Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
parent
019e8f21a7
commit
9383b94019
12 changed files with 494 additions and 149 deletions
179
history/2026-09-28-open-workplan-infrastructure-review.md
Normal file
179
history/2026-09-28-open-workplan-infrastructure-review.md
Normal file
|
|
@ -0,0 +1,179 @@
|
||||||
|
# Open workplans versus infrastructure — 2026-09-28
|
||||||
|
|
||||||
|
Reviewed all ten nonterminal root workplans (eight blocked, two backlog).
|
||||||
|
Initial review result: one finished, one active, six blocked, two backlog.
|
||||||
|
The follow-through section below records subsequent implementation and statuses.
|
||||||
|
Existing task IDs
|
||||||
|
and State Hub UUIDs are preserved. This is a planning reconciliation; no
|
||||||
|
runtime, credential, policy, DNS or destructive change was performed.
|
||||||
|
|
||||||
|
## Evidence boundary
|
||||||
|
|
||||||
|
Read-only `kubectl` checks against context `default` found one Ready node at
|
||||||
|
92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP,
|
||||||
|
privacyIDEA, user-engine, tenant-engine and audit-core each had one ready
|
||||||
|
Deployment replica. All six flex-auth consumer Deployments were ready and
|
||||||
|
contained `--caller-auth-mode enforce`. This is configuration/readiness
|
||||||
|
proof, not fresh user login, negative authorization or recovery testing.
|
||||||
|
|
||||||
|
All eight CNPG clusters reported one instance and one ready instance:
|
||||||
|
apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db,
|
||||||
|
target-revenue-pg and user-engine-pg. A healthy single-node cluster does not
|
||||||
|
prove HA or off-host recovery. No Keycloak Deployment was present.
|
||||||
|
|
||||||
|
OpenBao StatefulSet and UI gateway were ready; gateway/API Services were
|
||||||
|
ClusterIP and the namespace had no Ingress. CoulombCore, retained backup
|
||||||
|
contents, public DNS withdrawal and browser sessions were not reverified.
|
||||||
|
Owner receipts below support historical completion, not a fresh execution.
|
||||||
|
Sibling repositories were inspected as available local checkouts; their state
|
||||||
|
was not assumed to be a newly fetched remote head.
|
||||||
|
|
||||||
|
The State Hub inbox supplied flex-auth's September 27 approval of its reference
|
||||||
|
cleanup (`77b26d1e-550b-4926-9610-44fc3a566273`); it was marked read. The
|
||||||
|
human-needed task query returned no NK-/NET-prefixed records. This does not
|
||||||
|
remove the explicit approval gate written in NK-WP-0022. Topic-wide active
|
||||||
|
workplans include other repositories and are not the NetKingdom plan inventory.
|
||||||
|
|
||||||
|
## Plan dispositions at the initial review
|
||||||
|
|
||||||
|
| Plan | Updated state and next acceptance gate |
|
||||||
|
| --- | --- |
|
||||||
|
| [0009 tutorials](../workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md) | Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service. |
|
||||||
|
| [0011 federation](../workplans/NK-WP-0011-enterprise-federation-saml.md) | Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation. |
|
||||||
|
| [0022 retirement](../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md) | Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval. |
|
||||||
|
| [0027 reef/posture](../workplans/NK-WP-0027-reef-placement-reconciliation.md) | Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved. |
|
||||||
|
| [0031 freshness](../workplans/NK-WP-0031-deterministic-posture-feedback.md) | Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence. |
|
||||||
|
| [0032 Bao callback](../workplans/NK-WP-0032-openbao-operator-loopback-callback.md) | Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical. |
|
||||||
|
| [0035 cadence](../workplans/NK-WP-0035-emission-cadence-security-profile.md) | Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility. |
|
||||||
|
| [0039 rename/reference](../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md) | Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates. |
|
||||||
|
| [0040 execution receipt](../workplans/NK-WP-0040-execution-attribution-receipt.md) | Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds. |
|
||||||
|
| [0042 step-up](../workplans/NK-WP-0042-workload-mfa-step-up.md) | Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey. |
|
||||||
|
|
||||||
|
The two oldest plans now have one task per second-level section, conforming to
|
||||||
|
the file-backed workplan format. Completed implementation tasks were not
|
||||||
|
reopened merely because their historical validation dates are old.
|
||||||
|
|
||||||
|
## Necessary changes and conflicts
|
||||||
|
|
||||||
|
1. **Stale deployment copies can remove a live security control.**
|
||||||
|
`sso-mfa/k8s/tenant-engine/runtime.yaml` lacks live caller enforcement and
|
||||||
|
other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to its
|
||||||
|
`values/<consumer>.yaml`; tenant-engine's portion remains separately owned.
|
||||||
|
Repository rename does not rename the runtime, token audience or OCI package.
|
||||||
|
Source: [FLEX-WP-0020](../../flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md)
|
||||||
|
(locate by workplan ID if the owner filename changes), inbox receipt above.
|
||||||
|
2. **Recovery claims must follow the actual failure domain.** Reef declarations
|
||||||
|
still omit provider ceilings; one node and single-instance databases cannot
|
||||||
|
establish independent failover. Proposed V0/V1 carrier semantics require
|
||||||
|
owner agreement and workload evidence. A platform database drill does not
|
||||||
|
satisfy full identity restoration for destructive retirement.
|
||||||
|
Sources: [reef declaration](../../reef-railiance/declarations/reef.yaml),
|
||||||
|
[provider proposal](../docs/reef-posture-provider-contract.md).
|
||||||
|
3. **Declared evidence remains behind runtime improvements.** Audit Core's
|
||||||
|
tenancy file still describes flex-auth as unauthenticated A0, despite the
|
||||||
|
observed enforcement flags. Its E2 review metadata is unstructured and old.
|
||||||
|
Have the owner reconcile this; do not infer A/E upgrades from flags or tests.
|
||||||
|
Source: [audit tenancy](../../audit-core/tenancy.yaml).
|
||||||
|
4. **Generic cadence validity is not profile compliance or observation.**
|
||||||
|
Approval Engine and Qonto still fail the owner schema. Local-identity passes
|
||||||
|
that schema but fails the rare-class heartbeat obligation when its source
|
||||||
|
inventory is explicitly supplied. Audit Core holds no local-identity feed.
|
||||||
|
Upstream corrected its candidate bundle digest; profile and declaration
|
||||||
|
metadata need reconciliation without changing historical findings.
|
||||||
|
Sources: [local findings](../local-identity/emission-cadence-findings.md),
|
||||||
|
[upstream review](../../info-tech-canon/feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md).
|
||||||
|
5. **Existing MFA work and proposed generic step-up are different scopes.**
|
||||||
|
P06 already delivered optional policies for two clients, enrollment checks
|
||||||
|
and privileged guards. IAM v0.4 remains proposed; it is not evidence of
|
||||||
|
arbitrary workload step-up support. Reuse the implementation and close the
|
||||||
|
pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and
|
||||||
|
[P06 evidence](../../user-engine/docs/evidence/2026-09-13-p06-authentication-policy.md).
|
||||||
|
6. **Public Bao is retired.** September 24 removed public role callbacks;
|
||||||
|
current client source rejects their return. Do not repeat completed login
|
||||||
|
admission or preserve public URLs as a future default. DNS withdrawal is a
|
||||||
|
railiance-infra residual. Sources:
|
||||||
|
[callback receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json),
|
||||||
|
[login/retraction receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-public-listener-retract.json),
|
||||||
|
[callback pruning](../../railiance-platform/docs/evidence/2026-09-24-platform-admin-callback-prune.json),
|
||||||
|
[platform closure](../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md).
|
||||||
|
7. **Accepted canon and proposals must stay distinct.** IAM v0.3, Playbook
|
||||||
|
Capability v0.1 and security layer v0.7 remain the accepted baselines;
|
||||||
|
proposed amendments do not authorize runtime implementation or replace
|
||||||
|
owner agreement. New federation work must follow ADR-0015 packaging and
|
||||||
|
current tenant identity contracts, not the original greenfield assumptions.
|
||||||
|
|
||||||
|
## Most valuable future implementation
|
||||||
|
|
||||||
|
Recommended order; this is prioritization, not approval of deployment or deletion.
|
||||||
|
|
||||||
|
1. **Remove stale reference authority (0039).** Small, locally actionable work
|
||||||
|
that prevents a caller-auth regression. Replace the approved flex-auth
|
||||||
|
objects with exact owner pointers; finish tenant-engine's portion after its
|
||||||
|
answer. No rollout is needed.
|
||||||
|
2. **Close one real workload MFA journey (0042).** High user value with existing
|
||||||
|
provider work available. Pick a pilot with its owner, demonstrate enrollment,
|
||||||
|
return to action, recovery and denial with stale/insufficient assurance.
|
||||||
|
Coordinate existing actual-user gates rather than create another onboarding
|
||||||
|
implementation.
|
||||||
|
3. **Make evidence freshness and emission operational (0031 + 0035).** Add
|
||||||
|
authoritative metadata first, then migrate a source already sending to
|
||||||
|
Audit Core and prove heartbeat/reconciliation through its observer. This
|
||||||
|
makes missing or stale security evidence detectable. Resolve local-identity
|
||||||
|
activity-scope incompatibility explicitly; do not force a bootstrap tool
|
||||||
|
into a permanent service just to pass the profile.
|
||||||
|
4. **Bind a real execution to evidence (0040).** Agree the receipt and implement
|
||||||
|
one Railiance emitter/receiver integration with actor, artifact, decision,
|
||||||
|
approval and bounded time. This unblocks clock attribution and gives more
|
||||||
|
value than a schema-only finish.
|
||||||
|
5. **Mechanize recovery ceilings and finish retirement safely (0027 + 0022).**
|
||||||
|
Agree reef provider declarations, implement the three-valued join, and use
|
||||||
|
measured recovery evidence. Prepare the exact old identity deletion package
|
||||||
|
only after its recovery gate passes; approval remains a separate final step.
|
||||||
|
|
||||||
|
Tutorials should capture these proven paths incrementally. Enterprise
|
||||||
|
federation is lower priority until a concrete tenant/IdP demand justifies its
|
||||||
|
additional issuer, trust mapping, database and recovery burden.
|
||||||
|
|
||||||
|
## Validation
|
||||||
|
|
||||||
|
- Current read-only node, Deployment, CNPG and OpenBao resource inventories.
|
||||||
|
- Existing cadence checker against the current owner schema: Approval Engine
|
||||||
|
fails with three generic findings; Qonto fails with five. Local-identity is
|
||||||
|
generic-valid; supplying both documented load-bearing/rare classes yields
|
||||||
|
two `rare-heartbeat-missing` failures. Omitting inventory flags checks no
|
||||||
|
rare-class obligations and must not be used to claim adoption.
|
||||||
|
- Existing posture evaluator at explicit `2026-09-28T12:00:00Z` confirms
|
||||||
|
unknown owner/freshness and overdue review for audit-core. This is a chosen
|
||||||
|
reproducible evaluation instant, not the observation timestamp.
|
||||||
|
- Workplan frontmatter, task-ID preservation, task statuses and local Markdown
|
||||||
|
links checked; authored files pass `git diff --check`. The generated brief
|
||||||
|
retains its generator's Markdown hard-break whitespace. No application code changed.
|
||||||
|
|
||||||
|
State Hub lifecycle reconciliation classifies partially completed 0039 with an
|
||||||
|
actionable task as `active`; its file follows that convention. Existing
|
||||||
|
NK-WP/NET-WP prefix warnings are retained rather than renumbering historical
|
||||||
|
work records. At the initial review, repository instructions contained conflicting prefix
|
||||||
|
conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while
|
||||||
|
preserving historical IDs.
|
||||||
|
|
||||||
|
## Follow-through — 2026-09-28
|
||||||
|
|
||||||
|
After the user requested implementation, the approved part of NK-WP-0039-T04
|
||||||
|
was completed: seven obsolete flex-auth objects were removed from the combined
|
||||||
|
reference manifest and replaced with owner links in
|
||||||
|
[sso-mfa/k8s/tenant-engine/README.md](../sso-mfa/k8s/tenant-engine/README.md).
|
||||||
|
Parsed before/after YAML confirms all five tenant-engine objects are unchanged.
|
||||||
|
No repository apply path consumes the combined manifest; the user-engine
|
||||||
|
verifier uses its own file. Owner values enforce caller authentication and
|
||||||
|
bind each consumer to its own ServiceAccount. The remaining YAML stays
|
||||||
|
DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still
|
||||||
|
waits for the rename. This returns 0039 to blocked: the current disposition
|
||||||
|
of the original ten is one finished, seven blocked and two backlog.
|
||||||
|
|
||||||
|
The locally owned portion of NK-WP-0035-T04 also advanced: corrected the
|
||||||
|
profile's imported document maturity/version/revision and the local-identity
|
||||||
|
candidate bundle pin. The old pin and its correction remain in historical
|
||||||
|
findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass;
|
||||||
|
explicit rare-class revalidation remains generic-valid with exactly two
|
||||||
|
missing-heartbeat failures. The profile stays proposed and source/observer
|
||||||
|
adoption remains open. No runtime or external-owner source was changed.
|
||||||
31
sso-mfa/k8s/tenant-engine/README.md
Normal file
31
sso-mfa/k8s/tenant-engine/README.md
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
# Tenant Engine integration references
|
||||||
|
|
||||||
|
`runtime.yaml` is **REFERENCE ONLY — DO NOT APPLY**. Its five remaining
|
||||||
|
Tenant Engine objects are historical and differ from the live deployment in
|
||||||
|
image, storage, strategy, environment and egress. Their disposition awaits the
|
||||||
|
Tenant Engine owner under
|
||||||
|
[NK-WP-0039-T04](../../../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md).
|
||||||
|
|
||||||
|
The obsolete flex-auth objects were removed on 2026-09-28 with the owner's
|
||||||
|
agreement. Use the owner's maintained declarations and deployment procedure:
|
||||||
|
|
||||||
|
| Consumer | Authoritative values in the flex-auth repository |
|
||||||
|
| --- | --- |
|
||||||
|
| Tenant Engine | [values/tenant-engine.yaml](../../../../flex-auth/values/tenant-engine.yaml) |
|
||||||
|
| User Engine | [values/user-engine.yaml](../../../../flex-auth/values/user-engine.yaml) |
|
||||||
|
|
||||||
|
The [owner Helm chart](../../../../flex-auth/charts/flex-auth) renders the
|
||||||
|
consumer Deployment, Service and NetworkPolicy, including caller-auth
|
||||||
|
configuration. Both reviewed value files select enforcement and bind the
|
||||||
|
consumer to its own Kubernetes ServiceAccount. Keep those settings at their
|
||||||
|
owner; do not recreate a frozen deployment copy here.
|
||||||
|
|
||||||
|
These links assume sibling checkouts. The current repository coordinate is
|
||||||
|
`coulomb/flex-auth`; its proposed rename to `coulomb/access-engine` remains
|
||||||
|
gated by FLEX-WP-0020. NK-WP-0039-T03 will update these repository pointers
|
||||||
|
when the owner confirms the new coordinate. The `flex-auth` namespace,
|
||||||
|
Service DNS, caller-token audience and OCI package coordinate remain unchanged.
|
||||||
|
|
||||||
|
Ownership follows [ADR-0015](../../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md).
|
||||||
|
Removing references requires no cluster apply or rollout. Do not use the
|
||||||
|
remaining YAML as a way to provision the two flex-auth consumers.
|
||||||
|
|
@ -1,68 +1,16 @@
|
||||||
# REFERENCE ONLY - DO NOT APPLY. Not the runtime source of truth (ADR-0015).
|
# REFERENCE ONLY - DO NOT APPLY. Not the runtime source of truth (ADR-0015).
|
||||||
# flex-auth-* Deployments are owned by flex-auth (values/<consumer>.yaml) and
|
# Only historical tenant-engine objects remain, pending its owner's disposition.
|
||||||
# tenant-engine by its own repository. Live differs from this file beyond the
|
# Live tenant-engine differs in image, storage, strategy, environment and egress.
|
||||||
# flex-auth image digests (caller-auth enforce args, tenant-engine image, PVC,
|
# The obsolete flex-auth objects were removed under NK-WP-0039-T04.
|
||||||
# strategy, egress). Applying it would drop caller-auth enforcement. NK-WP-0039.
|
# Authoritative flex-auth declarations (repository: coulomb/flex-auth):
|
||||||
apiVersion: v1
|
# values/tenant-engine.yaml
|
||||||
kind: Namespace
|
# values/user-engine.yaml
|
||||||
metadata: {name: flex-auth, labels: {net-kingdom/component: flex-auth}}
|
# Rendered by that repository's charts/flex-auth, including caller enforcement.
|
||||||
---
|
# See README.md for owner links, retained runtime names and the remaining gate.
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Namespace
|
kind: Namespace
|
||||||
metadata: {name: tenant-engine, labels: {net-kingdom/component: tenant-engine}}
|
metadata: {name: tenant-engine, labels: {net-kingdom/component: tenant-engine}}
|
||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
|
||||||
template:
|
|
||||||
metadata: {labels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
|
||||||
spec:
|
|
||||||
automountServiceAccountToken: false
|
|
||||||
securityContext: {runAsNonRoot: true, seccompProfile: {type: RuntimeDefault}}
|
|
||||||
containers:
|
|
||||||
- name: flex-auth
|
|
||||||
image: forgejo.coulomb.social/coulomb/flex-auth@sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd
|
|
||||||
args: ["serve", "--addr", "0.0.0.0:8080", "--registry", "/opt/flex-auth/examples/tenant-engine/registry_snapshot.json", "--policy", "/opt/flex-auth/examples/tenant-engine/policy_package.md"]
|
|
||||||
ports: [{name: http, containerPort: 8080}]
|
|
||||||
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
|
|
||||||
resources: {requests: {cpu: 25m, memory: 32Mi}, limits: {cpu: 300m, memory: 192Mi}}
|
|
||||||
readinessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 5}
|
|
||||||
livenessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 20}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
|
|
||||||
spec: {selector: {app.kubernetes.io/name: flex-auth-tenant-engine}, ports: [{name: http, port: 8080, targetPort: http}]}
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector: {matchLabels: {app.kubernetes.io/name: flex-auth-user-engine}}
|
|
||||||
template:
|
|
||||||
metadata: {labels: {app.kubernetes.io/name: flex-auth-user-engine}}
|
|
||||||
spec:
|
|
||||||
automountServiceAccountToken: false
|
|
||||||
securityContext: {runAsNonRoot: true, seccompProfile: {type: RuntimeDefault}}
|
|
||||||
containers:
|
|
||||||
- name: flex-auth
|
|
||||||
image: forgejo.coulomb.social/coulomb/flex-auth@sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b
|
|
||||||
args: ["serve", "--addr", "0.0.0.0:8080", "--registry", "/opt/flex-auth/examples/user-engine/registry_snapshot.json", "--policy", "/opt/flex-auth/examples/user-engine/policy_package.md"]
|
|
||||||
ports: [{name: http, containerPort: 8080}]
|
|
||||||
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
|
|
||||||
resources: {requests: {cpu: 25m, memory: 32Mi}, limits: {cpu: 300m, memory: 192Mi}}
|
|
||||||
readinessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 5}
|
|
||||||
livenessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 20}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
|
|
||||||
spec: {selector: {app.kubernetes.io/name: flex-auth-user-engine}, ports: [{name: http, port: 8080, targetPort: http}]}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: PersistentVolumeClaim
|
kind: PersistentVolumeClaim
|
||||||
metadata: {name: tenant-engine-data, namespace: tenant-engine}
|
metadata: {name: tenant-engine-data, namespace: tenant-engine}
|
||||||
|
|
@ -101,32 +49,6 @@ spec: {selector: {app.kubernetes.io/name: tenant-engine}, ports: [{name: http, p
|
||||||
---
|
---
|
||||||
apiVersion: networking.k8s.io/v1
|
apiVersion: networking.k8s.io/v1
|
||||||
kind: NetworkPolicy
|
kind: NetworkPolicy
|
||||||
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
|
|
||||||
spec:
|
|
||||||
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
|
||||||
policyTypes: [Ingress, Egress]
|
|
||||||
ingress:
|
|
||||||
- from:
|
|
||||||
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: tenant-engine}}
|
|
||||||
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
|
||||||
ports: [{protocol: TCP, port: 8080}]
|
|
||||||
egress: []
|
|
||||||
---
|
|
||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: NetworkPolicy
|
|
||||||
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
|
|
||||||
spec:
|
|
||||||
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-user-engine}}
|
|
||||||
policyTypes: [Ingress, Egress]
|
|
||||||
ingress:
|
|
||||||
- from:
|
|
||||||
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: user-engine}}
|
|
||||||
podSelector: {matchLabels: {app.kubernetes.io/name: user-engine}}
|
|
||||||
ports: [{protocol: TCP, port: 8080}]
|
|
||||||
egress: []
|
|
||||||
---
|
|
||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: NetworkPolicy
|
|
||||||
metadata: {name: tenant-engine, namespace: tenant-engine}
|
metadata: {name: tenant-engine, namespace: tenant-engine}
|
||||||
spec:
|
spec:
|
||||||
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
||||||
|
|
|
||||||
|
|
@ -11,7 +11,7 @@ topic_slug: netkingdom
|
||||||
planning_priority: medium
|
planning_priority: medium
|
||||||
planning_order: 9
|
planning_order: 9
|
||||||
created: 2026-05-17
|
created: 2026-05-17
|
||||||
updated: 2026-07-08
|
updated: "2026-09-28"
|
||||||
depends_on:
|
depends_on:
|
||||||
- NK-WP-0008
|
- NK-WP-0008
|
||||||
state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e"
|
state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e"
|
||||||
|
|
@ -64,7 +64,7 @@ Out of scope:
|
||||||
- hiding provider-specific security differences behind one generic
|
- hiding provider-specific security differences behind one generic
|
||||||
command
|
command
|
||||||
|
|
||||||
## Tasks
|
## Create the tutorial template
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0009-T01
|
id: NK-WP-0009-T01
|
||||||
|
|
@ -77,6 +77,8 @@ Create a tutorial template with prerequisites, architecture context,
|
||||||
commands, manifests, verification, rollback, threat checks, and
|
commands, manifests, verification, rollback, threat checks, and
|
||||||
cross-repo ownership notes.
|
cross-repo ownership notes.
|
||||||
|
|
||||||
|
## Demonstrate temporary object credentials
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0009-T02
|
id: NK-WP-0009-T02
|
||||||
status: todo
|
status: todo
|
||||||
|
|
@ -89,6 +91,8 @@ NetKingdom identity token", covering key-cape/Keycloak identity,
|
||||||
flex-auth authorization, object-store STS exchange, and SDK consumer
|
flex-auth authorization, object-store STS exchange, and SDK consumer
|
||||||
configuration.
|
configuration.
|
||||||
|
|
||||||
|
## Document the existing OpenBao operating path
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0009-T03
|
id: NK-WP-0009-T03
|
||||||
status: todo
|
status: todo
|
||||||
|
|
@ -101,6 +105,8 @@ NetKingdom-enabled Railiance platform", linking to the Railiance
|
||||||
Platform workplan and covering auth methods, secret engines, CSI/ESO
|
Platform workplan and covering auth methods, secret engines, CSI/ESO
|
||||||
integration, leases, unseal, backup, and break-glass.
|
integration, leases, unseal, backup, and break-glass.
|
||||||
|
|
||||||
|
## Document SSH certificates and tunnels
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0009-T04
|
id: NK-WP-0009-T04
|
||||||
status: todo
|
status: todo
|
||||||
|
|
@ -112,6 +118,8 @@ Write "Use short-lived SSH credentials for admins, agents, and
|
||||||
automations", using ops-warden and ops-bridge as the reference
|
automations", using ops-warden and ops-bridge as the reference
|
||||||
implementation.
|
implementation.
|
||||||
|
|
||||||
|
## Integrate a protected flex-auth consumer
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0009-T05
|
id: NK-WP-0009-T05
|
||||||
status: todo
|
status: todo
|
||||||
|
|
@ -123,6 +131,8 @@ Write "Add a protected system to flex-auth", covering resource
|
||||||
manifests, action vocabulary, claim envelopes, policy packages,
|
manifests, action vocabulary, claim envelopes, policy packages,
|
||||||
decision envelopes, and delegated PDP options.
|
decision envelopes, and delegated PDP options.
|
||||||
|
|
||||||
|
## Verify the tutorial outcomes
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0009-T06
|
id: NK-WP-0009-T06
|
||||||
status: todo
|
status: todo
|
||||||
|
|
@ -142,3 +152,22 @@ clear "done when" outcome and does not become prose-only guidance.
|
||||||
step.
|
step.
|
||||||
- Tutorials include verification and rollback guidance, not just happy
|
- Tutorials include verification and rollback guidance, not just happy
|
||||||
path commands.
|
path commands.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
Keep this plan in backlog, with the first implementation slice T01 + T03 +
|
||||||
|
T04 + T06: document the paths already operated and capture safe verification
|
||||||
|
and recovery outcomes. OpenBao is already deployed and private; T03 should
|
||||||
|
teach consumption, attended access and recovery, with greenfield deployment
|
||||||
|
kept as an isolated lab exercise. Use the named `openbao-ui-railiance01`
|
||||||
|
tunnel and owner runbooks, not a public Bao URL or copied runtime manifest.
|
||||||
|
|
||||||
|
T02 is conditional on an owner-backed object-store STS issuer and refusal/lease
|
||||||
|
proof; ADR-0008 is architecture, not evidence that the endpoint is live. T05
|
||||||
|
must include projected caller identity, audience, binding and unauthorized
|
||||||
|
caller rejection: all six live consumers now enforce caller authentication.
|
||||||
|
Use accepted IAM v0.3 and owner package declarations under ADR-0015. T06
|
||||||
|
requires executable safe fixtures or repeatable outcome checks; never teach
|
||||||
|
operators to apply the stale tenant-engine reference YAML.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: worsch
|
owner: worsch
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
created: "2026-05-20"
|
created: "2026-05-20"
|
||||||
updated: "2026-07-08"
|
updated: "2026-09-28"
|
||||||
state_hub_workstream_id: "1075448f-d533-5f9e-94b7-c3adfe151a07"
|
state_hub_workstream_id: "1075448f-d533-5f9e-94b7-c3adfe151a07"
|
||||||
depends_on:
|
depends_on:
|
||||||
- NK-WP-0003
|
- NK-WP-0003
|
||||||
|
|
@ -53,10 +53,10 @@ Keycloak as the internal user store. None of those assumptions hold now:
|
||||||
| NK-WP-0001 assumption | Current reality | Effect on this plan |
|
| NK-WP-0001 assumption | Current reality | Effect on this plan |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| HashiCorp Vault, bootstrapped from KeePassXC | **OpenBao** is the runtime secret authority (NK-WP-0006); SOPS/age + agent bootstrap exist (NK-WP-0004/0005) | Keycloak DB + admin secrets come from OpenBao via ESO; no new vault bootstrap |
|
| HashiCorp Vault, bootstrapped from KeePassXC | **OpenBao** is the runtime secret authority (NK-WP-0006); SOPS/age + agent bootstrap exist (NK-WP-0004/0005) | Keycloak DB + admin secrets come from OpenBao via ESO; no new vault bootstrap |
|
||||||
| PostgreSQL built from scratch | CloudNativePG running on RAILIANCE01 (NK-WP-0003) | Add `keycloak_db` to the existing operator, reuse backup pattern |
|
| PostgreSQL built from scratch | CloudNativePG running on RAILIANCE01 (NK-WP-0003) | Admit a database consumer through current platform owners; prove backup/restore |
|
||||||
| Keycloak is the internal source of truth (D2 hybrid) | KeyCape lightweight stack is the *deployed* IAM Profile issuer | Keycloak is a **broker/federation front-end**, not the primary user store |
|
| Keycloak is the internal source of truth (D2 hybrid) | KeyCape lightweight stack is the *deployed* IAM Profile issuer | Keycloak is a **broker/federation front-end**, not the primary user store |
|
||||||
| Authorization via Keycloak Authorization Services | flex-auth + Topaz is the canonical PDP (ADR-0006) | Keycloak AuthZ Services is at most an optional adapter, never canonical |
|
| Authorization via Keycloak Authorization Services | flex-auth + Topaz is the canonical PDP (ADR-0006) | Keycloak AuthZ Services is at most an optional adapter, never canonical |
|
||||||
| Single-tenant Coulomb deployment | Recursive `tenant:platform` vs `tenant:coulomb` model (NK-WP-0006) | Realm-per-tenant; tenant admins must not receive platform-root |
|
| Single-tenant Coulomb deployment | Recursive `tenant:platform` vs `tenant:coulomb` model (NK-WP-0006) | Evaluate realm-per-tenant; tenant admins must not receive platform-root |
|
||||||
| MFA solely via privacyIDEA provider JAR | privacyIDEA deployed *and* upstream IdPs carry their own MFA | MFA assurance source becomes a decision, not a default |
|
| MFA solely via privacyIDEA provider JAR | privacyIDEA deployed *and* upstream IdPs carry their own MFA | MFA assurance source becomes a decision, not a default |
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
|
|
@ -68,7 +68,7 @@ Keycloak as the internal user store. None of those assumptions hold now:
|
||||||
└──────────────┼──────────────┘
|
└──────────────┼──────────────┘
|
||||||
▼
|
▼
|
||||||
[ Keycloak ] expanded-mode broker
|
[ Keycloak ] expanded-mode broker
|
||||||
│ realm-per-tenant; IAM Profile issuer
|
│ realm-per-tenant candidate; IAM Profile issuer
|
||||||
│ secrets ← OpenBao (ESO)
|
│ secrets ← OpenBao (ESO)
|
||||||
│ MFA ← privacyIDEA *or* upstream assurance
|
│ MFA ← privacyIDEA *or* upstream assurance
|
||||||
▼
|
▼
|
||||||
|
|
@ -77,7 +77,7 @@ Keycloak as the internal user store. None of those assumptions hold now:
|
||||||
├──► applications (depend on the Profile, not the provider)
|
├──► applications (depend on the Profile, not the provider)
|
||||||
└──► flex-auth / Topaz ── authorization decision (PDP)
|
└──► flex-auth / Topaz ── authorization decision (PDP)
|
||||||
|
|
||||||
coexists with: KeyCape lightweight issuer (id.coulomb.social)
|
coexists with: KeyCape lightweight issuer (kc.coulomb.social)
|
||||||
```
|
```
|
||||||
|
|
||||||
Keycloak answers identity (who, how authenticated, coarse claims,
|
Keycloak answers identity (who, how authenticated, coarse claims,
|
||||||
|
|
@ -90,10 +90,10 @@ OpenBao.
|
||||||
In scope:
|
In scope:
|
||||||
|
|
||||||
- decision record for expanded-mode adoption: trigger, federation
|
- decision record for expanded-mode adoption: trigger, federation
|
||||||
topology (broker vs SAML SP), realm-per-tenant model, and coexistence
|
topology (broker vs SAML SP), realm isolation model, and coexistence
|
||||||
with the KeyCape lightweight issuer
|
with the KeyCape lightweight issuer
|
||||||
- custom Keycloak image (privacyIDEA provider JAR if MFA is delegated to
|
- owner-packaged Keycloak image (privacyIDEA provider JAR only if selected
|
||||||
privacyIDEA) and Helm deployment on RAILIANCE01
|
and verified compatible) and managed deployment on railiance01
|
||||||
- upstream federation: Entra ID (OIDC), AD (LDAP), generic SAML 2.0 IdP
|
- upstream federation: Entra ID (OIDC), AD (LDAP), generic SAML 2.0 IdP
|
||||||
- claim mapping to the NetKingdom IAM Profile (issuer, audience, subject,
|
- claim mapping to the NetKingdom IAM Profile (issuer, audience, subject,
|
||||||
groups, tenant, assurance evidence) and IAM Profile conformance checks
|
groups, tenant, assurance evidence) and IAM Profile conformance checks
|
||||||
|
|
@ -112,7 +112,7 @@ Out of scope:
|
||||||
- tenant-specific federation policy for tenants beyond `tenant:platform`
|
- tenant-specific federation policy for tenants beyond `tenant:platform`
|
||||||
and `tenant:coulomb`
|
and `tenant:coulomb`
|
||||||
|
|
||||||
## Tasks
|
## Decide federation adoption and topology
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T01
|
id: NK-WP-0011-T01
|
||||||
|
|
@ -125,11 +125,14 @@ priority: high
|
||||||
an ADR (ADR-0009) capturing: the concrete trigger for switching a tenant
|
an ADR (ADR-0009) capturing: the concrete trigger for switching a tenant
|
||||||
from lightweight to expanded mode; whether Keycloak acts as an OIDC
|
from lightweight to expanded mode; whether Keycloak acts as an OIDC
|
||||||
identity broker, a SAML service provider, or both; the realm-per-tenant
|
identity broker, a SAML service provider, or both; the realm-per-tenant
|
||||||
mapping onto `tenant:platform` / `tenant:coulomb`; how the Keycloak issuer
|
candidate and its alternatives mapped onto `tenant:platform` /
|
||||||
coexists with the KeyCape issuer (`id.coulomb.social`) so applications
|
`tenant:coulomb`; how the Keycloak issuer
|
||||||
|
coexists with the KeyCape issuer (`kc.coulomb.social`) so applications
|
||||||
still target one IAM Profile contract; and the canonical hostname/issuer
|
still target one IAM Profile contract; and the canonical hostname/issuer
|
||||||
for the broker. Resolve or supersede D2 from NK-WP-0001.
|
for the broker. Resolve or supersede D2 from NK-WP-0001.
|
||||||
|
|
||||||
|
## Admit the database consumer
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T02
|
id: NK-WP-0011-T02
|
||||||
state_hub_task_id: "2fe6f100-3a5d-563e-b033-7d7b846ae487"
|
state_hub_task_id: "2fe6f100-3a5d-563e-b033-7d7b846ae487"
|
||||||
|
|
@ -137,12 +140,15 @@ status: todo
|
||||||
priority: high
|
priority: high
|
||||||
```
|
```
|
||||||
|
|
||||||
**PostgreSQL `keycloak_db` on the existing operator.** Add a `keycloak`
|
**PostgreSQL `keycloak_db` on the existing operator.** Have railiance-platform
|
||||||
database and role to the CloudNativePG instance from NK-WP-0003 (do not
|
and rapp-postgres admit a named Keycloak database consumer against the current
|
||||||
deploy a new database). Source credentials from OpenBao via ESO into a K8s
|
database catalog and isolation needs. Do not assume the historical NK-WP-0003
|
||||||
Secret. Confirm the existing backup schedule covers the new database and
|
instance is the correct placement. Source credentials from OpenBao via ESO
|
||||||
|
into a K8s Secret. Confirm the existing backup schedule covers the new database and
|
||||||
run a restore drill for `keycloak_db` specifically.
|
run a restore drill for `keycloak_db` specifically.
|
||||||
|
|
||||||
|
## Package the broker deployment
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T03
|
id: NK-WP-0011-T03
|
||||||
state_hub_task_id: "32d1411b-10a4-5a8b-8f43-99ac46d83908"
|
state_hub_task_id: "32d1411b-10a4-5a8b-8f43-99ac46d83908"
|
||||||
|
|
@ -152,12 +158,15 @@ priority: high
|
||||||
|
|
||||||
**Deploy expanded-mode Keycloak.** Build a custom image
|
**Deploy expanded-mode Keycloak.** Build a custom image
|
||||||
(`kc.sh build`, privacyIDEA provider JAR included only if T5 delegates MFA
|
(`kc.sh build`, privacyIDEA provider JAR included only if T5 delegates MFA
|
||||||
to privacyIDEA). Deploy via plain Helm on RAILIANCE01 behind Traefik +
|
to privacyIDEA). Assign the package/runtime owner under ADR-0015 and deploy
|
||||||
|
through its managed declaration on railiance01 behind Traefik +
|
||||||
cert-manager at the issuer hostname from T1. Admin bootstrap secret and DB
|
cert-manager at the issuer hostname from T1. Admin bootstrap secret and DB
|
||||||
secret come from OpenBao/ESO — never typed, never in git. Hostname
|
secret come from OpenBao/ESO — never typed, never in git. Hostname
|
||||||
strictness + proxy headers configured for Traefik. Realm import is
|
strictness + proxy headers configured for Traefik. Realm import is
|
||||||
GitOps-friendly (realm JSON/CR in git).
|
GitOps-friendly (realm JSON/CR in git).
|
||||||
|
|
||||||
|
## Integrate an upstream identity provider
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T04
|
id: NK-WP-0011-T04
|
||||||
state_hub_task_id: "6697a994-7343-5ea8-8b37-bc3b921e5a9b"
|
state_hub_task_id: "6697a994-7343-5ea8-8b37-bc3b921e5a9b"
|
||||||
|
|
@ -172,6 +181,8 @@ audience, subject, groups, **tenant**, and assurance evidence. Define the
|
||||||
attribute/claim mappers and group→role mapping. Verify a federated login
|
attribute/claim mappers and group→role mapping. Verify a federated login
|
||||||
end-to-end for at least the Entra ID path.
|
end-to-end for at least the Entra ID path.
|
||||||
|
|
||||||
|
## Define federated assurance
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T05
|
id: NK-WP-0011-T05
|
||||||
state_hub_task_id: "d845380d-3dbc-5e59-8f2b-5a4d1b32d89d"
|
state_hub_task_id: "d845380d-3dbc-5e59-8f2b-5a4d1b32d89d"
|
||||||
|
|
@ -187,6 +198,8 @@ evidence in the token. Require step-up for admin console and
|
||||||
platform-root-sensitive clients. Ensure assurance evidence is carried in
|
platform-root-sensitive clients. Ensure assurance evidence is carried in
|
||||||
the IAM Profile token so flex-auth can gate privileged actions on it.
|
the IAM Profile token so flex-auth can gate privileged actions on it.
|
||||||
|
|
||||||
|
## Verify IAM conformance and coexistence
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T06
|
id: NK-WP-0011-T06
|
||||||
state_hub_task_id: "9cb7fd93-c16e-5102-83ce-195b3aa87446"
|
state_hub_task_id: "9cb7fd93-c16e-5102-83ce-195b3aa87446"
|
||||||
|
|
@ -199,9 +212,11 @@ conformance checks against the Keycloak issuer (discovery document, PKCE,
|
||||||
token/claim shape, JWKS, userinfo). Verify an application configured for
|
token/claim shape, JWKS, userinfo). Verify an application configured for
|
||||||
the IAM Profile can authenticate against either the KeyCape or the
|
the IAM Profile can authenticate against either the KeyCape or the
|
||||||
Keycloak issuer per the T1 selection rule. Use the canonical
|
Keycloak issuer per the T1 selection rule. Use the canonical
|
||||||
`canon/standards/iam-profile_v0.2.md` contract and the executable suite in
|
`canon/standards/iam-profile_v0.3.md` contract and the executable suite in
|
||||||
`tools/iam-profile-conformance/`. Document per-tenant issuer selection.
|
`tools/iam-profile-conformance/`. Document per-tenant issuer selection.
|
||||||
|
|
||||||
|
## Enforce tenant and platform boundaries
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T07
|
id: NK-WP-0011-T07
|
||||||
state_hub_task_id: "38998c68-29bf-50d2-8c8d-0c75184d5833"
|
state_hub_task_id: "38998c68-29bf-50d2-8c8d-0c75184d5833"
|
||||||
|
|
@ -209,14 +224,17 @@ status: todo
|
||||||
priority: high
|
priority: high
|
||||||
```
|
```
|
||||||
|
|
||||||
**Recursive tenancy & authorization boundary.** Implement realm-per-tenant
|
**Recursive tenancy & authorization boundary.** Implement T1's reviewed
|
||||||
with platform-root guardrails: tenant admins manage only their realm and
|
realm/tenant topology with platform-root guardrails. If realm-per-tenant is
|
||||||
|
selected, tenant admins manage only their realm; in every topology they
|
||||||
must not be able to alter IAM Profile semantics, the platform realm,
|
must not be able to alter IAM Profile semantics, the platform realm,
|
||||||
federation trust, OpenBao platform mounts, or audit retention (per the
|
federation trust, OpenBao platform mounts, or audit retention (per the
|
||||||
flex-auth/Topaz implications in the architecture doc). Confirm flex-auth +
|
flex-auth/Topaz implications in the architecture doc). Confirm flex-auth +
|
||||||
Topaz remains the PDP; if a Keycloak Authorization Services adapter is
|
Topaz remains the PDP; if a Keycloak Authorization Services adapter is
|
||||||
used at all, document it as a delegated, non-canonical adapter.
|
used at all, document it as a delegated, non-canonical adapter.
|
||||||
|
|
||||||
|
## Prove recovery and audit delivery
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0011-T08
|
id: NK-WP-0011-T08
|
||||||
state_hub_task_id: "e5f44ddc-9645-5f61-b84c-da5ab9cccb6d"
|
state_hub_task_id: "e5f44ddc-9645-5f61-b84c-da5ab9cccb6d"
|
||||||
|
|
@ -224,8 +242,9 @@ status: todo
|
||||||
priority: medium
|
priority: medium
|
||||||
```
|
```
|
||||||
|
|
||||||
**Backups, DR, break-glass, monitoring, audit.** Realm exports to git; DB
|
**Backups, DR, break-glass, monitoring, audit.** Only sanitized declarative
|
||||||
backup + restore drill (T2); break-glass admin path disabled-by-default
|
realm configuration belongs in git; keep credential-bearing exports in
|
||||||
|
protected backup custody; DB backup + restore drill (T2); break-glass admin path disabled-by-default
|
||||||
with alerting on use; Prometheus/Grafana for auth success/failure, MFA
|
with alerting on use; Prometheus/Grafana for auth success/failure, MFA
|
||||||
latency, federation errors. Ship Keycloak events to the durable platform
|
latency, federation errors. Ship Keycloak events to the durable platform
|
||||||
audit sink alongside flex-auth/Topaz/OpenBao records, with correlation
|
audit sink alongside flex-auth/Topaz/OpenBao records, with correlation
|
||||||
|
|
@ -235,7 +254,7 @@ production-readiness checklist.
|
||||||
## Acceptance Criteria
|
## Acceptance Criteria
|
||||||
|
|
||||||
- An ADR records the expanded-mode trigger, federation topology,
|
- An ADR records the expanded-mode trigger, federation topology,
|
||||||
realm-per-tenant model, and KeyCape/Keycloak issuer coexistence.
|
selected realm/tenant isolation model, and KeyCape/Keycloak issuer coexistence.
|
||||||
- A federated user from at least one enterprise IdP (Entra ID) can log in
|
- A federated user from at least one enterprise IdP (Entra ID) can log in
|
||||||
and receive an IAM Profile-conformant token with tenant + assurance
|
and receive an IAM Profile-conformant token with tenant + assurance
|
||||||
claims.
|
claims.
|
||||||
|
|
@ -257,5 +276,25 @@ production-readiness checklist.
|
||||||
- **railiance-platform**: OpenBao must expose a Keycloak auth role / ESO
|
- **railiance-platform**: OpenBao must expose a Keycloak auth role / ESO
|
||||||
path before T3; unseal/break-glass story must be ready.
|
path before T3; unseal/break-glass story must be ready.
|
||||||
- **IAM Profile spec**: resolved by NK-WP-0012. T6 consumes
|
- **IAM Profile spec**: resolved by NK-WP-0012. T6 consumes
|
||||||
`canon/standards/iam-profile_v0.2.md` and
|
`canon/standards/iam-profile_v0.3.md` and
|
||||||
`tools/iam-profile-conformance/`.
|
`tools/iam-profile-conformance/`.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
Keep in backlog until a named enterprise tenant, upstream IdP owner and
|
||||||
|
concrete federation need justify operating another issuer. No Keycloak
|
||||||
|
Deployment appears in today's cluster inventory. Realm-per-tenant remains a
|
||||||
|
proposal to evaluate in T01, not a requirement derived from current topology;
|
||||||
|
prove its mapping to tenant-engine's canonical identity/lifecycle contract.
|
||||||
|
|
||||||
|
The live issuer is `https://kc.coulomb.social`; IAM v0.3 is accepted and v0.4
|
||||||
|
step-up is proposed. T01/T05/T06 must coordinate with NK-WP-0042 and preserve
|
||||||
|
existing issuer/subject account bindings, audiences and session/revocation
|
||||||
|
behavior. Do not infer equivalent assurance from an upstream MFA claim without
|
||||||
|
a reviewed trust mapping. The single-node cluster and single-instance database
|
||||||
|
providers offer no automatic HA guarantee. T02/T08 must name backup ownership,
|
||||||
|
off-host custody and an isolated restore proof. OpenBao access is private via
|
||||||
|
the platform operator path. Resource placement, packaging and runtime
|
||||||
|
execution belong to their owners, not this canon repository.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
created: "2026-07-27"
|
created: "2026-07-27"
|
||||||
updated: "2026-08-08"
|
updated: "2026-09-28"
|
||||||
depends_on:
|
depends_on:
|
||||||
- USER-WP-0020
|
- USER-WP-0020
|
||||||
- NK-WP-0023
|
- NK-WP-0023
|
||||||
|
|
@ -24,16 +24,18 @@ CoulombCore (`92.205.130.254`) to railiance01 (`92.205.62.239`) without
|
||||||
losing users, groups, MFA enrollments, signing/encryption material, or the
|
losing users, groups, MFA enrollments, signing/encryption material, or the
|
||||||
ability to roll back.
|
ability to roll back.
|
||||||
|
|
||||||
The two servers currently run independent copies of KeyCape, Authelia, LLDAP,
|
At the July 27 migration baseline, the two servers ran independent copies of
|
||||||
privacyIDEA, and `net-kingdom-pg`. Public KeyCape DNS already points to
|
KeyCape, Authelia, LLDAP,
|
||||||
railiance01, while Authelia, LLDAP, and privacyIDEA DNS still points to
|
privacyIDEA, and `net-kingdom-pg`. At that baseline, public KeyCape DNS pointed to
|
||||||
CoulombCore. Retirement is forbidden until state equivalence, end-to-end
|
railiance01 while other identity names still pointed to CoulombCore.
|
||||||
login, backup restoration, and an observed rollback window pass.
|
T06/T07 below supersede that topology: identity cutover and reversible
|
||||||
|
retirement completed on July 30 after the recorded migration gates passed.
|
||||||
|
Final deletion still requires the separate T08 recovery and approval gates.
|
||||||
|
|
||||||
This cutover intentionally waits until the reusable user onboarding portal
|
The original cutover intentionally waited for the reusable user onboarding
|
||||||
completes the Binky tenant-admin flow. That supplies the human login/MFA and
|
portal to complete the Binky tenant-admin flow. That supplied the human
|
||||||
lifecycle evidence needed to judge which identity stack is authoritative
|
login/MFA and lifecycle evidence used to establish identity authority before
|
||||||
before state migration or retirement begins.
|
state migration and reversible retirement.
|
||||||
|
|
||||||
## T01 - Freeze the migration contract and inventory both stacks
|
## T01 - Freeze the migration contract and inventory both stacks
|
||||||
|
|
||||||
|
|
@ -313,11 +315,12 @@ runbooks. Run `statehub fix-consistency`.
|
||||||
Done when railiance01 is the sole authoritative identity stack, all evidence
|
Done when railiance01 is the sole authoritative identity stack, all evidence
|
||||||
is reconciled, and the workplan is marked finished.
|
is reconciled, and the workplan is marked finished.
|
||||||
|
|
||||||
Retention gate: keep the reversible CoulombCore identity resources through at
|
Retention minimum: 2026-08-29 has passed. The plan is no longer date-blocked.
|
||||||
least 2026-08-29. The workplan is blocked until that review date, when T08 can
|
T08 remains blocked on a scoped retained-resource inventory, a successful
|
||||||
be checked for readiness to finish. Reaching the date does not authorize
|
identity restore/restart receipt, and explicit destructive approval.
|
||||||
deletion or completion: T08 still requires a successful railiance01
|
Elapsed retention alone does not authorize deletion or completion: T08 still
|
||||||
restore/restart drill and new explicit approval for destructive deletion.
|
requires a successful railiance01 restore/restart drill and new explicit
|
||||||
|
approval for destructive deletion.
|
||||||
|
|
||||||
## Safety gates
|
## Safety gates
|
||||||
|
|
||||||
|
|
@ -328,3 +331,15 @@ restore/restart drill and new explicit approval for destructive deletion.
|
||||||
- No PVC/database/Secret deletion as part of the reversible retirement step.
|
- No PVC/database/Secret deletion as part of the reversible retirement step.
|
||||||
- Final deletion always requires an explicit human approval distinct from DNS
|
- Final deletion always requires an explicit human approval distinct from DNS
|
||||||
cutover approval.
|
cutover approval.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
Live read-only inventory confirms the identity services on railiance01 are
|
||||||
|
ready. CoulombCore was not inspected in this review; do not infer that its
|
||||||
|
retained resources have been deleted. Recheck the exact retained identity
|
||||||
|
resources and backup custody before preparing the T08 deletion list. A generic
|
||||||
|
platform-pg recovery drill is not a restore of LLDAP, Authelia, privacyIDEA
|
||||||
|
with its encryption material, and identity database state. Whole-host retirement
|
||||||
|
and other owners' workloads remain outside this identity-only deletion gate.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -10,7 +10,7 @@ owner: net-kingdom
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
planning_priority: P1
|
planning_priority: P1
|
||||||
created: "2026-08-19"
|
created: "2026-08-19"
|
||||||
updated: "2026-08-22"
|
updated: "2026-09-28"
|
||||||
state_hub_workstream_id: "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4"
|
state_hub_workstream_id: "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -250,3 +250,20 @@ ordinary next input.
|
||||||
authoritative workload ids and fail-safe exception evaluation
|
authoritative workload ids and fail-safe exception evaluation
|
||||||
- `docs/reef-posture-provider-contract.md` — concrete T02/T03 carrier and join
|
- `docs/reef-posture-provider-contract.md` — concrete T02/T03 carrier and join
|
||||||
proposal awaiting reef-owner agreement
|
proposal awaiting reef-owner agreement
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
The current `reef-railiance/declarations/reef.yaml` still has no
|
||||||
|
`posture_provider` block. Its `ownership_repo` is `railiance-infra`: involve
|
||||||
|
that substrate owner alongside repo-manager (carrier/schema) in T02. The live
|
||||||
|
cluster has one Ready node; all eight CNPG clusters report one instance. This
|
||||||
|
supports retaining the single-failure-domain constraint, not assigning a new
|
||||||
|
V level from replica counts. T02/T03 stay `wait`.
|
||||||
|
|
||||||
|
InfoTechCanon Data Model §11.23 explicitly lists `public`; ops-warden
|
||||||
|
`registry/policy/security-posture.yaml` still has no public maturity floor.
|
||||||
|
The missing artifact is an owner-agreed mapping separating disclosure class
|
||||||
|
from synthetic provenance, not proof that public exists. T06 stays `wait`;
|
||||||
|
no `public -> synthetic` alias or guessed M1 floor is permitted.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -10,7 +10,7 @@ owner: codex
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
planning_priority: P1
|
planning_priority: P1
|
||||||
created: "2026-08-23"
|
created: "2026-08-23"
|
||||||
updated: "2026-08-23"
|
updated: "2026-09-28"
|
||||||
state_hub_workstream_id: "9d7b04f9-3803-5613-b7a5-8bd606c77f5a"
|
state_hub_workstream_id: "9d7b04f9-3803-5613-b7a5-8bd606c77f5a"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -116,3 +116,20 @@ Verification on 2026-08-23:
|
||||||
|
|
||||||
Local implementation is complete. The workplan remains blocked only on T04's
|
Local implementation is complete. The workplan remains blocked only on T04's
|
||||||
externally owned audit-core declaration adoption.
|
externally owned audit-core declaration adoption.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
`audit-core/tenancy.yaml` still lacks machine-readable authoritative owner
|
||||||
|
and E2 freshness metadata. Its E2 prose retains the August 22 receipt and
|
||||||
|
24-hour replacement deadline; report freshness as `unknown` until the required
|
||||||
|
fields exist, without renewing that evidence from prose. The September 24
|
||||||
|
receiver/database recreate evidence supports V1 only and cannot refresh E2.
|
||||||
|
T04 remains `wait`; request the source declaration update and evaluate it with
|
||||||
|
an explicit current `--as-of` before closure.
|
||||||
|
|
||||||
|
The same declaration still describes flex-auth as unauthenticated A0, whereas
|
||||||
|
today all six live flex-auth Deployments pass `--caller-auth-mode enforce`.
|
||||||
|
The audit-core owner should reconcile that rationale against actual caller
|
||||||
|
bindings and policy evidence; deployment flags alone do not prove a new A level.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -4,12 +4,12 @@ type: workplan
|
||||||
title: "Admit the operator-tunneled OpenBao browser callback"
|
title: "Admit the operator-tunneled OpenBao browser callback"
|
||||||
domain: infotech
|
domain: infotech
|
||||||
repo: net-kingdom
|
repo: net-kingdom
|
||||||
status: blocked
|
status: finished
|
||||||
flavor: implementation
|
flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: net-kingdom
|
topic_slug: net-kingdom
|
||||||
created: "2026-08-23"
|
created: "2026-08-23"
|
||||||
updated: "2026-08-23"
|
updated: "2026-09-28"
|
||||||
related:
|
related:
|
||||||
- RMASTER-WP-0020-T09
|
- RMASTER-WP-0020-T09
|
||||||
- RAILIANCE-WP-0027-T03
|
- RAILIANCE-WP-0027-T03
|
||||||
|
|
@ -68,7 +68,7 @@ or Secret value was observed.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0032-T03
|
id: NK-WP-0032-T03
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "73b77110-2d4f-527e-98eb-2ec33897681e"
|
state_hub_task_id: "73b77110-2d4f-527e-98eb-2ec33897681e"
|
||||||
```
|
```
|
||||||
|
|
@ -82,7 +82,7 @@ query, browser storage, or role response body.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: NK-WP-0032-T04
|
id: NK-WP-0032-T04
|
||||||
status: wait
|
status: done
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "f62bda4a-7607-5c50-9e04-664cc1b829ac"
|
state_hub_task_id: "f62bda4a-7607-5c50-9e04-664cc1b829ac"
|
||||||
```
|
```
|
||||||
|
|
@ -91,3 +91,24 @@ After T02 and T03 pass, perform one attended MFA login through
|
||||||
`http://127.0.0.1:18200` and return only the success/failure outcome. This task
|
`http://127.0.0.1:18200` and return only the success/failure outcome. This task
|
||||||
does not authorize public Ingress retraction; Railiance Platform retains that
|
does not authorize public Ingress retraction; Railiance Platform retains that
|
||||||
separate guarded hold point.
|
separate guarded hold point.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
T03 and T04 are complete from existing owner evidence; no new attended login
|
||||||
|
or role write is needed for this reconciliation. Railiance Platform
|
||||||
|
`docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json`
|
||||||
|
proves the exact callback already present, Warden exit 0 and session revocation.
|
||||||
|
`docs/evidence/2026-09-15-openbao-public-listener-retract.json` records successful
|
||||||
|
operator loopback MFA, private HTTP 200, gateway readiness and public Ingress
|
||||||
|
retraction. `RPF-WP-0025` closure on September 22 records the handoff to
|
||||||
|
Railiance Master. These receipts discharge the original role and login gates.
|
||||||
|
|
||||||
|
Today the gateway and OpenBao are ready, their Services are ClusterIP, and the
|
||||||
|
openbao namespace has no Ingress. The September 24 callback-prune receipt
|
||||||
|
retired the public callbacks; current NetKingdom client source also forbids
|
||||||
|
their return. T01's bounded rollback requirement is historical, not an
|
||||||
|
instruction to restore public callbacks. DNS withdrawal remains the
|
||||||
|
railiance-infra owner residual described by RPF-WP-0025; this review does not
|
||||||
|
claim it is complete or authorize a listener change.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: claude-code
|
owner: claude-code
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
created: "2026-09-23"
|
created: "2026-09-23"
|
||||||
updated: "2026-09-23"
|
updated: "2026-09-28"
|
||||||
related: [FLEX-WP-0020, FLEX-DEC-2026-013, NK-WP-0026]
|
related: [FLEX-WP-0020, FLEX-DEC-2026-013, NK-WP-0026]
|
||||||
state_hub_workstream_id: "284a8ac2-61dc-5bee-b74a-0a62d9808edb"
|
state_hub_workstream_id: "284a8ac2-61dc-5bee-b74a-0a62d9808edb"
|
||||||
---
|
---
|
||||||
|
|
@ -40,7 +40,7 @@ Read-only check on railiance01 (node `92.205.62.239`) on 2026-09-23. The
|
||||||
`flex-auth-`. Every one pulls
|
`flex-auth-`. Every one pulls
|
||||||
`forgejo.coulomb.social/coulomb/flex-auth@sha256:…`.
|
`forgejo.coulomb.social/coulomb/flex-auth@sha256:…`.
|
||||||
|
|
||||||
NetKingdom declares two of them in `sso-mfa/k8s/tenant-engine/runtime.yaml`
|
At the September 23 inventory, NetKingdom declared two of them in `sso-mfa/k8s/tenant-engine/runtime.yaml`
|
||||||
(`flex-auth-tenant-engine`, `flex-auth-user-engine`). Everything else under
|
(`flex-auth-tenant-engine`, `flex-auth-user-engine`). Everything else under
|
||||||
`sso-mfa/k8s/**` that names flex-auth is a runtime name that stays: the
|
`sso-mfa/k8s/**` that names flex-auth is a runtime name that stays: the
|
||||||
namespace, Service DNS `flex-auth-user-engine.flex-auth.svc.cluster.local`,
|
namespace, Service DNS `flex-auth-user-engine.flex-auth.svc.cluster.local`,
|
||||||
|
|
@ -63,8 +63,8 @@ Resolved 2026-09-23 (flex-auth reply `28d9c6ca`): live is correct. `05a03a87`
|
||||||
was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence
|
was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence
|
||||||
`docs/evidence/2026-09-11-user-portal-tenant-policy.md`); `138aa347` has been
|
`docs/evidence/2026-09-11-user-portal-tenant-policy.md`); `138aa347` has been
|
||||||
live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is
|
live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is
|
||||||
`values/<consumer>.yaml` in flex-auth. `runtime.yaml` now declares the live
|
`values/<consumer>.yaml` in flex-auth. `runtime.yaml` was updated to those live
|
||||||
digests. See T04 for the rest of the drift.
|
digests. T04 later removes the obsolete flex-auth reference objects entirely.
|
||||||
|
|
||||||
## Confirm the image-pull path survives the rename
|
## Confirm the image-pull path survives the rename
|
||||||
|
|
||||||
|
|
@ -98,17 +98,16 @@ priority: medium
|
||||||
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"
|
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"
|
||||||
```
|
```
|
||||||
|
|
||||||
Once flex-auth announces that `coulomb/access-engine` resolves, update
|
Once flex-auth announces that `coulomb/access-engine` resolves, verify
|
||||||
references to the repository coordinate. If the image coordinate
|
repository-coordinate references against the retained runtime/package contract.
|
||||||
changes, update the two image pins in `sso-mfa/k8s/tenant-engine/runtime.yaml`
|
T02 confirms image coordinates stay unchanged; do not schedule image-pin
|
||||||
in the same change as the digest reconciliation from T01. Applying that live
|
changes or a rollout as part of this rename. Leave historical records intact.
|
||||||
needs the founder's go-ahead. Leave runtime names and historical records
|
|
||||||
unchanged.
|
|
||||||
|
|
||||||
After T02, no in-repo coordinate reference needs to change: the image pins
|
T04 now introduces explicit owner-repository links in
|
||||||
stay, and NK-WP-0026 is a historical record. This task waits only for
|
`sso-mfa/k8s/tenant-engine/README.md` and a repository coordinate in the YAML
|
||||||
flex-auth's announcement that `access-engine` resolves, which confirms that
|
header. After the rename announcement, update these pointers to the confirmed
|
||||||
nothing else moved.
|
new repository/checkout, verify both value-file paths resolve and preserve the
|
||||||
|
runtime/package names. NK-WP-0026 remains a historical record.
|
||||||
|
|
||||||
## Retire or reconcile the stale flex-auth/tenant-engine reference manifest
|
## Retire or reconcile the stale flex-auth/tenant-engine reference manifest
|
||||||
|
|
||||||
|
|
@ -119,7 +118,7 @@ priority: high
|
||||||
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"
|
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"
|
||||||
```
|
```
|
||||||
|
|
||||||
**Waiting 2026-09-27.** Routed the retire-vs-reconcile question to flex-auth
|
**Historical hold, superseded in part by the September 28 review below.** Routed the retire-vs-reconcile question to flex-auth
|
||||||
(`2c637dc9-14ad-4815-aeb4-43254d01280c`) and tenant-engine
|
(`2c637dc9-14ad-4815-aeb4-43254d01280c`) and tenant-engine
|
||||||
(`9fc740da-1966-4d39-a28a-79fd4870edb1`). NetKingdom will act on whichever
|
(`9fc740da-1966-4d39-a28a-79fd4870edb1`). NetKingdom will act on whichever
|
||||||
answer comes back (retire and point to their authoritative declarations, or
|
answer comes back (retire and point to their authoritative declarations, or
|
||||||
|
|
@ -137,3 +136,42 @@ would drop caller-auth enforcement.
|
||||||
Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference
|
Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference
|
||||||
copy. The recommendation is to replace it with pointers to the owners'
|
copy. The recommendation is to replace it with pointers to the owners'
|
||||||
declarations (ADR-0015) rather than reconcile it field by field.
|
declarations (ADR-0015) rather than reconcile it field by field.
|
||||||
|
|
||||||
|
### Implementation — 2026-09-28
|
||||||
|
|
||||||
|
The approved flex-auth portion is complete. Removed seven reference objects:
|
||||||
|
the flex-auth Namespace and both consumers' Deployment, Service and
|
||||||
|
NetworkPolicy objects. Added exact links to `flex-auth/values/tenant-engine.yaml`,
|
||||||
|
`flex-auth/values/user-engine.yaml` and `charts/flex-auth` in the adjacent README.
|
||||||
|
Their caller enforcement and bindings stay owned by those declarations.
|
||||||
|
|
||||||
|
The five tenant-engine objects are structurally unchanged and retain the
|
||||||
|
DO-NOT-APPLY header. Repository script/workflow/Makefile searches found no
|
||||||
|
consumer of this combined manifest; the user-engine verifier uses its own
|
||||||
|
separate runtime file. Parsed before/after YAML proves only the seven approved
|
||||||
|
objects were removed. Owner links resolve locally and both value files declare
|
||||||
|
`callerAuth.mode: enforce`. No cluster apply, rollout or runtime rename occurred.
|
||||||
|
|
||||||
|
T04 returns to `wait` solely for tenant-engine's disposition of its remaining
|
||||||
|
objects; T03 waits for the repository rename. With no remaining locally
|
||||||
|
executable task in this plan, its status is `blocked` again.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
Flex-auth replied September 27 in message
|
||||||
|
`77b26d1e-550b-4926-9610-44fc3a566273`: no objection to replacing its
|
||||||
|
reference objects with pointers to authoritative `values/<consumer>.yaml`.
|
||||||
|
At the review baseline, T04 had a locally actionable flex-auth portion and
|
||||||
|
was `todo`; the plan was `active`. The implementation above supersedes that
|
||||||
|
status. Preserve the DO-NOT-APPLY guard. Retire only those flex-auth reference
|
||||||
|
objects when implementing that portion, with exact owner pointers and a check
|
||||||
|
that no application path consumes them. Tenant-engine's portion still awaits
|
||||||
|
its owner answer; do not treat flex-auth's response as authority over it.
|
||||||
|
T04 closes only when both portions are resolved.
|
||||||
|
|
||||||
|
Live read-only checks confirm all six flex-auth Deployments are ready and
|
||||||
|
enforce caller authentication. Applying the stale reference would risk losing
|
||||||
|
that protection. FLEX-WP-0020 still holds rename execution at T06; T03 stays
|
||||||
|
`wait`, independently of this reference cleanup.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: planning
|
||||||
owner: claude-code
|
owner: claude-code
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
created: "2026-09-23"
|
created: "2026-09-23"
|
||||||
updated: "2026-09-24"
|
updated: "2026-09-28"
|
||||||
related: [RCLK-WP-0002]
|
related: [RCLK-WP-0002]
|
||||||
state_hub_workstream_id: "e2533f3a-aa43-59b3-bff3-8e64b6149487"
|
state_hub_workstream_id: "e2533f3a-aa43-59b3-bff3-8e64b6149487"
|
||||||
---
|
---
|
||||||
|
|
@ -75,3 +75,20 @@ agreement) and Railiance (emitter confirmation) via State Hub messages
|
||||||
`4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and
|
`4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and
|
||||||
validator once both reply; nothing here can be finished unilaterally
|
validator once both reply; nothing here can be finished unilaterally
|
||||||
without pre-empting their agreement.
|
without pre-empting their agreement.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
Use accepted IAM Profile v0.3 and Playbook Capability Contract v0.1 as the
|
||||||
|
current baseline. Proposed IAM v0.4 and Playbook v0.2 are not deployed
|
||||||
|
capabilities. RCLK-WP-0002 still explicitly names this receipt as its dependency
|
||||||
|
on September 28. T02 remains `wait` for emitter and evidence-holder agreement.
|
||||||
|
|
||||||
|
Require the agreed schema to preserve unknown actor/delegation and clock
|
||||||
|
bounds explicitly, correlate decision/approval/run/artifact identities, and
|
||||||
|
distinguish durable receipt ingestion from attribution proof. Reuse audit-core
|
||||||
|
sender custody and reconciliation contracts rather than create another audit
|
||||||
|
sink. Acceptance needs an actual Railiance-emitted receipt and audit-core
|
||||||
|
readback, plus invalid/missing attribution cases; schema validation alone
|
||||||
|
cannot establish end-to-end attribution.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: planning
|
||||||
owner: claude-code
|
owner: claude-code
|
||||||
topic_slug: netkingdom
|
topic_slug: netkingdom
|
||||||
created: "2026-09-23"
|
created: "2026-09-23"
|
||||||
updated: "2026-09-24"
|
updated: "2026-09-28"
|
||||||
related: [NK-ADR-0016, NK-WP-0037]
|
related: [NK-ADR-0016, NK-WP-0037]
|
||||||
state_hub_workstream_id: "3f702215-704b-5788-8ca0-b8b9ba2dd3f8"
|
state_hub_workstream_id: "3f702215-704b-5788-8ca0-b8b9ba2dd3f8"
|
||||||
---
|
---
|
||||||
|
|
@ -72,3 +72,23 @@ on.
|
||||||
asking for a proposed pilot workload and U06 touchpoints. This is a
|
asking for a proposed pilot workload and U06 touchpoints. This is a
|
||||||
UX/product agreement across two repos and a pilot workload owner; NetKingdom
|
UX/product agreement across two repos and a pilot workload owner; NetKingdom
|
||||||
cannot decide it unilaterally.
|
cannot decide it unilaterally.
|
||||||
|
|
||||||
|
## Infrastructure review — 2026-09-28
|
||||||
|
|
||||||
|
Build T02 on the already completed USER-WP-0033 and KEY-WP-0035 P06 work.
|
||||||
|
Their September 14 release evidence records optional-after-enrollment policy
|
||||||
|
for `user-engine-portal` and `vergabe-demo-company`, privileged MFA guards,
|
||||||
|
confirmed enrollment/cancellation and old-session checks. Do not rebuild
|
||||||
|
those capabilities or interpret this plan as the first delivery of MFA policy.
|
||||||
|
|
||||||
|
The residual is workload-level interoperability and an accepted pilot journey:
|
||||||
|
agree the pilot owner, reuse U06 recovery, prove no-factor enrollment and
|
||||||
|
return to the protected action, and test stale AAL1, refusal and provider
|
||||||
|
unavailability. Existing scoped policy does not prove arbitrary-client
|
||||||
|
`acr_values` support or acceptance of IAM v0.4. KeyCape owns issuer enforcement;
|
||||||
|
user-engine owns the journey; the workload and flex-auth enforce the issued
|
||||||
|
assurance at the protected action. T02 remains `wait` for that agreement and
|
||||||
|
actual-user acceptance, coordinated with KEY-WP-0034 / USER-WP-0028 /
|
||||||
|
VERGABE-WP-0019, without reopening their completed provider work.
|
||||||
|
|
||||||
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue