Deployment, Service and NetworkPolicy, including caller-auth
|
||
|
|
configuration. Both reviewed value files select enforcement and bind the
|
||
|
|
consumer to its own Kubernetes ServiceAccount. Keep those settings at their
|
||
|
|
owner; do not recreate a frozen deployment copy here.
|
||
|
|
|
||
|
|
These links assume sibling checkouts. The current repository coordinate is
|
||
|
|
`coulomb/flex-auth`; its proposed rename to `coulomb/access-engine` remains
|
||
|
|
gated by FLEX-WP-0020. NK-WP-0039-T03 will update these repository pointers
|
||
|
|
when the owner confirms the new coordinate. The `flex-auth` namespace,
|
||
|
|
Service DNS, caller-token audience and OCI package coordinate remain unchanged.
|
||
|
|
|
||
|
|
Ownership follows [ADR-0015](../../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md).
|
||
|
|
Removing references requires no cluster apply or rollout. Do not use the
|
||
|
|
remaining YAML as a way to provision the two flex-auth consumers.
|