Reconcile infrastructure workplans and retire stale flex-auth references

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:03 +02:00
parent 019e8f21a7
commit 9383b94019
12 changed files with 494 additions and 149 deletions

View file

@ -9,7 +9,7 @@ flavor: planning
owner: claude-code
topic_slug: netkingdom
created: "2026-09-23"
updated: "2026-09-24"
updated: "2026-09-28"
related: [NK-ADR-0016, NK-WP-0037]
state_hub_workstream_id: "3f702215-704b-5788-8ca0-b8b9ba2dd3f8"
---
@ -72,3 +72,23 @@ on.
asking for a proposed pilot workload and U06 touchpoints. This is a
UX/product agreement across two repos and a pilot workload owner; NetKingdom
cannot decide it unilaterally.
## Infrastructure review — 2026-09-28
Build T02 on the already completed USER-WP-0033 and KEY-WP-0035 P06 work.
Their September 14 release evidence records optional-after-enrollment policy
for `user-engine-portal` and `vergabe-demo-company`, privileged MFA guards,
confirmed enrollment/cancellation and old-session checks. Do not rebuild
those capabilities or interpret this plan as the first delivery of MFA policy.
The residual is workload-level interoperability and an accepted pilot journey:
agree the pilot owner, reuse U06 recovery, prove no-factor enrollment and
return to the protected action, and test stale AAL1, refusal and provider
unavailability. Existing scoped policy does not prove arbitrary-client
`acr_values` support or acceptance of IAM v0.4. KeyCape owns issuer enforcement;
user-engine owns the journey; the workload and flex-auth enforce the issued
assurance at the protected action. T02 remains `wait` for that agreement and
actual-user acceptance, coordinated with KEY-WP-0034 / USER-WP-0028 /
VERGABE-WP-0019, without reopening their completed provider work.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).