docs: point user-engine apply home at rapp-user-engine
This commit is contained in:
parent
cced59d3aa
commit
f4f885289e
1 changed files with 13 additions and 0 deletions
|
|
@ -1,5 +1,10 @@
|
|||
# user-engine portal on reef-railiance
|
||||
|
||||
**Apply home moved.** The managed package is `rapp-user-engine`. Render,
|
||||
deploy, verify, and rollback from that repo (`make deploy`,
|
||||
`make verify-live`). These files remain migration input until that
|
||||
package is the only checkout operators apply.
|
||||
|
||||
This is a stateful `rail-kubernetes` platform workload. It intentionally has
|
||||
no public Ingress until the KeyCape authorization-code/PKCE edge and
|
||||
`user-engine-portal` client are configured. Direct access to protected routes
|
||||
|
|
@ -25,6 +30,14 @@ only those scoped values into `user-engine-delivery` without printing them.
|
|||
Rerun it after either provider rotates its token, then restart user-engine
|
||||
because the application receives these two values as environment variables.
|
||||
|
||||
The desired runtime also projects a short-lived ServiceAccount token with
|
||||
audience `flex-auth` at `/var/run/secrets/flex-auth-caller/token`. user-engine
|
||||
re-reads it per policy decision; it is not a Kubernetes API credential and is
|
||||
not copied into a Secret. This manifest must be promoted with a user-engine
|
||||
image that understands `USER_ENGINE_FLEX_AUTH_TOKEN_FILE` and flex-auth desired
|
||||
state that binds `system:serviceaccount:user-engine:user-engine`. The current
|
||||
pinned digest predates that coordinated rollout.
|
||||
|
||||
```bash
|
||||
kubectl apply -f openbao-runtime.yaml
|
||||
kubectl apply -f runtime.yaml
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue