From a58df4c3e6c3dd3d36a864da70663da643c75a4a Mon Sep 17 00:00:00 2001 From: tegwick Date: Tue, 28 Jul 2026 16:48:47 +0200 Subject: [PATCH] Advance pre-cutover identity conformance --- WORK-RECORDS.md | 4 +-- ...oulombcore-cutover-inventory-2026-07-28.md | 25 +++++++++++++++++++ sso-mfa/k8s/user-engine/runtime.yaml | 2 +- ...tity-cutover-and-coulombcore-retirement.md | 17 ++++++++++++- ...user-engine-portal-platform-integration.md | 10 +++++++- 5 files changed, 53 insertions(+), 5 deletions(-) diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 054bead..a8605d8 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -45,7 +45,7 @@ | task | NK-WP-0022-T02 | done | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | | task | NK-WP-0022-T03 | done | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | | task | NK-WP-0022-T04 | done | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | -| task | NK-WP-0022-T05 | wait | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | +| task | NK-WP-0022-T05 | progress | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | | task | NK-WP-0022-T06 | progress | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | | task | NK-WP-0022-T07 | wait | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | | task | NK-WP-0022-T08 | wait | — | workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md | @@ -55,7 +55,7 @@ | task | NK-WP-0023-T04 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md | | task | NK-WP-0023-T05 | progress | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md | | task | NK-WP-0023-T06 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md | -| task | NK-WP-0023-T07 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md | +| task | NK-WP-0023-T07 | progress | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md | | task | NK-WP-0023-T08 | wait | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md | | intake | NK-IN-0001 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md | | intake | NK-IN-0002 | closed | blue | docs/intakes/activity-core-ops-sso-operators.md | diff --git a/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md b/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md index f1a9137..3a43a89 100644 --- a/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md +++ b/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md @@ -186,6 +186,31 @@ TLS-preserving direct resolution to `92.205.62.239` returned HTTP 200 with successful certificate verification for `auth`, `login`, `lldap`, `pink`, and `pink-account` under `coulomb.social`. +## Pre-cutover conformance progress + +KeyCape's canonical issuer is `https://kc.coulomb.social`; +`auth.coulomb.social` and `login.coulomb.social` belong to Authelia. The +user-engine portal currently returns a 303 to KeyCape with an exact callback +and S256 PKCE challenge. + +The `rapp-qonto-client` service flow passes against KeyCape: `qonto:read` +returns a token, a deliberately wrong secret returns 401 without a token, and +the excessive `qonto:write` scope returns 400 without a token. + +The deployed user-engine API created the Binky tenant-admin lifecycle record, +membership, LLDAP subject, and identity link. The provider reports +`password_setup_required`. This flow found a newline-bearing runtime Secret +that could not legally be sent as an HTTP header; user-engine commit +`0ef2ae5` normalizes transport whitespace, passes 105 tests with three +integration skips, and is deployed as `user-engine:portal-0ef2ae5`. + +The human conformance gate is not yet complete. LLDAP's native self-service +password reset requires configured SMTP, but this deployment has no SMTP +settings. The existing Binky mailbox route authorizes read-only IMAP and +explicitly does not authorize SMTP. No operator-set initial password was used +as a shortcut. A reusable NetKingdom password-setup or transactional-mail +handoff must precede Binky MFA enrollment and final claim/denial evidence. + ## Required next evidence 1. Exercise platform-root and Binky login/MFA using TLS-preserving direct diff --git a/sso-mfa/k8s/user-engine/runtime.yaml b/sso-mfa/k8s/user-engine/runtime.yaml index 3c8f415..5b547a3 100644 --- a/sso-mfa/k8s/user-engine/runtime.yaml +++ b/sso-mfa/k8s/user-engine/runtime.yaml @@ -45,7 +45,7 @@ spec: seccompProfile: {type: RuntimeDefault} containers: - name: portal - image: user-engine:portal-e23674d + image: user-engine:portal-0ef2ae5 imagePullPolicy: Never ports: [{name: http, containerPort: 8080}] env: diff --git a/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md b/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md index 2cf9491..25d1ae3 100644 --- a/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md +++ b/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md @@ -168,7 +168,7 @@ certificates for `auth`, `login`, `lldap`, `pink`, and `pink-account`. ```task id: NK-WP-0022-T05 -status: wait +status: progress priority: high state_hub_task_id: "5b01e471-afd0-479d-8b35-66eef7820cf6" ``` @@ -182,6 +182,21 @@ the platform-root and Binky tenant paths without exposing tokens. Done when all critical human and service flows pass and rollback criteria are machine-readable. +2026-07-28 progress: the portal starts a KeyCape authorization-code flow with +S256 PKCE, and KeyCape discovery/TLS is healthy at its canonical +`kc.coulomb.social` issuer. `rapp-qonto-client` obtains a token only for +`qonto:read`; a wrong secret returns 401 and excessive `qonto:write` returns +400 without a token. The Binky administrator was created and provisioned +through user-engine's deployed versioned API, producing a linked LLDAP +identity and `password_setup_required` state. This exposed and fixed newline +normalization for the portal's trusted proxy secret in user-engine +`0ef2ae5`; 105 tests pass and the fixed image is live. + +Human acceptance remains open: LLDAP has no SMTP configuration, so its native +self-service reset cannot deliver the first-password handoff. No operator-set +password was substituted. A NetKingdom-owned password-setup or transactional +mail handoff plus Binky MFA enrollment and final claim/denial checks remain. + ## T06 - Cut over remaining DNS with monitored rollback ```task diff --git a/workplans/NK-WP-0023-user-engine-portal-platform-integration.md b/workplans/NK-WP-0023-user-engine-portal-platform-integration.md index 23a812f..6ebf7bd 100644 --- a/workplans/NK-WP-0023-user-engine-portal-platform-integration.md +++ b/workplans/NK-WP-0023-user-engine-portal-platform-integration.md @@ -157,7 +157,7 @@ outage, suspension, restore, and browser/MFA matrix remains. ```task id: NK-WP-0023-T07 -status: wait +status: progress priority: high state_hub_task_id: "a574dcec-f7cd-417b-aeaa-5392a7428241" ``` @@ -168,6 +168,14 @@ OIDC/PKCE + MFA, and verify the Binky-only tenant-admin token and lifecycle controls. Publish only non-secret evidence to `KEY-WP-0004-T02/T07`, then finish that workplan. +2026-07-28: the deployed versioned portal API created the Binky tenant-admin +user and membership and provisioned/linked its LLDAP identity. The provider +correctly reports `password_setup_required`. During this flow a newline in the +mounted trusted-proxy Secret proved HTTP-incompatible; user-engine `0ef2ae5` +normalizes runtime transport whitespace, has 105 passing tests, and is live. +LLDAP SMTP is not configured, so first-password handoff and MFA/claim +acceptance remain rather than falling back to an operator-set password. + ## T08 - Document enterprise integration extension points ```task