Accept ADR-0009 with tenant-selectable isolation upgrade path
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

Add shared-realm and dedicated-instance tiers selected by the IAM capability
role, binding reference points (issuer invariance, subject preservation,
tier-neutral declaration, drill), and NK-WP-0011-T09.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 295952@bnt-lap001
Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
This commit is contained in:
tegwick 2026-09-28 23:41:12 +02:00
parent 7d11ce58ce
commit 5497e2c100
3 changed files with 73 additions and 16 deletions

View file

@ -117,7 +117,7 @@ Out of scope:
```task
id: NK-WP-0011-T01
state_hub_task_id: "a5807808-fb34-50de-8f67-9128011833d4"
status: progress
status: done
priority: high
```
@ -251,8 +251,25 @@ audit sink alongside flex-auth/Topaz/OpenBao records, with correlation
ids — satisfying the "Audit sink" and "Break-glass" rows of the
production-readiness checklist.
## Prove the isolation upgrade path
```task
id: NK-WP-0011-T09
status: todo
priority: medium
```
**Shared-realm to dedicated-instance upgrade (ADR-0009, decision 3).** Write
the owner-executed upgrade runbook and rehearse it in an isolated environment
before any paid tier is offered. The drill must show issuer URL unchanged,
every user `sub` and federated link preserved, login working after cutover,
rollback by re-routing during the retention window, and per-tier backup and
restore evidence. Coordinate with tenant-engine on deriving the tier from the
`IAM` capability role; do not add an independent tier field.
## Acceptance Criteria
- A rehearsed shared-to-dedicated isolation upgrade preserves issuer and subjects.
- An ADR records the expanded-mode trigger, federation topology,
selected realm/tenant isolation model, and KeyCape/Keycloak issuer coexistence.
- A federated user from at least one enterprise IdP (Entra ID) can log in