Deploy scoped user-engine delivery lanes
This commit is contained in:
parent
af8a6889d0
commit
dbbccc1a80
5 changed files with 42 additions and 5 deletions
|
|
@ -59,10 +59,10 @@
|
||||||
| task | NK-WP-0023-T06 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T06 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T07 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T07 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0023-T08 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
| task | NK-WP-0023-T08 | done | — | workplans/NK-WP-0023-user-engine-portal-platform-integration.md |
|
||||||
| task | NK-WP-0024-T01 | progress | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
| task | NK-WP-0024-T01 | wait | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
| task | NK-WP-0024-T02 | progress | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
| task | NK-WP-0024-T02 | wait | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
| task | NK-WP-0024-T03 | progress | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
| task | NK-WP-0024-T03 | wait | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
| task | NK-WP-0024-T04 | progress | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
| task | NK-WP-0024-T04 | wait | — | workplans/NK-WP-0024-user-engine-portal-integration-expansion.md |
|
||||||
| task | NK-WP-0025-T01 | done | — | workplans/NK-WP-0025-public-self-registration-and-application-jit.md |
|
| task | NK-WP-0025-T01 | done | — | workplans/NK-WP-0025-public-self-registration-and-application-jit.md |
|
||||||
| task | NK-WP-0025-T02 | wait | — | workplans/NK-WP-0025-public-self-registration-and-application-jit.md |
|
| task | NK-WP-0025-T02 | wait | — | workplans/NK-WP-0025-public-self-registration-and-application-jit.md |
|
||||||
| task | NK-WP-0025-T03 | wait | — | workplans/NK-WP-0025-public-self-registration-and-application-jit.md |
|
| task | NK-WP-0025-T03 | wait | — | workplans/NK-WP-0025-public-self-registration-and-application-jit.md |
|
||||||
|
|
|
||||||
|
|
@ -18,6 +18,13 @@ service token at `platform/workloads/user-engine/runtime`. The
|
||||||
`openbao-runtime.yaml` stores and ExternalSecrets deliver those values into the
|
`openbao-runtime.yaml` stores and ExternalSecrets deliver those values into the
|
||||||
existing namespaced Secret names without changing application interfaces.
|
existing namespaced Secret names without changing application interfaces.
|
||||||
|
|
||||||
|
The audit-core sender and email-connect ingest credentials stay authoritative
|
||||||
|
in their provider namespaces. Run
|
||||||
|
`tools/sync-user-engine-delivery-secret.sh` from the repository root to copy
|
||||||
|
only those scoped values into `user-engine-delivery` without printing them.
|
||||||
|
Rerun it after either provider rotates its token, then restart user-engine
|
||||||
|
because the application receives these two values as environment variables.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl apply -f openbao-runtime.yaml
|
kubectl apply -f openbao-runtime.yaml
|
||||||
kubectl apply -f runtime.yaml
|
kubectl apply -f runtime.yaml
|
||||||
|
|
|
||||||
|
|
@ -45,7 +45,7 @@ spec:
|
||||||
seccompProfile: {type: RuntimeDefault}
|
seccompProfile: {type: RuntimeDefault}
|
||||||
containers:
|
containers:
|
||||||
- name: portal
|
- name: portal
|
||||||
image: forgejo.coulomb.social/coulomb/user-engine@sha256:ffca598fab9c035b58a40ae6c2be365497743a7594bc584124ab231383f25d8a
|
image: forgejo.coulomb.social/coulomb/user-engine@sha256:4eac10bf157e48eeadef16a2da83a00933914c9d37338f01679692008de21565
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports: [{name: http, containerPort: 8080}]
|
ports: [{name: http, containerPort: 8080}]
|
||||||
env:
|
env:
|
||||||
|
|
|
||||||
19
tools/sync-user-engine-delivery-secret.sh
Executable file
19
tools/sync-user-engine-delivery-secret.sh
Executable file
|
|
@ -0,0 +1,19 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Copy only the two scoped receiver credentials into user-engine. Values stay
|
||||||
|
# in process memory and Kubernetes API requests; stdout contains metadata only.
|
||||||
|
audit_json="$(kubectl -n audit-core get secret audit-core-senders -o jsonpath='{.data.senders\.json}' | base64 -d)"
|
||||||
|
event_token="$(python3 -c 'import json,sys; rows=json.load(sys.stdin); print(next(row["tokens"][0] for row in rows if row["name"] == "user-engine"))' <<<"$audit_json")"
|
||||||
|
mail_token="$(kubectl -n email-connect get secret email-connect-runtime -o jsonpath='{.data.EMAIL_CONNECT_INGEST_TOKEN}' | base64 -d)"
|
||||||
|
|
||||||
|
test -n "$event_token"
|
||||||
|
test -n "$mail_token"
|
||||||
|
|
||||||
|
kubectl -n user-engine create secret generic user-engine-delivery \
|
||||||
|
--from-literal=event-token="$event_token" \
|
||||||
|
--from-literal=mail-token="$mail_token" \
|
||||||
|
--dry-run=client -o yaml \
|
||||||
|
| kubectl apply -f - >/dev/null
|
||||||
|
|
||||||
|
echo "user-engine delivery Secret synchronized (values withheld)"
|
||||||
|
|
@ -156,3 +156,14 @@ external-provider skips. NetKingdom's runtime manifest now declares both
|
||||||
cluster-local endpoints, separate Secret keys, and audit-core egress. The
|
cluster-local endpoints, separate Secret keys, and audit-core egress. The
|
||||||
remaining gate is custody delivery of those two scoped values, image publish,
|
remaining gate is custody delivery of those two scoped values, image publish,
|
||||||
rollout, and the combined live matrix.
|
rollout, and the combined live matrix.
|
||||||
|
|
||||||
|
2026-08-13 rollout: the scoped provider credentials were transferred entirely
|
||||||
|
through Kubernetes APIs into Secret `user-engine-delivery`, containing exactly
|
||||||
|
`event-token` and `mail-token`; no value was printed or persisted outside the
|
||||||
|
cluster. user-engine commit `a0f39f5` was published and deployed at immutable
|
||||||
|
digest `sha256:4eac10bf157e48eeadef16a2da83a00933914c9d37338f01679692008de21565`.
|
||||||
|
The rollout completed, `/readyz` reports all checks true, and in-pod probes
|
||||||
|
reach flex-auth, audit-core, and email-connect with HTTP 200 through the
|
||||||
|
declared NetworkPolicies. Remaining T04 evidence is application-level outbox
|
||||||
|
delivery and the negative matrix; health reachability alone is not reported
|
||||||
|
as delivery acceptance.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue