1.8 KiB
user-engine identity provisioning contract
user-engine is authoritative for user, tenant membership and lifecycle intent. NetKingdom is authoritative for provider subjects, credentials, password policy, MFA factors and authentication sessions. KeyCape projects verified authentication facts; flex-auth decides whether an actor may change intent.
The NetKingdom adapter implements user-engine's provider-neutral
IdentityProvisioningPort. Every operation has an idempotency key and
correlation ID. Provisioning creates or links an LLDAP subject, initializes
privacyIDEA eligibility without enrolling a factor, and returns the external
subject. Password and factor enrollment remain user-facing KeyCape handoffs.
Lifecycle order is:
- Commit user-engine intent and an outbox event atomically.
- Claim the event and call the provider with its stable idempotency key.
- Store the provider subject and completion evidence.
- Retry ambiguous failures; reconcile provider and domain state periodically.
Suspension disables provider authentication before reporting external completion. Reactivation preserves the same subject. Deprovisioning first removes active sessions and factors, then tombstones or removes the directory subject according to retention policy. A failed downstream action remains retryable and visible; it never rolls back authoritative audit history.
The adapter receives scoped provider credentials only through runtime secret references. Neither browsers nor the user-engine domain receive directory, MFA, KeyCape or mail-administration credentials.
Externally managed identities record provider, immutable external subject,
ownership (platform or customer), provisioning mode (managed,
federated, or jit), and last-observed freshness. Future SCIM and corporate
directory adapters use the same lifecycle results and conflict rules.