From ae986c723aebe0c302bb4ad0589b52b355c4822e Mon Sep 17 00:00:00 2001 From: tegwick Date: Tue, 28 Jul 2026 02:52:14 +0200 Subject: [PATCH] Record CoulombCore cutover inventory --- ...oulombcore-cutover-inventory-2026-07-28.md | 75 +++++++++++++++++++ ...tity-cutover-and-coulombcore-retirement.md | 13 +++- 2 files changed, 86 insertions(+), 2 deletions(-) create mode 100644 docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md diff --git a/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md b/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md new file mode 100644 index 0000000..7e1282e --- /dev/null +++ b/docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md @@ -0,0 +1,75 @@ +# Railiance01 / CoulombCore cutover inventory + +Captured read-only on 2026-07-28. This inventory intentionally contains no +Secret values, private keys, password hashes, tokens, or database contents. + +## Public routing + +| Name | Current target | Cutover owner/state | +| --- | --- | --- | +| `kc.coulomb.social` | railiance01 (`92.205.62.239`) | KeyCape active | +| `auth.coulomb.social` | railiance01 (`92.205.62.239`) | Authelia active | +| `login.coulomb.social` | railiance01 (`92.205.62.239`) | Authelia alias active | +| `lldap.coulomb.social` | CoulombCore (`92.205.130.254`) | identity cutover pending | +| `pink.coulomb.social` | CoulombCore (`92.205.130.254`) | identity cutover pending | +| `pink-account.coulomb.social` | CoulombCore (`92.205.130.254`) | identity cutover pending | +| `bao.coulomb.social` | CoulombCore (`92.205.130.254`) | OpenBao-owned cutover | +| `gitea.coulomb.social` | CoulombCore (`92.205.130.254`) | Forgejo/Gitea-owned cutover | +| `hub.coulomb.social` | CoulombCore (`92.205.130.254`) | State Hub-owned cutover | + +Public recursive resolvers return railiance01 for both Authelia names. The +certificate at railiance01 is trusted and covers both names. The portal → +KeyCape → Authelia redirect chain terminates on railiance01. + +During cutover, cert-manager's HTTP-01 self-check inherited stale node DNS. +The live controller now uses `1.1.1.1:53,8.8.8.8:53` for ACME self-checks and +the expanded certificate was renewed through `cmctl`. The cluster add-on +configuration must codify that resolver flag so a future Helm reconciliation +does not remove it. + +## Identity workload comparison + +| Component | CoulombCore | railiance01 | Finding | +| --- | --- | --- | --- | +| KeyCape | `main-nonce-0601` | `key-cape:909bb32` | New runtime is ahead; both healthy | +| Authelia | `authelia:4.38` | `authelia:4.38` | Same declared image | +| LLDAP | `lldap/lldap:stable` | `lldap/lldap:stable` | Independent PVCs; content differs | +| privacyIDEA | `3.12.2` | `3.12.2` | Independent data/log PVCs | +| NetKingdom PostgreSQL | 10 Gi PVC | 10 Gi PVC | Independent clusters require semantic comparison | +| Identity provisioner | absent | `identity-provisioner:dbf7cfd` | railiance01-only lifecycle adapter | +| User engine | absent | `user-engine:portal-e23674d` | railiance01-only control surface | + +Both KeyCape endpoints serve the same public JWKS fingerprint: +`8e3237da6030c6af91c5005d0112a149204bc549f67d2234939c5581fdb95a32`. +This proves current public signing-key continuity, not full configuration +equivalence. + +## Persistent state and backup observations + +- Both LLDAP databases are 139264 bytes, but their SHA-256 fingerprints differ: + CoulombCore `b3be5eed...b91278`; railiance01 `fc538cc8...03dab`. + Equal size is not equivalence. Railiance01 also has newer writes from the + provisioning conformance path. +- railiance01 runs daily LLDAP, Authelia, and privacyIDEA backup CronJobs and + exposes an LLDAP backup directory on its PVC. +- The queried CoulombCore workload inventory exposed daily logical PostgreSQL + backup CronJobs, but no matching LLDAP, Authelia, or privacyIDEA backup + CronJobs. A fresh source-side protected backup is therefore a hard gate. +- Both servers retain independent LLDAP, Authelia, privacyIDEA, and + NetKingdom PostgreSQL PVCs. No DNS move for LLDAP/privacyIDEA is evidence of + data migration. +- CoulombCore still runs KeyCape and Authelia ingress even though their public + DNS moved. Keep these intact only for the bounded rollback window; prevent + new authoritative writes once state migration begins. + +## Required next evidence + +1. Create and verify fresh encrypted CoulombCore identity backups. +2. Compare semantic user/group counts and stable identifiers without exporting + credential material into logs. +3. Compare privacyIDEA realms, resolver mappings, token counts, and encryption + custody using redacted/count-only probes. +4. Compare NetKingdom PostgreSQL schemas and row counts. +5. Freeze writes, merge the authoritative source into railiance01, rerun the + comparisons, and then exercise platform-root and Binky login/MFA. +6. Move LLDAP and privacyIDEA DNS only after those gates pass. diff --git a/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md b/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md index 460a36a..46a3c12 100644 --- a/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md +++ b/workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md @@ -63,6 +63,14 @@ Hub must be handed to their owning workload cutovers before CoulombCore host retirement. Local resolver caches may temporarily retain the former `auth.coulomb.social` address. +The read-only comparison is recorded in +`docs/railiance01-coulombcore-cutover-inventory-2026-07-28.md`. It confirms +matching public KeyCape JWKS fingerprints and matching declared +Authelia/LLDAP/privacyIDEA images, but independent PVCs and divergent LLDAP +database fingerprints. CoulombCore exposes PostgreSQL logical backups but no +matching LLDAP, Authelia, or privacyIDEA backup CronJobs; fresh protected +source backups remain a hard gate. + ## T02 - Prove recoverable backups before changing state ```task @@ -158,8 +166,9 @@ window passes without fallback traffic or state divergence. 2026-07-28: authoritative/public recursive DNS now returns railiance01 for `auth.coulomb.social`; `login.coulomb.social` was added as an Authelia ingress -and certificate alias. LLDAP and both privacyIDEA names remain intentionally -on CoulombCore pending the state and conformance gates above. +and trusted certificate alias. The complete portal → KeyCape → Authelia +redirect reaches railiance01. LLDAP and both privacyIDEA names remain +intentionally on CoulombCore pending the state and conformance gates above. ## T07 - Retire CoulombCore identity workloads reversibly