Reconcile identity state onto railiance01
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-28 12:11:45 +02:00
parent 11d81f3360
commit 9497529ed2
3 changed files with 68 additions and 11 deletions

View file

@ -104,7 +104,7 @@ counts. The pod and transient restore log were removed automatically.
```task
id: NK-WP-0022-T03
status: wait
status: done
priority: high
state_hub_task_id: "737b2210-92c7-45c2-a37a-76951e459c83"
```
@ -125,6 +125,18 @@ CoulombCore privacyIDEA has one enrolled token, two realms, two resolvers, and
two policies; railiance01 is empty. All privacyIDEA custody fingerprints
differ, so its database and encryption/signing material must migrate together.
2026-07-28: completed the bounded reconciliation documented in
`docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md`. Fresh encrypted
source and destination snapshots preceded all changes. LLDAP now contains the
authoritative `platform-root` identity and memberships plus preserved
railiance01-only users and tenant groups; disposable source lifecycle users
were excluded. privacyIDEA database counts and all matching custody
fingerprints agree. Twelve nonempty interhub source-table digests agree while
the newer destination schema, migration ledger, and destination-only user were
preserved. SQLite integrity, privacyIDEA HTTP, deployment rollout, and
post-restart semantic probes passed. Transient artifacts were removed and
CoulombCore writers remain frozen against divergence.
## T04 - Align configuration, secrets, and internal dependencies
```task