Reconcile infrastructure workplans and retire stale flex-auth references

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:03 +02:00
parent 019e8f21a7
commit 9383b94019
12 changed files with 494 additions and 149 deletions

View file

@ -0,0 +1,31 @@
# Tenant Engine integration references
`runtime.yaml` is **REFERENCE ONLY — DO NOT APPLY**. Its five remaining
Tenant Engine objects are historical and differ from the live deployment in
image, storage, strategy, environment and egress. Their disposition awaits the
Tenant Engine owner under
[NK-WP-0039-T04](../../../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md).
The obsolete flex-auth objects were removed on 2026-09-28 with the owner's
agreement. Use the owner's maintained declarations and deployment procedure:
| Consumer | Authoritative values in the flex-auth repository |
| --- | --- |
| Tenant Engine | [values/tenant-engine.yaml](../../../../flex-auth/values/tenant-engine.yaml) |
| User Engine | [values/user-engine.yaml](../../../../flex-auth/values/user-engine.yaml) |
The [owner Helm chart](../../../../flex-auth/charts/flex-auth) renders the
consumer Deployment, Service and NetworkPolicy, including caller-auth
configuration. Both reviewed value files select enforcement and bind the
consumer to its own Kubernetes ServiceAccount. Keep those settings at their
owner; do not recreate a frozen deployment copy here.
These links assume sibling checkouts. The current repository coordinate is
`coulomb/flex-auth`; its proposed rename to `coulomb/access-engine` remains
gated by FLEX-WP-0020. NK-WP-0039-T03 will update these repository pointers
when the owner confirms the new coordinate. The `flex-auth` namespace,
Service DNS, caller-token audience and OCI package coordinate remain unchanged.
Ownership follows [ADR-0015](../../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md).
Removing references requires no cluster apply or rollout. Do not use the
remaining YAML as a way to provision the two flex-auth consumers.