Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
parent
019e8f21a7
commit
9383b94019
12 changed files with 494 additions and 149 deletions
31
sso-mfa/k8s/tenant-engine/README.md
Normal file
31
sso-mfa/k8s/tenant-engine/README.md
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
# Tenant Engine integration references
|
||||
|
||||
`runtime.yaml` is **REFERENCE ONLY — DO NOT APPLY**. Its five remaining
|
||||
Tenant Engine objects are historical and differ from the live deployment in
|
||||
image, storage, strategy, environment and egress. Their disposition awaits the
|
||||
Tenant Engine owner under
|
||||
[NK-WP-0039-T04](../../../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md).
|
||||
|
||||
The obsolete flex-auth objects were removed on 2026-09-28 with the owner's
|
||||
agreement. Use the owner's maintained declarations and deployment procedure:
|
||||
|
||||
| Consumer | Authoritative values in the flex-auth repository |
|
||||
| --- | --- |
|
||||
| Tenant Engine | [values/tenant-engine.yaml](../../../../flex-auth/values/tenant-engine.yaml) |
|
||||
| User Engine | [values/user-engine.yaml](../../../../flex-auth/values/user-engine.yaml) |
|
||||
|
||||
The [owner Helm chart](../../../../flex-auth/charts/flex-auth) renders the
|
||||
consumer Deployment, Service and NetworkPolicy, including caller-auth
|
||||
configuration. Both reviewed value files select enforcement and bind the
|
||||
consumer to its own Kubernetes ServiceAccount. Keep those settings at their
|
||||
owner; do not recreate a frozen deployment copy here.
|
||||
|
||||
These links assume sibling checkouts. The current repository coordinate is
|
||||
`coulomb/flex-auth`; its proposed rename to `coulomb/access-engine` remains
|
||||
gated by FLEX-WP-0020. NK-WP-0039-T03 will update these repository pointers
|
||||
when the owner confirms the new coordinate. The `flex-auth` namespace,
|
||||
Service DNS, caller-token audience and OCI package coordinate remain unchanged.
|
||||
|
||||
Ownership follows [ADR-0015](../../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md).
|
||||
Removing references requires no cluster apply or rollout. Do not use the
|
||||
remaining YAML as a way to provision the two flex-auth consumers.
|
||||
|
|
@ -1,68 +1,16 @@
|
|||
# REFERENCE ONLY - DO NOT APPLY. Not the runtime source of truth (ADR-0015).
|
||||
# flex-auth-* Deployments are owned by flex-auth (values/<consumer>.yaml) and
|
||||
# tenant-engine by its own repository. Live differs from this file beyond the
|
||||
# flex-auth image digests (caller-auth enforce args, tenant-engine image, PVC,
|
||||
# strategy, egress). Applying it would drop caller-auth enforcement. NK-WP-0039.
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata: {name: flex-auth, labels: {net-kingdom/component: flex-auth}}
|
||||
---
|
||||
# Only historical tenant-engine objects remain, pending its owner's disposition.
|
||||
# Live tenant-engine differs in image, storage, strategy, environment and egress.
|
||||
# The obsolete flex-auth objects were removed under NK-WP-0039-T04.
|
||||
# Authoritative flex-auth declarations (repository: coulomb/flex-auth):
|
||||
# values/tenant-engine.yaml
|
||||
# values/user-engine.yaml
|
||||
# Rendered by that repository's charts/flex-auth, including caller enforcement.
|
||||
# See README.md for owner links, retained runtime names and the remaining gate.
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata: {name: tenant-engine, labels: {net-kingdom/component: tenant-engine}}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
|
||||
spec:
|
||||
replicas: 1
|
||||
selector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
||||
template:
|
||||
metadata: {labels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
securityContext: {runAsNonRoot: true, seccompProfile: {type: RuntimeDefault}}
|
||||
containers:
|
||||
- name: flex-auth
|
||||
image: forgejo.coulomb.social/coulomb/flex-auth@sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd
|
||||
args: ["serve", "--addr", "0.0.0.0:8080", "--registry", "/opt/flex-auth/examples/tenant-engine/registry_snapshot.json", "--policy", "/opt/flex-auth/examples/tenant-engine/policy_package.md"]
|
||||
ports: [{name: http, containerPort: 8080}]
|
||||
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
|
||||
resources: {requests: {cpu: 25m, memory: 32Mi}, limits: {cpu: 300m, memory: 192Mi}}
|
||||
readinessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 5}
|
||||
livenessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 20}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
|
||||
spec: {selector: {app.kubernetes.io/name: flex-auth-tenant-engine}, ports: [{name: http, port: 8080, targetPort: http}]}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
|
||||
spec:
|
||||
replicas: 1
|
||||
selector: {matchLabels: {app.kubernetes.io/name: flex-auth-user-engine}}
|
||||
template:
|
||||
metadata: {labels: {app.kubernetes.io/name: flex-auth-user-engine}}
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
securityContext: {runAsNonRoot: true, seccompProfile: {type: RuntimeDefault}}
|
||||
containers:
|
||||
- name: flex-auth
|
||||
image: forgejo.coulomb.social/coulomb/flex-auth@sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b
|
||||
args: ["serve", "--addr", "0.0.0.0:8080", "--registry", "/opt/flex-auth/examples/user-engine/registry_snapshot.json", "--policy", "/opt/flex-auth/examples/user-engine/policy_package.md"]
|
||||
ports: [{name: http, containerPort: 8080}]
|
||||
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
|
||||
resources: {requests: {cpu: 25m, memory: 32Mi}, limits: {cpu: 300m, memory: 192Mi}}
|
||||
readinessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 5}
|
||||
livenessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 20}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
|
||||
spec: {selector: {app.kubernetes.io/name: flex-auth-user-engine}, ports: [{name: http, port: 8080, targetPort: http}]}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata: {name: tenant-engine-data, namespace: tenant-engine}
|
||||
|
|
@ -101,32 +49,6 @@ spec: {selector: {app.kubernetes.io/name: tenant-engine}, ports: [{name: http, p
|
|||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
|
||||
spec:
|
||||
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
||||
policyTypes: [Ingress, Egress]
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: tenant-engine}}
|
||||
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
||||
ports: [{protocol: TCP, port: 8080}]
|
||||
egress: []
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
|
||||
spec:
|
||||
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-user-engine}}
|
||||
policyTypes: [Ingress, Egress]
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: user-engine}}
|
||||
podSelector: {matchLabels: {app.kubernetes.io/name: user-engine}}
|
||||
ports: [{protocol: TCP, port: 8080}]
|
||||
egress: []
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata: {name: tenant-engine, namespace: tenant-engine}
|
||||
spec:
|
||||
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue