Close portal integration MVP and narrow identity cutover
This commit is contained in:
parent
888e5c491f
commit
5959fc0537
4 changed files with 111 additions and 6 deletions
|
|
@ -14,7 +14,8 @@
|
||||||
| workplan | NK-WP-0011 | backlog | — | workplans/NK-WP-0011-enterprise-federation-saml.md |
|
| workplan | NK-WP-0011 | backlog | — | workplans/NK-WP-0011-enterprise-federation-saml.md |
|
||||||
| workplan | NK-WP-0021 | finished | — | workplans/NK-WP-0021-activity-core-ops-sso-operators.md |
|
| workplan | NK-WP-0021 | finished | — | workplans/NK-WP-0021-activity-core-ops-sso-operators.md |
|
||||||
| workplan | NK-WP-0022 | active | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md |
|
| workplan | NK-WP-0022 | active | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md |
|
||||||
| workplan | NK-WP-0023 | active | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| workplan | NK-WP-0023 | finished | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
|
| workplan | NK-WP-0024 | backlog | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
| task | ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md |
|
| task | ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md |
|
||||||
| task | ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md |
|
| task | ADHOC-2026-07-02-T02 | done | — | workplans/ADHOC-2026-07-02.md |
|
||||||
| task | NET-WP-0020-T01 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md |
|
| task | NET-WP-0020-T01 | done | — | workplans/NET-WP-0020-openbao-unseal-custody-and-ssh-automation.md |
|
||||||
|
|
@ -52,10 +53,14 @@
|
||||||
| task | NK-WP-0023-T01 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T01 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T02 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T02 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T03 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T03 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T04 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T04 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T05 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T05 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T06 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T06 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T07 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T07 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T08 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T08 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
|
| task | NK-WP-0024-T01 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
|
| task | NK-WP-0024-T02 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
|
| task | NK-WP-0024-T03 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
|
| task | NK-WP-0024-T04 | todo | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
| intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
| intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
||||||
| intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
| intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md |
|
||||||
|
|
|
||||||
|
|
@ -240,6 +240,15 @@ and trusted certificate alias. The complete portal → KeyCape → Authelia
|
||||||
redirect reaches railiance01. LLDAP and both privacyIDEA names remain
|
redirect reaches railiance01. LLDAP and both privacyIDEA names remain
|
||||||
intentionally on CoulombCore pending the state and conformance gates above.
|
intentionally on CoulombCore pending the state and conformance gates above.
|
||||||
|
|
||||||
|
2026-07-30 recheck: normal resolution now sends `auth`, `login`, `pink`,
|
||||||
|
`pink-account`, and `kc` to railiance01 (`92.205.62.239`). Only
|
||||||
|
`lldap.coulomb.social` still resolves to CoulombCore (`92.205.130.254`);
|
||||||
|
`bao` remains there intentionally and is outside this identity-workload
|
||||||
|
cutover. No automated DNS credential lane is registered: `warden route find`
|
||||||
|
returned generic OpenBao/login/SSH routes, not provider DNS authority.
|
||||||
|
Consequently T06 remains in progress on one explicit operator DNS change and
|
||||||
|
its observation window, rather than being closed cosmetically.
|
||||||
|
|
||||||
## T07 - Retire CoulombCore identity workloads reversibly
|
## T07 - Retire CoulombCore identity workloads reversibly
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
@ -262,6 +271,12 @@ explicit recorded approval.
|
||||||
Done when CoulombCore serves no identity traffic and remains recoverable
|
Done when CoulombCore serves no identity traffic and remains recoverable
|
||||||
during the retention window.
|
during the retention window.
|
||||||
|
|
||||||
|
2026-07-30 inventory: legacy KeyCape, LLDAP, and privacyIDEA are already scaled
|
||||||
|
to zero with their resources retained; only CoulombCore Authelia remains at
|
||||||
|
one replica. It must not be scaled down until the final LLDAP DNS record and
|
||||||
|
T06 observation gate pass. The reversible retirement is therefore reduced to
|
||||||
|
one remaining workload plus stale ingress/backup checks.
|
||||||
|
|
||||||
## T08 - Final deletion and closure
|
## T08 - Final deletion and closure
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
|
||||||
|
|
@ -4,7 +4,7 @@ type: workplan
|
||||||
title: "Integrate and deploy the user-engine onboarding portal"
|
title: "Integrate and deploy the user-engine onboarding portal"
|
||||||
domain: infotech
|
domain: infotech
|
||||||
repo: net-kingdom
|
repo: net-kingdom
|
||||||
status: active
|
status: finished
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
created: "2026-07-27"
|
created: "2026-07-27"
|
||||||
|
|
@ -138,7 +138,7 @@ errors, so future users may enter either `bernd.worsch` or the full email.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0023-T04
|
id: NK-WP-0023-T04
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "6ce33c92-031a-4f23-8ee2-108451b394fe"
|
state_hub_task_id: "6ce33c92-031a-4f23-8ee2-108451b394fe"
|
||||||
```
|
```
|
||||||
|
|
@ -224,7 +224,7 @@ value entered recorded output. All T05 acceptance criteria are complete.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0023-T06
|
id: NK-WP-0023-T06
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "96a7cd2b-6cab-47ab-a899-44bc0f6da58c"
|
state_hub_task_id: "96a7cd2b-6cab-47ab-a899-44bc0f6da58c"
|
||||||
```
|
```
|
||||||
|
|
@ -297,3 +297,17 @@ defines compatibility seams, not enterprise implementation.
|
||||||
federation, SCIM, JIT, group mapping, provenance, source ownership,
|
federation, SCIM, JIT, group mapping, provenance, source ownership,
|
||||||
conflict/freshness rules, offboarding, failure behavior, and demand triggers
|
conflict/freshness rules, offboarding, failure behavior, and demand triggers
|
||||||
without starting the demand-gated enterprise implementation.
|
without starting the demand-gated enterprise implementation.
|
||||||
|
|
||||||
|
## Milestone closure (2026-07-30)
|
||||||
|
|
||||||
|
The live Binky MVP consumes verified KeyCape claims, enforces tenant/platform
|
||||||
|
role separation through user-engine's authorization port, correlates durable
|
||||||
|
audit/outbox records, and keeps password and MFA interactions on
|
||||||
|
NetKingdom-owned surfaces. Role-scoped administration, platform and unrelated
|
||||||
|
tenant denial, AAL2 login, drift/reconciliation, replay-safe deletion, restore,
|
||||||
|
rollback, secret rotation, and dependency failure/recovery are proven.
|
||||||
|
|
||||||
|
Replacing the pre-production authorization adapter with a deployed flex-auth
|
||||||
|
policy package, invitation mail, operated outbox replay/dead-letter delivery,
|
||||||
|
and the broader integration failure matrix transfer explicitly to
|
||||||
|
`NK-WP-0024`; they are not claimed as part of this completed milestone.
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,71 @@
|
||||||
|
---
|
||||||
|
id: NK-WP-0024
|
||||||
|
type: workplan
|
||||||
|
title: "Expand user-engine platform integrations beyond the Binky MVP"
|
||||||
|
domain: infotech
|
||||||
|
repo: net-kingdom
|
||||||
|
status: backlog
|
||||||
|
owner: codex
|
||||||
|
topic_slug: netkingdom
|
||||||
|
created: "2026-07-30"
|
||||||
|
updated: "2026-07-30"
|
||||||
|
depends_on:
|
||||||
|
- NK-WP-0023
|
||||||
|
- USER-WP-0021
|
||||||
|
state_hub_workstream_id: "9bd05700-a839-4014-8f88-8a78f2757721"
|
||||||
|
---
|
||||||
|
|
||||||
|
# NK-WP-0024 - Portal integration expansion
|
||||||
|
|
||||||
|
Track deferred integration breadth separately from the completed live MVP.
|
||||||
|
Activate with the corresponding user-engine product-expansion tasks.
|
||||||
|
|
||||||
|
## T01 - Establish flex-auth production authorization
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0024-T01
|
||||||
|
status: todo
|
||||||
|
priority: high
|
||||||
|
state_hub_task_id: "7dff0ac6-c5eb-486c-83db-a1400f30f77d"
|
||||||
|
```
|
||||||
|
|
||||||
|
Define self, tenant-admin, and platform-admin resource/action vocabulary,
|
||||||
|
deploy the policy package, replace user-engine's local runtime adapter with a
|
||||||
|
fail-closed flex-auth HTTP adapter, and correlate decision IDs with audit.
|
||||||
|
|
||||||
|
## T02 - Add invitation and verification mail delivery
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0024-T02
|
||||||
|
status: todo
|
||||||
|
priority: medium
|
||||||
|
state_hub_task_id: "9d5f272b-115c-404d-8387-7f987cee65ea"
|
||||||
|
```
|
||||||
|
|
||||||
|
Deliver invitation and verification messages through approved custody and
|
||||||
|
mail lanes. Mailbox ownership remains evidence, never authorization.
|
||||||
|
|
||||||
|
## T03 - Operate durable event delivery
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0024-T03
|
||||||
|
status: todo
|
||||||
|
priority: high
|
||||||
|
state_hub_task_id: "17d6390b-05a8-436c-879b-4e0331d85be5"
|
||||||
|
```
|
||||||
|
|
||||||
|
Connect the user-engine transactional outbox to the platform event lane with
|
||||||
|
bounded retries, replay, dead-letter visibility, redaction, and correlation.
|
||||||
|
|
||||||
|
## T04 - Run expanded integration failure matrix
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: NK-WP-0024-T04
|
||||||
|
status: todo
|
||||||
|
priority: high
|
||||||
|
state_hub_task_id: "4c54e8e4-19d9-4470-bb43-3d43cf27af71"
|
||||||
|
```
|
||||||
|
|
||||||
|
Prove flex-auth denial/unavailability, mail failure, identity-provider outage,
|
||||||
|
partial provisioning recovery, invitation replay/expiry, and cross-tenant
|
||||||
|
negative behavior through the deployed path.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue