Reconcile infrastructure workplans and retire stale flex-auth references

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:03 +02:00
parent 019e8f21a7
commit 9383b94019
12 changed files with 494 additions and 149 deletions

View file

@ -0,0 +1,179 @@
# Open workplans versus infrastructure — 2026-09-28
Reviewed all ten nonterminal root workplans (eight blocked, two backlog).
Initial review result: one finished, one active, six blocked, two backlog.
The follow-through section below records subsequent implementation and statuses.
Existing task IDs
and State Hub UUIDs are preserved. This is a planning reconciliation; no
runtime, credential, policy, DNS or destructive change was performed.
## Evidence boundary
Read-only `kubectl` checks against context `default` found one Ready node at
92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP,
privacyIDEA, user-engine, tenant-engine and audit-core each had one ready
Deployment replica. All six flex-auth consumer Deployments were ready and
contained `--caller-auth-mode enforce`. This is configuration/readiness
proof, not fresh user login, negative authorization or recovery testing.
All eight CNPG clusters reported one instance and one ready instance:
apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db,
target-revenue-pg and user-engine-pg. A healthy single-node cluster does not
prove HA or off-host recovery. No Keycloak Deployment was present.
OpenBao StatefulSet and UI gateway were ready; gateway/API Services were
ClusterIP and the namespace had no Ingress. CoulombCore, retained backup
contents, public DNS withdrawal and browser sessions were not reverified.
Owner receipts below support historical completion, not a fresh execution.
Sibling repositories were inspected as available local checkouts; their state
was not assumed to be a newly fetched remote head.
The State Hub inbox supplied flex-auth's September 27 approval of its reference
cleanup (`77b26d1e-550b-4926-9610-44fc3a566273`); it was marked read. The
human-needed task query returned no NK-/NET-prefixed records. This does not
remove the explicit approval gate written in NK-WP-0022. Topic-wide active
workplans include other repositories and are not the NetKingdom plan inventory.
## Plan dispositions at the initial review
| Plan | Updated state and next acceptance gate |
| --- | --- |
| [0009 tutorials](../workplans/NK-WP-0009-netkingdom-security-pattern-tutorials.md) | Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service. |
| [0011 federation](../workplans/NK-WP-0011-enterprise-federation-saml.md) | Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation. |
| [0022 retirement](../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md) | Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval. |
| [0027 reef/posture](../workplans/NK-WP-0027-reef-placement-reconciliation.md) | Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved. |
| [0031 freshness](../workplans/NK-WP-0031-deterministic-posture-feedback.md) | Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence. |
| [0032 Bao callback](../workplans/NK-WP-0032-openbao-operator-loopback-callback.md) | Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical. |
| [0035 cadence](../workplans/NK-WP-0035-emission-cadence-security-profile.md) | Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility. |
| [0039 rename/reference](../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md) | Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates. |
| [0040 execution receipt](../workplans/NK-WP-0040-execution-attribution-receipt.md) | Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds. |
| [0042 step-up](../workplans/NK-WP-0042-workload-mfa-step-up.md) | Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey. |
The two oldest plans now have one task per second-level section, conforming to
the file-backed workplan format. Completed implementation tasks were not
reopened merely because their historical validation dates are old.
## Necessary changes and conflicts
1. **Stale deployment copies can remove a live security control.**
`sso-mfa/k8s/tenant-engine/runtime.yaml` lacks live caller enforcement and
other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to its
`values/<consumer>.yaml`; tenant-engine's portion remains separately owned.
Repository rename does not rename the runtime, token audience or OCI package.
Source: [FLEX-WP-0020](../../flex-auth/workplans/FLEX-WP-0020-repository-identity-migration.md)
(locate by workplan ID if the owner filename changes), inbox receipt above.
2. **Recovery claims must follow the actual failure domain.** Reef declarations
still omit provider ceilings; one node and single-instance databases cannot
establish independent failover. Proposed V0/V1 carrier semantics require
owner agreement and workload evidence. A platform database drill does not
satisfy full identity restoration for destructive retirement.
Sources: [reef declaration](../../reef-railiance/declarations/reef.yaml),
[provider proposal](../docs/reef-posture-provider-contract.md).
3. **Declared evidence remains behind runtime improvements.** Audit Core's
tenancy file still describes flex-auth as unauthenticated A0, despite the
observed enforcement flags. Its E2 review metadata is unstructured and old.
Have the owner reconcile this; do not infer A/E upgrades from flags or tests.
Source: [audit tenancy](../../audit-core/tenancy.yaml).
4. **Generic cadence validity is not profile compliance or observation.**
Approval Engine and Qonto still fail the owner schema. Local-identity passes
that schema but fails the rare-class heartbeat obligation when its source
inventory is explicitly supplied. Audit Core holds no local-identity feed.
Upstream corrected its candidate bundle digest; profile and declaration
metadata need reconciliation without changing historical findings.
Sources: [local findings](../local-identity/emission-cadence-findings.md),
[upstream review](../../info-tech-canon/feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md).
5. **Existing MFA work and proposed generic step-up are different scopes.**
P06 already delivered optional policies for two clients, enrollment checks
and privileged guards. IAM v0.4 remains proposed; it is not evidence of
arbitrary workload step-up support. Reuse the implementation and close the
pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and
[P06 evidence](../../user-engine/docs/evidence/2026-09-13-p06-authentication-policy.md).
6. **Public Bao is retired.** September 24 removed public role callbacks;
current client source rejects their return. Do not repeat completed login
admission or preserve public URLs as a future default. DNS withdrawal is a
railiance-infra residual. Sources:
[callback receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json),
[login/retraction receipt](../../railiance-platform/docs/evidence/2026-09-15-openbao-public-listener-retract.json),
[callback pruning](../../railiance-platform/docs/evidence/2026-09-24-platform-admin-callback-prune.json),
[platform closure](../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md).
7. **Accepted canon and proposals must stay distinct.** IAM v0.3, Playbook
Capability v0.1 and security layer v0.7 remain the accepted baselines;
proposed amendments do not authorize runtime implementation or replace
owner agreement. New federation work must follow ADR-0015 packaging and
current tenant identity contracts, not the original greenfield assumptions.
## Most valuable future implementation
Recommended order; this is prioritization, not approval of deployment or deletion.
1. **Remove stale reference authority (0039).** Small, locally actionable work
that prevents a caller-auth regression. Replace the approved flex-auth
objects with exact owner pointers; finish tenant-engine's portion after its
answer. No rollout is needed.
2. **Close one real workload MFA journey (0042).** High user value with existing
provider work available. Pick a pilot with its owner, demonstrate enrollment,
return to action, recovery and denial with stale/insufficient assurance.
Coordinate existing actual-user gates rather than create another onboarding
implementation.
3. **Make evidence freshness and emission operational (0031 + 0035).** Add
authoritative metadata first, then migrate a source already sending to
Audit Core and prove heartbeat/reconciliation through its observer. This
makes missing or stale security evidence detectable. Resolve local-identity
activity-scope incompatibility explicitly; do not force a bootstrap tool
into a permanent service just to pass the profile.
4. **Bind a real execution to evidence (0040).** Agree the receipt and implement
one Railiance emitter/receiver integration with actor, artifact, decision,
approval and bounded time. This unblocks clock attribution and gives more
value than a schema-only finish.
5. **Mechanize recovery ceilings and finish retirement safely (0027 + 0022).**
Agree reef provider declarations, implement the three-valued join, and use
measured recovery evidence. Prepare the exact old identity deletion package
only after its recovery gate passes; approval remains a separate final step.
Tutorials should capture these proven paths incrementally. Enterprise
federation is lower priority until a concrete tenant/IdP demand justifies its
additional issuer, trust mapping, database and recovery burden.
## Validation
- Current read-only node, Deployment, CNPG and OpenBao resource inventories.
- Existing cadence checker against the current owner schema: Approval Engine
fails with three generic findings; Qonto fails with five. Local-identity is
generic-valid; supplying both documented load-bearing/rare classes yields
two `rare-heartbeat-missing` failures. Omitting inventory flags checks no
rare-class obligations and must not be used to claim adoption.
- Existing posture evaluator at explicit `2026-09-28T12:00:00Z` confirms
unknown owner/freshness and overdue review for audit-core. This is a chosen
reproducible evaluation instant, not the observation timestamp.
- Workplan frontmatter, task-ID preservation, task statuses and local Markdown
links checked; authored files pass `git diff --check`. The generated brief
retains its generator's Markdown hard-break whitespace. No application code changed.
State Hub lifecycle reconciliation classifies partially completed 0039 with an
actionable task as `active`; its file follows that convention. Existing
NK-WP/NET-WP prefix warnings are retained rather than renumbering historical
work records. At the initial review, repository instructions contained conflicting prefix
conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while
preserving historical IDs.
## Follow-through — 2026-09-28
After the user requested implementation, the approved part of NK-WP-0039-T04
was completed: seven obsolete flex-auth objects were removed from the combined
reference manifest and replaced with owner links in
[sso-mfa/k8s/tenant-engine/README.md](../sso-mfa/k8s/tenant-engine/README.md).
Parsed before/after YAML confirms all five tenant-engine objects are unchanged.
No repository apply path consumes the combined manifest; the user-engine
verifier uses its own file. Owner values enforce caller authentication and
bind each consumer to its own ServiceAccount. The remaining YAML stays
DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still
waits for the rename. This returns 0039 to blocked: the current disposition
of the original ten is one finished, seven blocked and two backlog.
The locally owned portion of NK-WP-0035-T04 also advanced: corrected the
profile's imported document maturity/version/revision and the local-identity
candidate bundle pin. The old pin and its correction remain in historical
findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass;
explicit rare-class revalidation remains generic-valid with exactly two
missing-heartbeat failures. The profile stays proposed and source/observer
adoption remains open. No runtime or external-owner source was changed.

View file

@ -0,0 +1,31 @@
# Tenant Engine integration references
`runtime.yaml` is **REFERENCE ONLY — DO NOT APPLY**. Its five remaining
Tenant Engine objects are historical and differ from the live deployment in
image, storage, strategy, environment and egress. Their disposition awaits the
Tenant Engine owner under
[NK-WP-0039-T04](../../../workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md).
The obsolete flex-auth objects were removed on 2026-09-28 with the owner's
agreement. Use the owner's maintained declarations and deployment procedure:
| Consumer | Authoritative values in the flex-auth repository |
| --- | --- |
| Tenant Engine | [values/tenant-engine.yaml](../../../../flex-auth/values/tenant-engine.yaml) |
| User Engine | [values/user-engine.yaml](../../../../flex-auth/values/user-engine.yaml) |
The [owner Helm chart](../../../../flex-auth/charts/flex-auth) renders the
consumer Deployment, Service and NetworkPolicy, including caller-auth
configuration. Both reviewed value files select enforcement and bind the
consumer to its own Kubernetes ServiceAccount. Keep those settings at their
owner; do not recreate a frozen deployment copy here.
These links assume sibling checkouts. The current repository coordinate is
`coulomb/flex-auth`; its proposed rename to `coulomb/access-engine` remains
gated by FLEX-WP-0020. NK-WP-0039-T03 will update these repository pointers
when the owner confirms the new coordinate. The `flex-auth` namespace,
Service DNS, caller-token audience and OCI package coordinate remain unchanged.
Ownership follows [ADR-0015](../../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md).
Removing references requires no cluster apply or rollout. Do not use the
remaining YAML as a way to provision the two flex-auth consumers.

View file

@ -1,68 +1,16 @@
# REFERENCE ONLY - DO NOT APPLY. Not the runtime source of truth (ADR-0015). # REFERENCE ONLY - DO NOT APPLY. Not the runtime source of truth (ADR-0015).
# flex-auth-* Deployments are owned by flex-auth (values/<consumer>.yaml) and # Only historical tenant-engine objects remain, pending its owner's disposition.
# tenant-engine by its own repository. Live differs from this file beyond the # Live tenant-engine differs in image, storage, strategy, environment and egress.
# flex-auth image digests (caller-auth enforce args, tenant-engine image, PVC, # The obsolete flex-auth objects were removed under NK-WP-0039-T04.
# strategy, egress). Applying it would drop caller-auth enforcement. NK-WP-0039. # Authoritative flex-auth declarations (repository: coulomb/flex-auth):
apiVersion: v1 # values/tenant-engine.yaml
kind: Namespace # values/user-engine.yaml
metadata: {name: flex-auth, labels: {net-kingdom/component: flex-auth}} # Rendered by that repository's charts/flex-auth, including caller enforcement.
--- # See README.md for owner links, retained runtime names and the remaining gate.
apiVersion: v1 apiVersion: v1
kind: Namespace kind: Namespace
metadata: {name: tenant-engine, labels: {net-kingdom/component: tenant-engine}} metadata: {name: tenant-engine, labels: {net-kingdom/component: tenant-engine}}
--- ---
apiVersion: apps/v1
kind: Deployment
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
spec:
replicas: 1
selector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
template:
metadata: {labels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
spec:
automountServiceAccountToken: false
securityContext: {runAsNonRoot: true, seccompProfile: {type: RuntimeDefault}}
containers:
- name: flex-auth
image: forgejo.coulomb.social/coulomb/flex-auth@sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd
args: ["serve", "--addr", "0.0.0.0:8080", "--registry", "/opt/flex-auth/examples/tenant-engine/registry_snapshot.json", "--policy", "/opt/flex-auth/examples/tenant-engine/policy_package.md"]
ports: [{name: http, containerPort: 8080}]
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
resources: {requests: {cpu: 25m, memory: 32Mi}, limits: {cpu: 300m, memory: 192Mi}}
readinessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 5}
livenessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 20}
---
apiVersion: v1
kind: Service
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
spec: {selector: {app.kubernetes.io/name: flex-auth-tenant-engine}, ports: [{name: http, port: 8080, targetPort: http}]}
---
apiVersion: apps/v1
kind: Deployment
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
spec:
replicas: 1
selector: {matchLabels: {app.kubernetes.io/name: flex-auth-user-engine}}
template:
metadata: {labels: {app.kubernetes.io/name: flex-auth-user-engine}}
spec:
automountServiceAccountToken: false
securityContext: {runAsNonRoot: true, seccompProfile: {type: RuntimeDefault}}
containers:
- name: flex-auth
image: forgejo.coulomb.social/coulomb/flex-auth@sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b
args: ["serve", "--addr", "0.0.0.0:8080", "--registry", "/opt/flex-auth/examples/user-engine/registry_snapshot.json", "--policy", "/opt/flex-auth/examples/user-engine/policy_package.md"]
ports: [{name: http, containerPort: 8080}]
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
resources: {requests: {cpu: 25m, memory: 32Mi}, limits: {cpu: 300m, memory: 192Mi}}
readinessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 5}
livenessProbe: {httpGet: {path: /healthz, port: http}, periodSeconds: 20}
---
apiVersion: v1
kind: Service
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
spec: {selector: {app.kubernetes.io/name: flex-auth-user-engine}, ports: [{name: http, port: 8080, targetPort: http}]}
---
apiVersion: v1 apiVersion: v1
kind: PersistentVolumeClaim kind: PersistentVolumeClaim
metadata: {name: tenant-engine-data, namespace: tenant-engine} metadata: {name: tenant-engine-data, namespace: tenant-engine}
@ -101,32 +49,6 @@ spec: {selector: {app.kubernetes.io/name: tenant-engine}, ports: [{name: http, p
--- ---
apiVersion: networking.k8s.io/v1 apiVersion: networking.k8s.io/v1
kind: NetworkPolicy kind: NetworkPolicy
metadata: {name: flex-auth-tenant-engine, namespace: flex-auth}
spec:
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
policyTypes: [Ingress, Egress]
ingress:
- from:
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: tenant-engine}}
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
ports: [{protocol: TCP, port: 8080}]
egress: []
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata: {name: flex-auth-user-engine, namespace: flex-auth}
spec:
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-user-engine}}
policyTypes: [Ingress, Egress]
ingress:
- from:
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: user-engine}}
podSelector: {matchLabels: {app.kubernetes.io/name: user-engine}}
ports: [{protocol: TCP, port: 8080}]
egress: []
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata: {name: tenant-engine, namespace: tenant-engine} metadata: {name: tenant-engine, namespace: tenant-engine}
spec: spec:
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}} podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}

View file

@ -11,7 +11,7 @@ topic_slug: netkingdom
planning_priority: medium planning_priority: medium
planning_order: 9 planning_order: 9
created: 2026-05-17 created: 2026-05-17
updated: 2026-07-08 updated: "2026-09-28"
depends_on: depends_on:
- NK-WP-0008 - NK-WP-0008
state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e" state_hub_workstream_id: "d4d02dbf-3974-502d-8b87-b776fc63e17e"
@ -64,7 +64,7 @@ Out of scope:
- hiding provider-specific security differences behind one generic - hiding provider-specific security differences behind one generic
command command
## Tasks ## Create the tutorial template
```task ```task
id: NK-WP-0009-T01 id: NK-WP-0009-T01
@ -77,6 +77,8 @@ Create a tutorial template with prerequisites, architecture context,
commands, manifests, verification, rollback, threat checks, and commands, manifests, verification, rollback, threat checks, and
cross-repo ownership notes. cross-repo ownership notes.
## Demonstrate temporary object credentials
```task ```task
id: NK-WP-0009-T02 id: NK-WP-0009-T02
status: todo status: todo
@ -89,6 +91,8 @@ NetKingdom identity token", covering key-cape/Keycloak identity,
flex-auth authorization, object-store STS exchange, and SDK consumer flex-auth authorization, object-store STS exchange, and SDK consumer
configuration. configuration.
## Document the existing OpenBao operating path
```task ```task
id: NK-WP-0009-T03 id: NK-WP-0009-T03
status: todo status: todo
@ -101,6 +105,8 @@ NetKingdom-enabled Railiance platform", linking to the Railiance
Platform workplan and covering auth methods, secret engines, CSI/ESO Platform workplan and covering auth methods, secret engines, CSI/ESO
integration, leases, unseal, backup, and break-glass. integration, leases, unseal, backup, and break-glass.
## Document SSH certificates and tunnels
```task ```task
id: NK-WP-0009-T04 id: NK-WP-0009-T04
status: todo status: todo
@ -112,6 +118,8 @@ Write "Use short-lived SSH credentials for admins, agents, and
automations", using ops-warden and ops-bridge as the reference automations", using ops-warden and ops-bridge as the reference
implementation. implementation.
## Integrate a protected flex-auth consumer
```task ```task
id: NK-WP-0009-T05 id: NK-WP-0009-T05
status: todo status: todo
@ -123,6 +131,8 @@ Write "Add a protected system to flex-auth", covering resource
manifests, action vocabulary, claim envelopes, policy packages, manifests, action vocabulary, claim envelopes, policy packages,
decision envelopes, and delegated PDP options. decision envelopes, and delegated PDP options.
## Verify the tutorial outcomes
```task ```task
id: NK-WP-0009-T06 id: NK-WP-0009-T06
status: todo status: todo
@ -142,3 +152,22 @@ clear "done when" outcome and does not become prose-only guidance.
step. step.
- Tutorials include verification and rollback guidance, not just happy - Tutorials include verification and rollback guidance, not just happy
path commands. path commands.
## Infrastructure review — 2026-09-28
Keep this plan in backlog, with the first implementation slice T01 + T03 +
T04 + T06: document the paths already operated and capture safe verification
and recovery outcomes. OpenBao is already deployed and private; T03 should
teach consumption, attended access and recovery, with greenfield deployment
kept as an isolated lab exercise. Use the named `openbao-ui-railiance01`
tunnel and owner runbooks, not a public Bao URL or copied runtime manifest.
T02 is conditional on an owner-backed object-store STS issuer and refusal/lease
proof; ADR-0008 is architecture, not evidence that the endpoint is live. T05
must include projected caller identity, audience, binding and unauthorized
caller rejection: all six live consumers now enforce caller authentication.
Use accepted IAM v0.3 and owner package declarations under ADR-0015. T06
requires executable safe fixtures or repeatable outcome checks; never teach
operators to apply the stale tenant-engine reference YAML.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: worsch owner: worsch
topic_slug: netkingdom topic_slug: netkingdom
created: "2026-05-20" created: "2026-05-20"
updated: "2026-07-08" updated: "2026-09-28"
state_hub_workstream_id: "1075448f-d533-5f9e-94b7-c3adfe151a07" state_hub_workstream_id: "1075448f-d533-5f9e-94b7-c3adfe151a07"
depends_on: depends_on:
- NK-WP-0003 - NK-WP-0003
@ -53,10 +53,10 @@ Keycloak as the internal user store. None of those assumptions hold now:
| NK-WP-0001 assumption | Current reality | Effect on this plan | | NK-WP-0001 assumption | Current reality | Effect on this plan |
|---|---|---| |---|---|---|
| HashiCorp Vault, bootstrapped from KeePassXC | **OpenBao** is the runtime secret authority (NK-WP-0006); SOPS/age + agent bootstrap exist (NK-WP-0004/0005) | Keycloak DB + admin secrets come from OpenBao via ESO; no new vault bootstrap | | HashiCorp Vault, bootstrapped from KeePassXC | **OpenBao** is the runtime secret authority (NK-WP-0006); SOPS/age + agent bootstrap exist (NK-WP-0004/0005) | Keycloak DB + admin secrets come from OpenBao via ESO; no new vault bootstrap |
| PostgreSQL built from scratch | CloudNativePG running on RAILIANCE01 (NK-WP-0003) | Add `keycloak_db` to the existing operator, reuse backup pattern | | PostgreSQL built from scratch | CloudNativePG running on RAILIANCE01 (NK-WP-0003) | Admit a database consumer through current platform owners; prove backup/restore |
| Keycloak is the internal source of truth (D2 hybrid) | KeyCape lightweight stack is the *deployed* IAM Profile issuer | Keycloak is a **broker/federation front-end**, not the primary user store | | Keycloak is the internal source of truth (D2 hybrid) | KeyCape lightweight stack is the *deployed* IAM Profile issuer | Keycloak is a **broker/federation front-end**, not the primary user store |
| Authorization via Keycloak Authorization Services | flex-auth + Topaz is the canonical PDP (ADR-0006) | Keycloak AuthZ Services is at most an optional adapter, never canonical | | Authorization via Keycloak Authorization Services | flex-auth + Topaz is the canonical PDP (ADR-0006) | Keycloak AuthZ Services is at most an optional adapter, never canonical |
| Single-tenant Coulomb deployment | Recursive `tenant:platform` vs `tenant:coulomb` model (NK-WP-0006) | Realm-per-tenant; tenant admins must not receive platform-root | | Single-tenant Coulomb deployment | Recursive `tenant:platform` vs `tenant:coulomb` model (NK-WP-0006) | Evaluate realm-per-tenant; tenant admins must not receive platform-root |
| MFA solely via privacyIDEA provider JAR | privacyIDEA deployed *and* upstream IdPs carry their own MFA | MFA assurance source becomes a decision, not a default | | MFA solely via privacyIDEA provider JAR | privacyIDEA deployed *and* upstream IdPs carry their own MFA | MFA assurance source becomes a decision, not a default |
## Architecture ## Architecture
@ -68,7 +68,7 @@ Keycloak as the internal user store. None of those assumptions hold now:
└──────────────┼──────────────┘ └──────────────┼──────────────┘
▼ ▼
[ Keycloak ] expanded-mode broker [ Keycloak ] expanded-mode broker
│ realm-per-tenant; IAM Profile issuer │ realm-per-tenant candidate; IAM Profile issuer
│ secrets ← OpenBao (ESO) │ secrets ← OpenBao (ESO)
│ MFA ← privacyIDEA *or* upstream assurance │ MFA ← privacyIDEA *or* upstream assurance
▼ ▼
@ -77,7 +77,7 @@ Keycloak as the internal user store. None of those assumptions hold now:
├──► applications (depend on the Profile, not the provider) ├──► applications (depend on the Profile, not the provider)
└──► flex-auth / Topaz ── authorization decision (PDP) └──► flex-auth / Topaz ── authorization decision (PDP)
coexists with: KeyCape lightweight issuer (id.coulomb.social) coexists with: KeyCape lightweight issuer (kc.coulomb.social)
``` ```
Keycloak answers identity (who, how authenticated, coarse claims, Keycloak answers identity (who, how authenticated, coarse claims,
@ -90,10 +90,10 @@ OpenBao.
In scope: In scope:
- decision record for expanded-mode adoption: trigger, federation - decision record for expanded-mode adoption: trigger, federation
topology (broker vs SAML SP), realm-per-tenant model, and coexistence topology (broker vs SAML SP), realm isolation model, and coexistence
with the KeyCape lightweight issuer with the KeyCape lightweight issuer
- custom Keycloak image (privacyIDEA provider JAR if MFA is delegated to - owner-packaged Keycloak image (privacyIDEA provider JAR only if selected
privacyIDEA) and Helm deployment on RAILIANCE01 and verified compatible) and managed deployment on railiance01
- upstream federation: Entra ID (OIDC), AD (LDAP), generic SAML 2.0 IdP - upstream federation: Entra ID (OIDC), AD (LDAP), generic SAML 2.0 IdP
- claim mapping to the NetKingdom IAM Profile (issuer, audience, subject, - claim mapping to the NetKingdom IAM Profile (issuer, audience, subject,
groups, tenant, assurance evidence) and IAM Profile conformance checks groups, tenant, assurance evidence) and IAM Profile conformance checks
@ -112,7 +112,7 @@ Out of scope:
- tenant-specific federation policy for tenants beyond `tenant:platform` - tenant-specific federation policy for tenants beyond `tenant:platform`
and `tenant:coulomb` and `tenant:coulomb`
## Tasks ## Decide federation adoption and topology
```task ```task
id: NK-WP-0011-T01 id: NK-WP-0011-T01
@ -125,11 +125,14 @@ priority: high
an ADR (ADR-0009) capturing: the concrete trigger for switching a tenant an ADR (ADR-0009) capturing: the concrete trigger for switching a tenant
from lightweight to expanded mode; whether Keycloak acts as an OIDC from lightweight to expanded mode; whether Keycloak acts as an OIDC
identity broker, a SAML service provider, or both; the realm-per-tenant identity broker, a SAML service provider, or both; the realm-per-tenant
mapping onto `tenant:platform` / `tenant:coulomb`; how the Keycloak issuer candidate and its alternatives mapped onto `tenant:platform` /
coexists with the KeyCape issuer (`id.coulomb.social`) so applications `tenant:coulomb`; how the Keycloak issuer
coexists with the KeyCape issuer (`kc.coulomb.social`) so applications
still target one IAM Profile contract; and the canonical hostname/issuer still target one IAM Profile contract; and the canonical hostname/issuer
for the broker. Resolve or supersede D2 from NK-WP-0001. for the broker. Resolve or supersede D2 from NK-WP-0001.
## Admit the database consumer
```task ```task
id: NK-WP-0011-T02 id: NK-WP-0011-T02
state_hub_task_id: "2fe6f100-3a5d-563e-b033-7d7b846ae487" state_hub_task_id: "2fe6f100-3a5d-563e-b033-7d7b846ae487"
@ -137,12 +140,15 @@ status: todo
priority: high priority: high
``` ```
**PostgreSQL `keycloak_db` on the existing operator.** Add a `keycloak` **PostgreSQL `keycloak_db` on the existing operator.** Have railiance-platform
database and role to the CloudNativePG instance from NK-WP-0003 (do not and rapp-postgres admit a named Keycloak database consumer against the current
deploy a new database). Source credentials from OpenBao via ESO into a K8s database catalog and isolation needs. Do not assume the historical NK-WP-0003
Secret. Confirm the existing backup schedule covers the new database and instance is the correct placement. Source credentials from OpenBao via ESO
into a K8s Secret. Confirm the existing backup schedule covers the new database and
run a restore drill for `keycloak_db` specifically. run a restore drill for `keycloak_db` specifically.
## Package the broker deployment
```task ```task
id: NK-WP-0011-T03 id: NK-WP-0011-T03
state_hub_task_id: "32d1411b-10a4-5a8b-8f43-99ac46d83908" state_hub_task_id: "32d1411b-10a4-5a8b-8f43-99ac46d83908"
@ -152,12 +158,15 @@ priority: high
**Deploy expanded-mode Keycloak.** Build a custom image **Deploy expanded-mode Keycloak.** Build a custom image
(`kc.sh build`, privacyIDEA provider JAR included only if T5 delegates MFA (`kc.sh build`, privacyIDEA provider JAR included only if T5 delegates MFA
to privacyIDEA). Deploy via plain Helm on RAILIANCE01 behind Traefik + to privacyIDEA). Assign the package/runtime owner under ADR-0015 and deploy
through its managed declaration on railiance01 behind Traefik +
cert-manager at the issuer hostname from T1. Admin bootstrap secret and DB cert-manager at the issuer hostname from T1. Admin bootstrap secret and DB
secret come from OpenBao/ESO — never typed, never in git. Hostname secret come from OpenBao/ESO — never typed, never in git. Hostname
strictness + proxy headers configured for Traefik. Realm import is strictness + proxy headers configured for Traefik. Realm import is
GitOps-friendly (realm JSON/CR in git). GitOps-friendly (realm JSON/CR in git).
## Integrate an upstream identity provider
```task ```task
id: NK-WP-0011-T04 id: NK-WP-0011-T04
state_hub_task_id: "6697a994-7343-5ea8-8b37-bc3b921e5a9b" state_hub_task_id: "6697a994-7343-5ea8-8b37-bc3b921e5a9b"
@ -172,6 +181,8 @@ audience, subject, groups, **tenant**, and assurance evidence. Define the
attribute/claim mappers and group→role mapping. Verify a federated login attribute/claim mappers and group→role mapping. Verify a federated login
end-to-end for at least the Entra ID path. end-to-end for at least the Entra ID path.
## Define federated assurance
```task ```task
id: NK-WP-0011-T05 id: NK-WP-0011-T05
state_hub_task_id: "d845380d-3dbc-5e59-8f2b-5a4d1b32d89d" state_hub_task_id: "d845380d-3dbc-5e59-8f2b-5a4d1b32d89d"
@ -187,6 +198,8 @@ evidence in the token. Require step-up for admin console and
platform-root-sensitive clients. Ensure assurance evidence is carried in platform-root-sensitive clients. Ensure assurance evidence is carried in
the IAM Profile token so flex-auth can gate privileged actions on it. the IAM Profile token so flex-auth can gate privileged actions on it.
## Verify IAM conformance and coexistence
```task ```task
id: NK-WP-0011-T06 id: NK-WP-0011-T06
state_hub_task_id: "9cb7fd93-c16e-5102-83ce-195b3aa87446" state_hub_task_id: "9cb7fd93-c16e-5102-83ce-195b3aa87446"
@ -199,9 +212,11 @@ conformance checks against the Keycloak issuer (discovery document, PKCE,
token/claim shape, JWKS, userinfo). Verify an application configured for token/claim shape, JWKS, userinfo). Verify an application configured for
the IAM Profile can authenticate against either the KeyCape or the the IAM Profile can authenticate against either the KeyCape or the
Keycloak issuer per the T1 selection rule. Use the canonical Keycloak issuer per the T1 selection rule. Use the canonical
`canon/standards/iam-profile_v0.2.md` contract and the executable suite in `canon/standards/iam-profile_v0.3.md` contract and the executable suite in
`tools/iam-profile-conformance/`. Document per-tenant issuer selection. `tools/iam-profile-conformance/`. Document per-tenant issuer selection.
## Enforce tenant and platform boundaries
```task ```task
id: NK-WP-0011-T07 id: NK-WP-0011-T07
state_hub_task_id: "38998c68-29bf-50d2-8c8d-0c75184d5833" state_hub_task_id: "38998c68-29bf-50d2-8c8d-0c75184d5833"
@ -209,14 +224,17 @@ status: todo
priority: high priority: high
``` ```
**Recursive tenancy & authorization boundary.** Implement realm-per-tenant **Recursive tenancy & authorization boundary.** Implement T1's reviewed
with platform-root guardrails: tenant admins manage only their realm and realm/tenant topology with platform-root guardrails. If realm-per-tenant is
selected, tenant admins manage only their realm; in every topology they
must not be able to alter IAM Profile semantics, the platform realm, must not be able to alter IAM Profile semantics, the platform realm,
federation trust, OpenBao platform mounts, or audit retention (per the federation trust, OpenBao platform mounts, or audit retention (per the
flex-auth/Topaz implications in the architecture doc). Confirm flex-auth + flex-auth/Topaz implications in the architecture doc). Confirm flex-auth +
Topaz remains the PDP; if a Keycloak Authorization Services adapter is Topaz remains the PDP; if a Keycloak Authorization Services adapter is
used at all, document it as a delegated, non-canonical adapter. used at all, document it as a delegated, non-canonical adapter.
## Prove recovery and audit delivery
```task ```task
id: NK-WP-0011-T08 id: NK-WP-0011-T08
state_hub_task_id: "e5f44ddc-9645-5f61-b84c-da5ab9cccb6d" state_hub_task_id: "e5f44ddc-9645-5f61-b84c-da5ab9cccb6d"
@ -224,8 +242,9 @@ status: todo
priority: medium priority: medium
``` ```
**Backups, DR, break-glass, monitoring, audit.** Realm exports to git; DB **Backups, DR, break-glass, monitoring, audit.** Only sanitized declarative
backup + restore drill (T2); break-glass admin path disabled-by-default realm configuration belongs in git; keep credential-bearing exports in
protected backup custody; DB backup + restore drill (T2); break-glass admin path disabled-by-default
with alerting on use; Prometheus/Grafana for auth success/failure, MFA with alerting on use; Prometheus/Grafana for auth success/failure, MFA
latency, federation errors. Ship Keycloak events to the durable platform latency, federation errors. Ship Keycloak events to the durable platform
audit sink alongside flex-auth/Topaz/OpenBao records, with correlation audit sink alongside flex-auth/Topaz/OpenBao records, with correlation
@ -235,7 +254,7 @@ production-readiness checklist.
## Acceptance Criteria ## Acceptance Criteria
- An ADR records the expanded-mode trigger, federation topology, - An ADR records the expanded-mode trigger, federation topology,
realm-per-tenant model, and KeyCape/Keycloak issuer coexistence. selected realm/tenant isolation model, and KeyCape/Keycloak issuer coexistence.
- A federated user from at least one enterprise IdP (Entra ID) can log in - A federated user from at least one enterprise IdP (Entra ID) can log in
and receive an IAM Profile-conformant token with tenant + assurance and receive an IAM Profile-conformant token with tenant + assurance
claims. claims.
@ -257,5 +276,25 @@ production-readiness checklist.
- **railiance-platform**: OpenBao must expose a Keycloak auth role / ESO - **railiance-platform**: OpenBao must expose a Keycloak auth role / ESO
path before T3; unseal/break-glass story must be ready. path before T3; unseal/break-glass story must be ready.
- **IAM Profile spec**: resolved by NK-WP-0012. T6 consumes - **IAM Profile spec**: resolved by NK-WP-0012. T6 consumes
`canon/standards/iam-profile_v0.2.md` and `canon/standards/iam-profile_v0.3.md` and
`tools/iam-profile-conformance/`. `tools/iam-profile-conformance/`.
## Infrastructure review — 2026-09-28
Keep in backlog until a named enterprise tenant, upstream IdP owner and
concrete federation need justify operating another issuer. No Keycloak
Deployment appears in today's cluster inventory. Realm-per-tenant remains a
proposal to evaluate in T01, not a requirement derived from current topology;
prove its mapping to tenant-engine's canonical identity/lifecycle contract.
The live issuer is `https://kc.coulomb.social`; IAM v0.3 is accepted and v0.4
step-up is proposed. T01/T05/T06 must coordinate with NK-WP-0042 and preserve
existing issuer/subject account bindings, audiences and session/revocation
behavior. Do not infer equivalent assurance from an upstream MFA claim without
a reviewed trust mapping. The single-node cluster and single-instance database
providers offer no automatic HA guarantee. T02/T08 must name backup ownership,
off-host custody and an isolated restore proof. OpenBao access is private via
the platform operator path. Resource placement, packaging and runtime
execution belong to their owners, not this canon repository.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex owner: codex
topic_slug: netkingdom topic_slug: netkingdom
created: "2026-07-27" created: "2026-07-27"
updated: "2026-08-08" updated: "2026-09-28"
depends_on: depends_on:
- USER-WP-0020 - USER-WP-0020
- NK-WP-0023 - NK-WP-0023
@ -24,16 +24,18 @@ CoulombCore (`92.205.130.254`) to railiance01 (`92.205.62.239`) without
losing users, groups, MFA enrollments, signing/encryption material, or the losing users, groups, MFA enrollments, signing/encryption material, or the
ability to roll back. ability to roll back.
The two servers currently run independent copies of KeyCape, Authelia, LLDAP, At the July 27 migration baseline, the two servers ran independent copies of
privacyIDEA, and `net-kingdom-pg`. Public KeyCape DNS already points to KeyCape, Authelia, LLDAP,
railiance01, while Authelia, LLDAP, and privacyIDEA DNS still points to privacyIDEA, and `net-kingdom-pg`. At that baseline, public KeyCape DNS pointed to
CoulombCore. Retirement is forbidden until state equivalence, end-to-end railiance01 while other identity names still pointed to CoulombCore.
login, backup restoration, and an observed rollback window pass. T06/T07 below supersede that topology: identity cutover and reversible
retirement completed on July 30 after the recorded migration gates passed.
Final deletion still requires the separate T08 recovery and approval gates.
This cutover intentionally waits until the reusable user onboarding portal The original cutover intentionally waited for the reusable user onboarding
completes the Binky tenant-admin flow. That supplies the human login/MFA and portal to complete the Binky tenant-admin flow. That supplied the human
lifecycle evidence needed to judge which identity stack is authoritative login/MFA and lifecycle evidence used to establish identity authority before
before state migration or retirement begins. state migration and reversible retirement.
## T01 - Freeze the migration contract and inventory both stacks ## T01 - Freeze the migration contract and inventory both stacks
@ -313,11 +315,12 @@ runbooks. Run `statehub fix-consistency`.
Done when railiance01 is the sole authoritative identity stack, all evidence Done when railiance01 is the sole authoritative identity stack, all evidence
is reconciled, and the workplan is marked finished. is reconciled, and the workplan is marked finished.
Retention gate: keep the reversible CoulombCore identity resources through at Retention minimum: 2026-08-29 has passed. The plan is no longer date-blocked.
least 2026-08-29. The workplan is blocked until that review date, when T08 can T08 remains blocked on a scoped retained-resource inventory, a successful
be checked for readiness to finish. Reaching the date does not authorize identity restore/restart receipt, and explicit destructive approval.
deletion or completion: T08 still requires a successful railiance01 Elapsed retention alone does not authorize deletion or completion: T08 still
restore/restart drill and new explicit approval for destructive deletion. requires a successful railiance01 restore/restart drill and new explicit
approval for destructive deletion.
## Safety gates ## Safety gates
@ -328,3 +331,15 @@ restore/restart drill and new explicit approval for destructive deletion.
- No PVC/database/Secret deletion as part of the reversible retirement step. - No PVC/database/Secret deletion as part of the reversible retirement step.
- Final deletion always requires an explicit human approval distinct from DNS - Final deletion always requires an explicit human approval distinct from DNS
cutover approval. cutover approval.
## Infrastructure review — 2026-09-28
Live read-only inventory confirms the identity services on railiance01 are
ready. CoulombCore was not inspected in this review; do not infer that its
retained resources have been deleted. Recheck the exact retained identity
resources and backup custody before preparing the T08 deletion list. A generic
platform-pg recovery drill is not a restore of LLDAP, Authelia, privacyIDEA
with its encryption material, and identity database state. Whole-host retirement
and other owners' workloads remain outside this identity-only deletion gate.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -10,7 +10,7 @@ owner: net-kingdom
topic_slug: netkingdom topic_slug: netkingdom
planning_priority: P1 planning_priority: P1
created: "2026-08-19" created: "2026-08-19"
updated: "2026-08-22" updated: "2026-09-28"
state_hub_workstream_id: "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4" state_hub_workstream_id: "965ad365-6b81-50a1-a2a3-2d0c1fcce0b4"
--- ---
@ -250,3 +250,20 @@ ordinary next input.
authoritative workload ids and fail-safe exception evaluation authoritative workload ids and fail-safe exception evaluation
- `docs/reef-posture-provider-contract.md` — concrete T02/T03 carrier and join - `docs/reef-posture-provider-contract.md` — concrete T02/T03 carrier and join
proposal awaiting reef-owner agreement proposal awaiting reef-owner agreement
## Infrastructure review — 2026-09-28
The current `reef-railiance/declarations/reef.yaml` still has no
`posture_provider` block. Its `ownership_repo` is `railiance-infra`: involve
that substrate owner alongside repo-manager (carrier/schema) in T02. The live
cluster has one Ready node; all eight CNPG clusters report one instance. This
supports retaining the single-failure-domain constraint, not assigning a new
V level from replica counts. T02/T03 stay `wait`.
InfoTechCanon Data Model §11.23 explicitly lists `public`; ops-warden
`registry/policy/security-posture.yaml` still has no public maturity floor.
The missing artifact is an owner-agreed mapping separating disclosure class
from synthetic provenance, not proof that public exists. T06 stays `wait`;
no `public -> synthetic` alias or guessed M1 floor is permitted.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -10,7 +10,7 @@ owner: codex
topic_slug: netkingdom topic_slug: netkingdom
planning_priority: P1 planning_priority: P1
created: "2026-08-23" created: "2026-08-23"
updated: "2026-08-23" updated: "2026-09-28"
state_hub_workstream_id: "9d7b04f9-3803-5613-b7a5-8bd606c77f5a" state_hub_workstream_id: "9d7b04f9-3803-5613-b7a5-8bd606c77f5a"
--- ---
@ -116,3 +116,20 @@ Verification on 2026-08-23:
Local implementation is complete. The workplan remains blocked only on T04's Local implementation is complete. The workplan remains blocked only on T04's
externally owned audit-core declaration adoption. externally owned audit-core declaration adoption.
## Infrastructure review — 2026-09-28
`audit-core/tenancy.yaml` still lacks machine-readable authoritative owner
and E2 freshness metadata. Its E2 prose retains the August 22 receipt and
24-hour replacement deadline; report freshness as `unknown` until the required
fields exist, without renewing that evidence from prose. The September 24
receiver/database recreate evidence supports V1 only and cannot refresh E2.
T04 remains `wait`; request the source declaration update and evaluate it with
an explicit current `--as-of` before closure.
The same declaration still describes flex-auth as unauthenticated A0, whereas
today all six live flex-auth Deployments pass `--caller-auth-mode enforce`.
The audit-core owner should reconcile that rationale against actual caller
bindings and policy evidence; deployment flags alone do not prove a new A level.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -4,12 +4,12 @@ type: workplan
title: "Admit the operator-tunneled OpenBao browser callback" title: "Admit the operator-tunneled OpenBao browser callback"
domain: infotech domain: infotech
repo: net-kingdom repo: net-kingdom
status: blocked status: finished
flavor: implementation flavor: implementation
owner: codex owner: codex
topic_slug: net-kingdom topic_slug: net-kingdom
created: "2026-08-23" created: "2026-08-23"
updated: "2026-08-23" updated: "2026-09-28"
related: related:
- RMASTER-WP-0020-T09 - RMASTER-WP-0020-T09
- RAILIANCE-WP-0027-T03 - RAILIANCE-WP-0027-T03
@ -68,7 +68,7 @@ or Secret value was observed.
```task ```task
id: NK-WP-0032-T03 id: NK-WP-0032-T03
status: wait status: done
priority: high priority: high
state_hub_task_id: "73b77110-2d4f-527e-98eb-2ec33897681e" state_hub_task_id: "73b77110-2d4f-527e-98eb-2ec33897681e"
``` ```
@ -82,7 +82,7 @@ query, browser storage, or role response body.
```task ```task
id: NK-WP-0032-T04 id: NK-WP-0032-T04
status: wait status: done
priority: high priority: high
state_hub_task_id: "f62bda4a-7607-5c50-9e04-664cc1b829ac" state_hub_task_id: "f62bda4a-7607-5c50-9e04-664cc1b829ac"
``` ```
@ -91,3 +91,24 @@ After T02 and T03 pass, perform one attended MFA login through
`http://127.0.0.1:18200` and return only the success/failure outcome. This task `http://127.0.0.1:18200` and return only the success/failure outcome. This task
does not authorize public Ingress retraction; Railiance Platform retains that does not authorize public Ingress retraction; Railiance Platform retains that
separate guarded hold point. separate guarded hold point.
## Infrastructure review — 2026-09-28
T03 and T04 are complete from existing owner evidence; no new attended login
or role write is needed for this reconciliation. Railiance Platform
`docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json`
proves the exact callback already present, Warden exit 0 and session revocation.
`docs/evidence/2026-09-15-openbao-public-listener-retract.json` records successful
operator loopback MFA, private HTTP 200, gateway readiness and public Ingress
retraction. `RPF-WP-0025` closure on September 22 records the handoff to
Railiance Master. These receipts discharge the original role and login gates.
Today the gateway and OpenBao are ready, their Services are ClusterIP, and the
openbao namespace has no Ingress. The September 24 callback-prune receipt
retired the public callbacks; current NetKingdom client source also forbids
their return. T01's bounded rollback requirement is historical, not an
instruction to restore public callbacks. DNS withdrawal remains the
railiance-infra owner residual described by RPF-WP-0025; this review does not
claim it is complete or authorize a listener change.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: claude-code owner: claude-code
topic_slug: netkingdom topic_slug: netkingdom
created: "2026-09-23" created: "2026-09-23"
updated: "2026-09-23" updated: "2026-09-28"
related: [FLEX-WP-0020, FLEX-DEC-2026-013, NK-WP-0026] related: [FLEX-WP-0020, FLEX-DEC-2026-013, NK-WP-0026]
state_hub_workstream_id: "284a8ac2-61dc-5bee-b74a-0a62d9808edb" state_hub_workstream_id: "284a8ac2-61dc-5bee-b74a-0a62d9808edb"
--- ---
@ -40,7 +40,7 @@ Read-only check on railiance01 (node `92.205.62.239`) on 2026-09-23. The
`flex-auth-`. Every one pulls `flex-auth-`. Every one pulls
`forgejo.coulomb.social/coulomb/flex-auth@sha256:…`. `forgejo.coulomb.social/coulomb/flex-auth@sha256:…`.
NetKingdom declares two of them in `sso-mfa/k8s/tenant-engine/runtime.yaml` At the September 23 inventory, NetKingdom declared two of them in `sso-mfa/k8s/tenant-engine/runtime.yaml`
(`flex-auth-tenant-engine`, `flex-auth-user-engine`). Everything else under (`flex-auth-tenant-engine`, `flex-auth-user-engine`). Everything else under
`sso-mfa/k8s/**` that names flex-auth is a runtime name that stays: the `sso-mfa/k8s/**` that names flex-auth is a runtime name that stays: the
namespace, Service DNS `flex-auth-user-engine.flex-auth.svc.cluster.local`, namespace, Service DNS `flex-auth-user-engine.flex-auth.svc.cluster.local`,
@ -63,8 +63,8 @@ Resolved 2026-09-23 (flex-auth reply `28d9c6ca`): live is correct. `05a03a87`
was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence
`docs/evidence/2026-09-11-user-portal-tenant-policy.md`); `138aa347` has been `docs/evidence/2026-09-11-user-portal-tenant-policy.md`); `138aa347` has been
live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is
`values/<consumer>.yaml` in flex-auth. `runtime.yaml` now declares the live `values/<consumer>.yaml` in flex-auth. `runtime.yaml` was updated to those live
digests. See T04 for the rest of the drift. digests. T04 later removes the obsolete flex-auth reference objects entirely.
## Confirm the image-pull path survives the rename ## Confirm the image-pull path survives the rename
@ -98,17 +98,16 @@ priority: medium
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402" state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"
``` ```
Once flex-auth announces that `coulomb/access-engine` resolves, update Once flex-auth announces that `coulomb/access-engine` resolves, verify
references to the repository coordinate. If the image coordinate repository-coordinate references against the retained runtime/package contract.
changes, update the two image pins in `sso-mfa/k8s/tenant-engine/runtime.yaml` T02 confirms image coordinates stay unchanged; do not schedule image-pin
in the same change as the digest reconciliation from T01. Applying that live changes or a rollout as part of this rename. Leave historical records intact.
needs the founder's go-ahead. Leave runtime names and historical records
unchanged.
After T02, no in-repo coordinate reference needs to change: the image pins T04 now introduces explicit owner-repository links in
stay, and NK-WP-0026 is a historical record. This task waits only for `sso-mfa/k8s/tenant-engine/README.md` and a repository coordinate in the YAML
flex-auth's announcement that `access-engine` resolves, which confirms that header. After the rename announcement, update these pointers to the confirmed
nothing else moved. new repository/checkout, verify both value-file paths resolve and preserve the
runtime/package names. NK-WP-0026 remains a historical record.
## Retire or reconcile the stale flex-auth/tenant-engine reference manifest ## Retire or reconcile the stale flex-auth/tenant-engine reference manifest
@ -119,7 +118,7 @@ priority: high
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3" state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"
``` ```
**Waiting 2026-09-27.** Routed the retire-vs-reconcile question to flex-auth **Historical hold, superseded in part by the September 28 review below.** Routed the retire-vs-reconcile question to flex-auth
(`2c637dc9-14ad-4815-aeb4-43254d01280c`) and tenant-engine (`2c637dc9-14ad-4815-aeb4-43254d01280c`) and tenant-engine
(`9fc740da-1966-4d39-a28a-79fd4870edb1`). NetKingdom will act on whichever (`9fc740da-1966-4d39-a28a-79fd4870edb1`). NetKingdom will act on whichever
answer comes back (retire and point to their authoritative declarations, or answer comes back (retire and point to their authoritative declarations, or
@ -137,3 +136,42 @@ would drop caller-auth enforcement.
Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference
copy. The recommendation is to replace it with pointers to the owners' copy. The recommendation is to replace it with pointers to the owners'
declarations (ADR-0015) rather than reconcile it field by field. declarations (ADR-0015) rather than reconcile it field by field.
### Implementation — 2026-09-28
The approved flex-auth portion is complete. Removed seven reference objects:
the flex-auth Namespace and both consumers' Deployment, Service and
NetworkPolicy objects. Added exact links to `flex-auth/values/tenant-engine.yaml`,
`flex-auth/values/user-engine.yaml` and `charts/flex-auth` in the adjacent README.
Their caller enforcement and bindings stay owned by those declarations.
The five tenant-engine objects are structurally unchanged and retain the
DO-NOT-APPLY header. Repository script/workflow/Makefile searches found no
consumer of this combined manifest; the user-engine verifier uses its own
separate runtime file. Parsed before/after YAML proves only the seven approved
objects were removed. Owner links resolve locally and both value files declare
`callerAuth.mode: enforce`. No cluster apply, rollout or runtime rename occurred.
T04 returns to `wait` solely for tenant-engine's disposition of its remaining
objects; T03 waits for the repository rename. With no remaining locally
executable task in this plan, its status is `blocked` again.
## Infrastructure review — 2026-09-28
Flex-auth replied September 27 in message
`77b26d1e-550b-4926-9610-44fc3a566273`: no objection to replacing its
reference objects with pointers to authoritative `values/<consumer>.yaml`.
At the review baseline, T04 had a locally actionable flex-auth portion and
was `todo`; the plan was `active`. The implementation above supersedes that
status. Preserve the DO-NOT-APPLY guard. Retire only those flex-auth reference
objects when implementing that portion, with exact owner pointers and a check
that no application path consumes them. Tenant-engine's portion still awaits
its owner answer; do not treat flex-auth's response as authority over it.
T04 closes only when both portions are resolved.
Live read-only checks confirm all six flex-auth Deployments are ready and
enforce caller authentication. Applying the stale reference would risk losing
that protection. FLEX-WP-0020 still holds rename execution at T06; T03 stays
`wait`, independently of this reference cleanup.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -9,7 +9,7 @@ flavor: planning
owner: claude-code owner: claude-code
topic_slug: netkingdom topic_slug: netkingdom
created: "2026-09-23" created: "2026-09-23"
updated: "2026-09-24" updated: "2026-09-28"
related: [RCLK-WP-0002] related: [RCLK-WP-0002]
state_hub_workstream_id: "e2533f3a-aa43-59b3-bff3-8e64b6149487" state_hub_workstream_id: "e2533f3a-aa43-59b3-bff3-8e64b6149487"
--- ---
@ -75,3 +75,20 @@ agreement) and Railiance (emitter confirmation) via State Hub messages
`4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and `4f1c67bc-8de2-483f-bcac-dbdf107ce95a`. NetKingdom adds the schema and
validator once both reply; nothing here can be finished unilaterally validator once both reply; nothing here can be finished unilaterally
without pre-empting their agreement. without pre-empting their agreement.
## Infrastructure review — 2026-09-28
Use accepted IAM Profile v0.3 and Playbook Capability Contract v0.1 as the
current baseline. Proposed IAM v0.4 and Playbook v0.2 are not deployed
capabilities. RCLK-WP-0002 still explicitly names this receipt as its dependency
on September 28. T02 remains `wait` for emitter and evidence-holder agreement.
Require the agreed schema to preserve unknown actor/delegation and clock
bounds explicitly, correlate decision/approval/run/artifact identities, and
distinguish durable receipt ingestion from attribution proof. Reuse audit-core
sender custody and reconciliation contracts rather than create another audit
sink. Acceptance needs an actual Railiance-emitted receipt and audit-core
readback, plus invalid/missing attribution cases; schema validation alone
cannot establish end-to-end attribution.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).

View file

@ -9,7 +9,7 @@ flavor: planning
owner: claude-code owner: claude-code
topic_slug: netkingdom topic_slug: netkingdom
created: "2026-09-23" created: "2026-09-23"
updated: "2026-09-24" updated: "2026-09-28"
related: [NK-ADR-0016, NK-WP-0037] related: [NK-ADR-0016, NK-WP-0037]
state_hub_workstream_id: "3f702215-704b-5788-8ca0-b8b9ba2dd3f8" state_hub_workstream_id: "3f702215-704b-5788-8ca0-b8b9ba2dd3f8"
--- ---
@ -72,3 +72,23 @@ on.
asking for a proposed pilot workload and U06 touchpoints. This is a asking for a proposed pilot workload and U06 touchpoints. This is a
UX/product agreement across two repos and a pilot workload owner; NetKingdom UX/product agreement across two repos and a pilot workload owner; NetKingdom
cannot decide it unilaterally. cannot decide it unilaterally.
## Infrastructure review — 2026-09-28
Build T02 on the already completed USER-WP-0033 and KEY-WP-0035 P06 work.
Their September 14 release evidence records optional-after-enrollment policy
for `user-engine-portal` and `vergabe-demo-company`, privileged MFA guards,
confirmed enrollment/cancellation and old-session checks. Do not rebuild
those capabilities or interpret this plan as the first delivery of MFA policy.
The residual is workload-level interoperability and an accepted pilot journey:
agree the pilot owner, reuse U06 recovery, prove no-factor enrollment and
return to the protected action, and test stale AAL1, refusal and provider
unavailability. Existing scoped policy does not prove arbitrary-client
`acr_values` support or acceptance of IAM v0.4. KeyCape owns issuer enforcement;
user-engine owns the journey; the workload and flex-auth enforce the issued
assurance at the protected action. T02 remains `wait` for that agreement and
actual-user acceptance, coordinated with KEY-WP-0034 / USER-WP-0028 /
VERGABE-WP-0019, without reopening their completed provider work.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).