Close portal integration MVP and narrow identity cutover
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-30 00:52:52 +02:00
parent 888e5c491f
commit 5959fc0537
4 changed files with 111 additions and 6 deletions

View file

@ -14,7 +14,8 @@
| workplan | NK-WP-0011 | backlog | — | workplans/NK-WP-0011-enterprise-federation-saml.md |
| workplan | NK-WP-0021 | finished | — | workplans/NK-WP-0021-activity-core-ops-sso-operators.md |
| workplan | NK-WP-0022 | active | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md |
| workplan | NK-WP-0023 | active | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| workplan | NK-WP-0023 | finished | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| workplan | NK-WP-0024 | backlog | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
| task | ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md |
| task | ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md |
| task | NET-WP-0020-T01 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md |
@ -52,10 +53,14 @@
| task | NK-WP-0023-T01 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T02 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T03 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T04 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T04 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T05 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T06 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T06 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T07 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0023-T08 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
| task | NK-WP-0024-T01 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
| task | NK-WP-0024-T02 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
| task | NK-WP-0024-T03 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
| task | NK-WP-0024-T04 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
| intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
| intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |

View file

@ -240,6 +240,15 @@ and trusted certificate alias. The complete portal → KeyCape → Authelia
redirect reaches railiance01. LLDAP and both privacyIDEA names remain
intentionally on CoulombCore pending the state and conformance gates above.
2026-07-30 recheck: normal resolution now sends `auth`, `login`, `pink`,
`pink-account`, and `kc` to railiance01 (`92.205.62.239`). Only
`lldap.coulomb.social` still resolves to CoulombCore (`92.205.130.254`);
`bao` remains there intentionally and is outside this identity-workload
cutover. No automated DNS credential lane is registered: `warden route find`
returned generic OpenBao/login/SSH routes, not provider DNS authority.
Consequently T06 remains in progress on one explicit operator DNS change and
its observation window, rather than being closed cosmetically.
## T07 - Retire CoulombCore identity workloads reversibly
```task
@ -262,6 +271,12 @@ explicit recorded approval.
Done when CoulombCore serves no identity traffic and remains recoverable
during the retention window.
2026-07-30 inventory: legacy KeyCape, LLDAP, and privacyIDEA are already scaled
to zero with their resources retained; only CoulombCore Authelia remains at
one replica. It must not be scaled down until the final LLDAP DNS record and
T06 observation gate pass. The reversible retirement is therefore reduced to
one remaining workload plus stale ingress/backup checks.
## T08 - Final deletion and closure
```task

View file

@ -4,7 +4,7 @@ type: workplan
title: "Integrate and deploy the user-engine onboarding portal"
domain: infotech
repo: net-kingdom
status: active
status: finished
owner: codex
topic_slug: netkingdom
created: "2026-07-27"
@ -138,7 +138,7 @@ errors, so future users may enter either `bernd.worsch` or the full email.
```task
id: NK-WP-0023-T04
status: wait
status: done
priority: high
state_hub_task_id: "6ce33c92-031a-4f23-8ee2-108451b394fe"
```
@ -224,7 +224,7 @@ value entered recorded output. All T05 acceptance criteria are complete.
```task
id: NK-WP-0023-T06
status: wait
status: done
priority: high
state_hub_task_id: "96a7cd2b-6cab-47ab-a899-44bc0f6da58c"
```
@ -297,3 +297,17 @@ defines compatibility seams, not enterprise implementation.
federation, SCIM, JIT, group mapping, provenance, source ownership,
conflict/freshness rules, offboarding, failure behavior, and demand triggers
without starting the demand-gated enterprise implementation.
## Milestone closure (2026-07-30)
The live Binky MVP consumes verified KeyCape claims, enforces tenant/platform
role separation through user-engine's authorization port, correlates durable
audit/outbox records, and keeps password and MFA interactions on
NetKingdom-owned surfaces. Role-scoped administration, platform and unrelated
tenant denial, AAL2 login, drift/reconciliation, replay-safe deletion, restore,
rollback, secret rotation, and dependency failure/recovery are proven.
Replacing the pre-production authorization adapter with a deployed flex-auth
policy package, invitation mail, operated outbox replay/dead-letter delivery,
and the broader integration failure matrix transfer explicitly to
`NK-WP-0024`; they are not claimed as part of this completed milestone.

View file

@ -0,0 +1,71 @@
---
id: NK-WP-0024
type: workplan
title: "Expand user-engine platform integrations beyond the Binky MVP"
domain: infotech
repo: net-kingdom
status: backlog
owner: codex
topic_slug: netkingdom
created: "2026-07-30"
updated: "2026-07-30"
depends_on:
- NK-WP-0023
- USER-WP-0021
state_hub_workstream_id: "9bd05700-a839-4014-8f88-8a78f2757721"
---
# NK-WP-0024 - Portal integration expansion
Track deferred integration breadth separately from the completed live MVP.
Activate with the corresponding user-engine product-expansion tasks.
## T01 - Establish flex-auth production authorization
```task
id: NK-WP-0024-T01
status: todo
priority: high
state_hub_task_id: "7dff0ac6-c5eb-486c-83db-a1400f30f77d"
```
Define self, tenant-admin, and platform-admin resource/action vocabulary,
deploy the policy package, replace user-engine's local runtime adapter with a
fail-closed flex-auth HTTP adapter, and correlate decision IDs with audit.
## T02 - Add invitation and verification mail delivery
```task
id: NK-WP-0024-T02
status: todo
priority: medium
state_hub_task_id: "9d5f272b-115c-404d-8387-7f987cee65ea"
```
Deliver invitation and verification messages through approved custody and
mail lanes. Mailbox ownership remains evidence, never authorization.
## T03 - Operate durable event delivery
```task
id: NK-WP-0024-T03
status: todo
priority: high
state_hub_task_id: "17d6390b-05a8-436c-879b-4e0331d85be5"
```
Connect the user-engine transactional outbox to the platform event lane with
bounded retries, replay, dead-letter visibility, redaction, and correlation.
## T04 - Run expanded integration failure matrix
```task
id: NK-WP-0024-T04
status: todo
priority: high
state_hub_task_id: "4c54e8e4-19d9-4470-bb43-3d43cf27af71"
```
Prove flex-auth denial/unavailability, mail failure, identity-provider outage,
partial provisioning recovery, invitation replay/expiry, and cross-tenant
negative behavior through the deployed path.