# user-engine portal on reef-railiance This is a stateful `rail-kubernetes` platform workload. It intentionally has no public Ingress until the KeyCape authorization-code/PKCE edge and `user-engine-portal` client are configured. Direct access to protected routes must remain impossible because the application accepts identity only from a trusted edge marker plus verified claims. For the current pre-production bootstrap the image is imported directly into k3s and uses `imagePullPolicy: Never`. Replace it with the immutable Forgejo OCI digest after the OpenBao package-publisher lane is available. The CloudNativePG operator creates `user-engine-pg-app`, including its `uri` field. `user-engine-runtime` contains only the generated edge marker and must be replaced by an ExternalSecret before public exposure. ```bash kubectl apply -f runtime.yaml kubectl -n user-engine rollout status deployment/user-engine kubectl -n user-engine get cluster,pod,service,networkpolicy ``` Rollback sets the Deployment image to the preceding immutable digest. Database migrations are additive and run before serving; restore uses the standard CNPG recovery contract once the offsite object-store reference is attached.