These workplans exist only in the retired local hub. Their random pre-ADR-007 identifiers are refused by C-06 as stale references, so they cannot be registered. Deriving from the canonical record id takes no identity from anything: central does not hold them and the old ids die with the cache. Records central already holds were deliberately left untouched. Refs CUST-WP-0068-T06 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
9.7 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | depends_on | state_hub_workstream_id | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| NK-WP-0024 | workplan | Expand user-engine platform integrations beyond the Binky MVP | infotech | net-kingdom | finished | codex | netkingdom | 2026-07-30 | 2026-08-14 |
|
635a73d4-b3cb-5c38-af22-56a6a66beb0e |
NK-WP-0024 - Portal integration expansion
2026-08-13 completion review
This workplan was blocked at review time. On 2026-08-13 AUDIT-WP-0005
finished: the PostgreSQL-backed audit-core workload is Ready with archive
custody, OpenBao-backed sender/database lanes, restart/rollback evidence, and
a live failure matrix (12 passed, 0 failed, 3 production-disruption skips).
The workplan is active again.
The audit dependency recorded above is stale operationally: AUDIT-WP-0003 finished only after cancelling its deployment tasks. Production custody and the live matrix moved to the now-finished AUDIT-WP-0005.
A consumer-side credential-isolation defect was found and fixed before
activation. The previous user-engine HTTPOutboxDeliveryAdapter accepted one
USER_ENGINE_DELIVERY_TOKEN for both receivers. audit-core and email-connect
are separately scoped receivers and must not share a bearer credential; the
adapter now accepts distinct event and mail tokens.
Track deferred integration breadth separately from the completed live MVP. Activate with the corresponding user-engine product-expansion tasks.
Provider workplans established 2026-08-08:
FLEX-WP-0009provides the user-engine policy package and cluster service.AUDIT-WP-0003provides authenticated durable event ingestion.EMAIL-WP-0004provides transactional invitation-mail delivery.
This workplan remains the consumer-side coordination and deployed integration gate; provider implementation status stays authoritative in the owning repos.
T01 - Establish flex-auth production authorization
id: NK-WP-0024-T01
status: done
priority: high
state_hub_task_id: "4bad414d-b0c1-52df-914f-cdc602192124"
Define self, tenant-admin, and platform-admin resource/action vocabulary, deploy the policy package, replace user-engine's local runtime adapter with a fail-closed flex-auth HTTP adapter, and correlate decision IDs with audit.
2026-08-08 implementation: added the fail-closed flex-auth HTTP adapter in
user-engine, including request mapping, decision-ID propagation, timeout and
malformed-response denial tests. The role/resource contract and safe rollout
gate are recorded in docs/user-engine-platform-expansion-contract.md.
Deployment remains pending because no cluster-local flex-auth Service or
validated user-engine policy package currently exists on railiance01.
2026-08-09 deployment: the validated user-engine policy is live at
flex-auth-user-engine.flex-auth.svc.cluster.local:8080; an in-namespace live
probe produced self-service allow and cross-tenant deny decisions. The portal
runtime switch remains coupled to the event/mail activation gate below.
Done 2026-08-14: the portal is live on the fail-closed HTTP adapter; its platform outbox dispatch was authorized by the deployed flex-auth policy and accepted into audit-core with correlated event IDs. Existing deployed allow, cross-tenant deny, missing-role deny, and wrong-system deny evidence remains valid.
T02 - Add invitation and verification mail delivery
id: NK-WP-0024-T02
status: done
priority: medium
state_hub_task_id: "88098a55-f2ca-5636-9a98-ae8a98cdeaf4"
Deliver invitation and verification messages through approved custody and mail lanes. Mailbox ownership remains evidence, never authorization.
2026-08-08 implementation: added authenticated, idempotent invitation-mail delivery from durable outbox events. The delivery token is a required runtime secret and the NetKingdom contract pins it to the existing OpenBao runtime lane. Live completion waits for an approved mail receiver and its custody entry; production is deliberately not pointed at a fabricated endpoint.
T03 - Operate durable event delivery
id: NK-WP-0024-T03
status: done
priority: high
state_hub_task_id: "59d3a6b5-7b9a-52a5-adc1-dd9fe74e3eba"
Connect the user-engine transactional outbox to the platform event lane with bounded retries, replay, dead-letter visibility, redaction, and correlation.
2026-08-08 implementation: added an authenticated HTTP event adapter carrying
event ID, tenant, correlation, occurrence time, and redacted domain payload.
It uses Idempotency-Key; the existing durable store supplies bounded retry,
dead-letter, diagnostics, and replay. Live completion waits for a selected
cluster event receiver and scoped delivery credential.
T04 - Run expanded integration failure matrix
id: NK-WP-0024-T04
status: done
priority: high
state_hub_task_id: "68eb8659-acd9-5188-bd12-b67fb18c6144"
Prove flex-auth denial/unavailability, mail failure, identity-provider outage, partial provisioning recovery, invitation replay/expiry, and cross-tenant negative behavior through the deployed path.
2026-08-08 source matrix: user-engine's full suite passes 119 tests with three external-provider tests skipped. New coverage proves flex-auth allow mapping, decision correlation, fail-closed unavailability, invitation mail routing, event routing, and idempotency. Existing USER-WP-0021 coverage proves provider outage, recovery, invitation expiry/replay, dead-letter/replay, and cross-tenant denial. The deployed-path matrix remains pending on the three production endpoints above.
2026-08-12 EMAIL-WP-0004-T04 hand-back: transactional invitation mail receiver
is live on railiance01 at
http://email-connect.email-connect.svc.cluster.local:8080. Failure contract
and non-secret evidence (retryable vs permanent codes, duplicate/resend,
suppression, evidence ceilings, redaction) are in
email-connect/docs/EMAIL-WP-0004-T04-failure-evidence.md. user-engine must
mount only EMAIL_CONNECT_INGEST_TOKEN (not SMTP). Provider acceptance and
mailbox challenges are not authorization.
2026-08-13 review: reopening gates are (1) split user-engine's event and mail bearer configuration, (2) finish and deploy AUDIT-WP-0005 with its OpenBao dynamic database and sender lanes, (3) mount both independently scoped sender credentials, roll out the current user-engine image, and (4) run the combined deployed failure matrix. Until then, marking any of T01-T04 done would claim a runtime cutover that has not occurred.
2026-08-13 resumed: user-engine now has distinct USER_ENGINE_EVENT_TOKEN
and USER_ENGINE_MAIL_TOKEN inputs; adapter tests assert that audit-core and
email-connect receive different Authorization headers and that mail delivery
fails closed without its token. The full source suite passes 132 tests with 3
external-provider skips. NetKingdom's runtime manifest now declares both
cluster-local endpoints, separate Secret keys, and audit-core egress. The
remaining gate is custody delivery of those two scoped values, image publish,
rollout, and the combined live matrix.
2026-08-13 rollout: the scoped provider credentials were transferred entirely
through Kubernetes APIs into Secret user-engine-delivery, containing exactly
event-token and mail-token; no value was printed or persisted outside the
cluster. user-engine commit a0f39f5 was published and deployed at immutable
digest sha256:4eac10bf157e48eeadef16a2da83a00933914c9d37338f01679692008de21565.
The rollout completed, /readyz reports all checks true, and in-pod probes
reach flex-auth, audit-core, and email-connect with HTTP 200 through the
declared NetworkPolicies. Remaining T04 evidence is application-level outbox
delivery and the negative matrix; health reachability alone is not reported
as delivery acceptance.
2026-08-14 live outbox proof: nine existing durable non-mail events were
dispatched through the deployed user-engine adapter. Three were accepted
immediately. Six received HTTP 400 because audit-core's user-engine sender
was limited to tenant:friendly:binky; the platform service legitimately
emits for multiple tenants. The sender remains write-only and source-bound to
user-engine, but its tenant claim scope is now *. After audit-core restart,
explicit replay delivered all six with attempt count 2; user-engine reports
zero pending events.
The run also exposed a PostgreSQL retry defect: pending_outbox() filtered on
failed_at IS NULL, unlike the in-memory contract, so bounded retries stopped
after one failure. user-engine commit 0b6a57d selects every undelivered,
non-dead-letter event and adds regression coverage; the full suite passes 133
tests with 3 external skips. The corrected immutable image is
sha256:1402712e8f3ddc1397e83edb9627251b0ea362f1e3308d252d0d688ac589556e.
T03 is complete: all nine durable source events are delivered, replay is idempotent at audit-core, user-engine reports zero pending events, and the corrected bounded-retry query is live and Ready.
Done 2026-08-14: email-engine's disposable harness proved application-level
verification issuance, mailbox receipt, single-use consumption, baseline
directory provisioning, and the allow-listed password handoff. The combined
deployed path exercised and recovered from authorization denial, verification
network refusal, a request-schema 400, PostgreSQL rolling-start lock
contention, and self-link authorization denial. Regression fixes are live in
user-engine commits 14b8121, d4a1327, 10ee042, and 5e37e9c; the final
suite passes 133 tests with 3 external-provider skips. The successful retry
returned 202 for start, 303 for the provider handoff, and 200 for password
completion. Directory inspection proved the baseline users group and absence
of the tenant-admin group. Three exact disposable directory identities were
deprovisioned, production email-connect custody was restored, and the
temporary harness resources were removed.