# user-engine portal on reef-railiance **Apply home moved.** The managed package is `rapp-user-engine`. Render, deploy, verify, and rollback from that repo (`make deploy`, `make verify-live`). These files remain migration input until that package is the only checkout operators apply. This is a stateful `rail-kubernetes` platform workload. It intentionally has no public Ingress until the KeyCape authorization-code/PKCE edge and `user-engine-portal` client are configured. Direct access to protected routes must remain impossible because the application accepts identity only from a trusted edge marker plus verified claims. The portal image is published through the activity-core workload-scoped Forgejo package credential and deployed from `forgejo.coulomb.social/coulomb/user-engine` by immutable digest. The public package read was verified without an image pull Secret; publishing still uses the ExternalSecret-backed credential and temporary client state. The CloudNativePG operator creates `user-engine-pg-app`, including its `uri` field. OpenBao is authoritative for the portal edge marker and provisioner service token at `platform/workloads/user-engine/runtime`. The `openbao-runtime.yaml` stores and ExternalSecrets deliver those values into the existing namespaced Secret names without changing application interfaces. The audit-core sender and email-connect ingest credentials stay authoritative in their provider namespaces. Run `tools/sync-user-engine-delivery-secret.sh` from the repository root to copy only those scoped values into `user-engine-delivery` without printing them. Rerun it after either provider rotates its token, then restart user-engine because the application receives these two values as environment variables. The desired runtime also projects a short-lived ServiceAccount token with audience `flex-auth` at `/var/run/secrets/flex-auth-caller/token`. user-engine re-reads it per policy decision; it is not a Kubernetes API credential and is not copied into a Secret. This manifest must be promoted with a user-engine image that understands `USER_ENGINE_FLEX_AUTH_TOKEN_FILE` and flex-auth desired state that binds `system:serviceaccount:user-engine:user-engine`. The current pinned digest predates that coordinated rollout. ```bash kubectl apply -f openbao-runtime.yaml kubectl apply -f runtime.yaml kubectl -n user-engine rollout status deployment/user-engine kubectl -n user-engine get cluster,pod,service,networkpolicy ``` Rollback sets the Deployment image to the preceding immutable digest. Database migrations are additive and run before serving; restore uses the standard CNPG recovery contract once the offsite object-store reference is attached.