Accept ADR-0009 with tenant-selectable isolation upgrade path
Add shared-realm and dedicated-instance tiers selected by the IAM capability role, binding reference points (issuer invariance, subject preservation, tier-neutral declaration, drill), and NK-WP-0011-T09. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 295952@bnt-lap001 Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
This commit is contained in:
parent
7d11ce58ce
commit
5497e2c100
3 changed files with 73 additions and 16 deletions
|
|
@ -117,7 +117,7 @@ Out of scope:
|
|||
```task
|
||||
id: NK-WP-0011-T01
|
||||
state_hub_task_id: "a5807808-fb34-50de-8f67-9128011833d4"
|
||||
status: progress
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -251,8 +251,25 @@ audit sink alongside flex-auth/Topaz/OpenBao records, with correlation
|
|||
ids — satisfying the "Audit sink" and "Break-glass" rows of the
|
||||
production-readiness checklist.
|
||||
|
||||
## Prove the isolation upgrade path
|
||||
|
||||
```task
|
||||
id: NK-WP-0011-T09
|
||||
status: todo
|
||||
priority: medium
|
||||
```
|
||||
|
||||
**Shared-realm to dedicated-instance upgrade (ADR-0009, decision 3).** Write
|
||||
the owner-executed upgrade runbook and rehearse it in an isolated environment
|
||||
before any paid tier is offered. The drill must show issuer URL unchanged,
|
||||
every user `sub` and federated link preserved, login working after cutover,
|
||||
rollback by re-routing during the retention window, and per-tier backup and
|
||||
restore evidence. Coordinate with tenant-engine on deriving the tier from the
|
||||
`IAM` capability role; do not add an independent tier field.
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
- A rehearsed shared-to-dedicated isolation upgrade preserves issuer and subjects.
|
||||
- An ADR records the expanded-mode trigger, federation topology,
|
||||
selected realm/tenant isolation model, and KeyCape/Keycloak issuer coexistence.
|
||||
- A federated user from at least one enterprise IdP (Entra ID) can log in
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue