diff --git a/workplans/NK-WP-0023-user-engine-portal-platform-integration.md b/workplans/NK-WP-0023-user-engine-portal-platform-integration.md index 0cf51b1..018e863 100644 --- a/workplans/NK-WP-0023-user-engine-portal-platform-integration.md +++ b/workplans/NK-WP-0023-user-engine-portal-platform-integration.md @@ -107,6 +107,12 @@ envelope. KeyCape `90a2078` now maps that group explicitly to tenant-admin mappings remain tenant scoped. The fixed image is Ready on railiance01. +The subsequent live MFA callback exposed a missing destination-side +NetworkPolicy: user-engine allowed egress to KeyCape, but the SSO default deny +had no matching ingress. Commit `8e7229a` adds the namespace-and-pod-scoped +`:8080` rule plus verifier coverage. After applying it, an in-pod discovery +request from user-engine to KeyCape returns HTTP 200. + ## T04 - Integrate authorization, email, audit, and events ```task