Reconcile infrastructure workplans and retire stale flex-auth references

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:03 +02:00
parent 019e8f21a7
commit 9383b94019
12 changed files with 494 additions and 149 deletions

View file

@ -0,0 +1,179 @@
# Open workplans versus infrastructure — 2026-09-28
Reviewed all ten nonterminal root workplans (eight blocked, two backlog).
Initial review result: one finished, one active, six blocked, two backlog.
The follow-through section below records subsequent implementation and statuses.
Existing task IDs
and State Hub UUIDs are preserved. This is a planning reconciliation; no
runtime, credential, policy, DNS or destructive change was performed.
## Evidence boundary
Read-only `kubectl` checks against context `default` found one Ready node at
92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP,
privacyIDEA, user-engine, tenant-engine and audit-core each had one ready
Deployment replica. All six flex-auth consumer Deployments were ready and
contained `--caller-auth-mode enforce`. This is configuration/readiness
proof, not fresh user login, negative authorization or recovery testing.
All eight CNPG clusters reported one instance and one ready instance:
apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db,
target-revenue-pg and user-engine-pg. A healthy single-node cluster does not
prove HA or off-host recovery. No Keycloak Deployment was present.
OpenBao StatefulSet and UI gateway were ready; gateway/API Services were
ClusterIP and the namespace had no Ingress. CoulombCore, retained backup
contents, public DNS withdrawal and browser sessions were not reverified.
Owner receipts below support historical completion, not a fresh execution.
Sibling repositories were inspected as available local checkouts; their state
was not assumed to be a newly fetched remote head.
The State Hub inbox supplied flex-auth's September 27 approval of its reference
cleanup (`77b26d1e-550b-4926-9610-44fc3a566273`); it was marked read. The
human-needed task query returned no NK-/NET-prefixed records. This does not
remove the explicit approval gate written in NK-WP-0022. Topic-wide active
workplans include other repositories and are not the NetKingdom plan inventory.
## Plan dispositions at the initial review
| Plan | Updated state and next acceptance gate |
| --- | --- |
| [0009 tutorials](../workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md) | Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service. |
| [0011 federation](../workplans/NK-WP-0011-enterprise-federation-saml.md) | Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation. |
| [0022 retirement](../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md) | Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval. |
| [0027 reef/posture](../workplans/NK-WP-0027-reef-placement-reconciliation.md) | Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved. |
| [0031 freshness](../workplans/NK-WP-0031-deterministic-posture-feedback.md) | Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence. |
| [0032 Bao callback](../workplans/NK-WP-0032-openbao-operator-loopback-callback.md) | Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical. |
| [0035 cadence](../workplans/NK-WP-0035-emission-cadence-security-profile.md) | Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility. |
| [0039 rename/reference](../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md) | Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates. |
| [0040 execution receipt](../workplans/NK-WP-0040-execution-attribution-receipt.md) | Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds. |
| [0042 step-up](../workplans/NK-WP-0042-workload-mfa-step-up.md) | Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey. |
The two oldest plans now have one task per second-level section, conforming to
the file-backed workplan format. Completed implementation tasks were not
reopened merely because their historical validation dates are old.
## Necessary changes and conflicts
1. **Stale deployment copies can remove a live security control.**
`sso-mfa/k8s/tenant-engine/runtime.yaml` lacks live caller enforcement and
other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to its
`values/<consumer>.yaml`; tenant-engine's portion remains separately owned.
Repository rename does not rename the runtime, token audience or OCI package.
Source: [FLEX-WP-0020](../../flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md)
(locate by workplan ID if the owner filename changes), inbox receipt above.
2. **Recovery claims must follow the actual failure domain.** Reef declarations
still omit provider ceilings; one node and single-instance databases cannot
establish independent failover. Proposed V0/V1 carrier semantics require
owner agreement and workload evidence. A platform database drill does not
satisfy full identity restoration for destructive retirement.
Sources: [reef declaration](../../reef-railiance/declarations/reef.yaml),
[provider proposal](../docs/reef-posture-provider-contract.md).
3. **Declared evidence remains behind runtime improvements.** Audit Core's
tenancy file still describes flex-auth as unauthenticated A0, despite the
observed enforcement flags. Its E2 review metadata is unstructured and old.
Have the owner reconcile this; do not infer A/E upgrades from flags or tests.
Source: [audit tenancy](../../audit-core/tenancy.yaml).
4. **Generic cadence validity is not profile compliance or observation.**
Approval Engine and Qonto still fail the owner schema. Local-identity passes
that schema but fails the rare-class heartbeat obligation when its source
inventory is explicitly supplied. Audit Core holds no local-identity feed.
Upstream corrected its candidate bundle digest; profile and declaration
metadata need reconciliation without changing historical findings.
Sources: [local findings](../local-identity/emission-cadence-findings.md),
[upstream review](../../info-tech-canon/feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md).
5. **Existing MFA work and proposed generic step-up are different scopes.**
P06 already delivered optional policies for two clients, enrollment checks
and privileged guards. IAM v0.4 remains proposed; it is not evidence of
arbitrary workload step-up support. Reuse the implementation and close the
pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and
[P06 evidence](../../user-engine/docs/evidence/2026-09-13-p06-authentication-policy.md).
6. **Public Bao is retired.** September 24 removed public role callbacks;
current client source rejects their return. Do not repeat completed login
admission or preserve public URLs as a future default. DNS withdrawal is a
railiance-infra residual. Sources:
[callback receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json),
[login/retraction receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-public-listener-retract.json),
[callback pruning](../../railiance-platform/docs/evidence/2026-09-24-platform-admin-callback-prune.json),
[platform closure](../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md).
7. **Accepted canon and proposals must stay distinct.** IAM v0.3, Playbook
Capability v0.1 and security layer v0.7 remain the accepted baselines;
proposed amendments do not authorize runtime implementation or replace
owner agreement. New federation work must follow ADR-0015 packaging and
current tenant identity contracts, not the original greenfield assumptions.
## Most valuable future implementation
Recommended order; this is prioritization, not approval of deployment or deletion.
1. **Remove stale reference authority (0039).** Small, locally actionable work
that prevents a caller-auth regression. Replace the approved flex-auth
objects with exact owner pointers; finish tenant-engine's portion after its
answer. No rollout is needed.
2. **Close one real workload MFA journey (0042).** High user value with existing
provider work available. Pick a pilot with its owner, demonstrate enrollment,
return to action, recovery and denial with stale/insufficient assurance.
Coordinate existing actual-user gates rather than create another onboarding
implementation.
3. **Make evidence freshness and emission operational (0031 + 0035).** Add
authoritative metadata first, then migrate a source already sending to
Audit Core and prove heartbeat/reconciliation through its observer. This
makes missing or stale security evidence detectable. Resolve local-identity
activity-scope incompatibility explicitly; do not force a bootstrap tool
into a permanent service just to pass the profile.
4. **Bind a real execution to evidence (0040).** Agree the receipt and implement
one Railiance emitter/receiver integration with actor, artifact, decision,
approval and bounded time. This unblocks clock attribution and gives more
value than a schema-only finish.
5. **Mechanize recovery ceilings and finish retirement safely (0027 + 0022).**
Agree reef provider declarations, implement the three-valued join, and use
measured recovery evidence. Prepare the exact old identity deletion package
only after its recovery gate passes; approval remains a separate final step.
Tutorials should capture these proven paths incrementally. Enterprise
federation is lower priority until a concrete tenant/IdP demand justifies its
additional issuer, trust mapping, database and recovery burden.
## Validation
- Current read-only node, Deployment, CNPG and OpenBao resource inventories.
- Existing cadence checker against the current owner schema: Approval Engine
fails with three generic findings; Qonto fails with five. Local-identity is
generic-valid; supplying both documented load-bearing/rare classes yields
two `rare-heartbeat-missing` failures. Omitting inventory flags checks no
rare-class obligations and must not be used to claim adoption.
- Existing posture evaluator at explicit `2026-09-28T12:00:00Z` confirms
unknown owner/freshness and overdue review for audit-core. This is a chosen
reproducible evaluation instant, not the observation timestamp.
- Workplan frontmatter, task-ID preservation, task statuses and local Markdown
links checked; authored files pass `git diff --check`. The generated brief
retains its generator's Markdown hard-break whitespace. No application code changed.
State Hub lifecycle reconciliation classifies partially completed 0039 with an
actionable task as `active`; its file follows that convention. Existing
NK-WP/NET-WP prefix warnings are retained rather than renumbering historical
work records. At the initial review, repository instructions contained conflicting prefix
conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while
preserving historical IDs.
## Follow-through — 2026-09-28
After the user requested implementation, the approved part of NK-WP-0039-T04
was completed: seven obsolete flex-auth objects were removed from the combined
reference manifest and replaced with owner links in
[sso-mfa/k8s/tenant-engine/README.md](../sso-mfa/k8s/tenant-engine/README.md).
Parsed before/after YAML confirms all five tenant-engine objects are unchanged.
No repository apply path consumes the combined manifest; the user-engine
verifier uses its own file. Owner values enforce caller authentication and
bind each consumer to its own ServiceAccount. The remaining YAML stays
DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still
waits for the rename. This returns 0039 to blocked: the current disposition
of the original ten is one finished, seven blocked and two backlog.
The locally owned portion of NK-WP-0035-T04 also advanced: corrected the
profile's imported document maturity/version/revision and the local-identity
candidate bundle pin. The old pin and its correction remain in historical
findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass;
explicit rare-class revalidation remains generic-valid with exactly two
missing-heartbeat failures. The profile stays proposed and source/observer
adoption remains open. No runtime or external-owner source was changed.