# NetKingdom Kubernetes integration guidance This directory holds bootstrap tooling, integration references and migration history. Current managed deployment belongs to the service/package owners under [ADR-0015](../../docs/adr/ADR-0015-netkingdom-railiance-workload-packaging-and-relational-platform.md). The [original foundation procedure](FOUNDATIONS-HISTORICAL.md) is retained as historical material, including its old prerequisites and apply commands. ## Operating baseline The [September 28 review](../../history/2026-09-28-open-workplan-infrastructure-review.md) observed one Ready Railiance01 node at `92.205.62.239`, healthy lightweight identity components and single-instance CNPG databases. This is a dated inventory, not an HA, recovery or user-login acceptance claim. | Surface | Current role and owner | | --- | --- | | KeyCape / Authelia / LLDAP (`sso`) and privacyIDEA (`mfa`) | Lightweight identity composition; issuer implementation in `key-cape`, integration contracts here | | User Engine | [rapp-user-engine](../../../rapp-user-engine/README.md) owns managed manifests, rollout and rollback | | Tenant Engine | [rapp-tenant-engine](../../../rapp-tenant-engine/README.md) owns managed runtime and database-consumption configuration | | flex-auth consumer services | [Owner values and chart pointers](tenant-engine/README.md); caller authentication is enforced by the owner declarations | | OpenBao and database custody | `railiance-platform`, with managed packages and consumer declarations in their owning repositories | | Kubernetes and host substrate | [railiance-cluster operator runbook](../../../railiance-cluster/docs/operator-runbook.md) and `railiance-infra` | OpenBao's public browser endpoint `bao.coulomb.social` is retired. Operators use the named `openbao-ui-railiance01` tunnel at `http://127.0.0.1:18200`; workloads use the internal Service. Follow the platform's [operator-only cutover record](../../../railiance-platform/workplans/RPF-WP-0025-openbao-operator-only-access.md) and credential routing in [AGENTS.md](../../AGENTS.md). Route access before requesting credentials; never copy tokens or Secret values into evidence. ## Read-only orientation Check the context before interpreting these results. All commands below read resource metadata and readiness; none applies manifests or initiates login. ```bash kubectl config current-context kubectl get nodes -o wide kubectl -n sso get deployments kubectl -n mfa get deployments kubectl -n user-engine get deployments kubectl -n tenant-engine get deployments kubectl -n flex-auth get deployments kubectl -n openbao get statefulsets,deployments,services,ingresses kubectl get clusters.postgresql.cnpg.io -A ``` Ready replicas do not prove negative authorization, actual-user MFA, successful backup restoration or independent failure domains. Use the relevant owner's verification and recovery procedure for those claims. ## Deployment and recovery Start with the owning package's current declaration, immutable image and reviewed rollout/rollback procedure. Do not recursively apply this tree. `tenant-engine/runtime.yaml` remains **REFERENCE ONLY — DO NOT APPLY** while its owner decides the disposition of the five retained historical objects. Its obsolete flex-auth objects have been replaced with owner pointers. The scripts and manifests elsewhere in this directory have individual scopes; their presence here does not make them current production repair commands. The [attended procedure inventory](../../docs/attended-procedure-inventory.md) records their exercise limits. Use the [custody model](../../docs/openbao-unseal-custody-models.md) and current owner runbooks to prepare recovery. A database-only drill does not prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption material, or all identity database state. CoulombCore identity cutover is complete; final retained-resource deletion remains gated by [NK-WP-0022](../../workplans/NK-WP-0022-railiance01-identity-cutover-and-coulombcore-retirement.md). Expiration of the retention minimum does not authorize deletion.