Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 299762@bnt-lap001 Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
5.2 KiB
| id | type | title | domain | repo | status | flavor | owner | topic_slug | created | updated | related | state_hub_workstream_id | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| NK-WP-0039 | workplan | Take in the flex-auth to access-engine repository-coordinate rename | infotech | net-kingdom | active | implementation | claude-code | netkingdom | 2026-09-23 | 2026-09-23 |
|
284a8ac2-61dc-5bee-b74a-0a62d9808edb |
Intake for the flex-auth handoff request (hub message 3bc95c76, surface
deployment). flex-auth renames its repository coordinate
coulomb/flex-auth to coulomb/access-engine. The repository UUID
fda8ad85-a7d7-4055-8f21-902a533e59df and Forge ID 42 stay. Runtime names stay
flex-auth (FLEX-DEC-2026-013): namespace, Deployments, Services, labels,
token audience, env names and in-image paths are not renamed.
This workplan does not authorize a runtime rename, image-coordinate change or rollout.
Verify live flex-auth Deployments and sso-mfa/k8s
id: NK-WP-0039-T01
status: done
priority: high
state_hub_task_id: "adfaa07d-dd15-50a6-a781-7cee2772fc90"
Read-only check on railiance01 (node 92.205.62.239) on 2026-09-23. The
flex-auth namespace runs six Deployments, all 1/1:
informed-decision-sitting, informed-decision-t03, ops-warden,
secrets-engine, tenant-engine and user-engine, each prefixed
flex-auth-. Every one pulls
forgejo.coulomb.social/coulomb/flex-auth@sha256:….
NetKingdom declares two of them in sso-mfa/k8s/tenant-engine/runtime.yaml
(flex-auth-tenant-engine, flex-auth-user-engine). Everything else under
sso-mfa/k8s/** that names flex-auth is a runtime name that stays: the
namespace, Service DNS flex-auth-user-engine.flex-auth.svc.cluster.local,
the flex-auth-caller projected token and its flex-auth audience, labels,
USER_ENGINE_FLEX_AUTH_* env names and /opt/flex-auth/... paths.
The only repository-coordinate references are the two image pins in
sso-mfa/k8s/tenant-engine/runtime.yaml and the historical
workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md.
Finding, recorded and not changed: the declared image digests differ from the live ones.
| Deployment | Declared | Live |
|---|---|---|
flex-auth-tenant-engine |
c25fc34a… |
05a03a87… |
flex-auth-user-engine |
1f529037… |
138aa347… |
Resolved 2026-09-23 (flex-auth reply 28d9c6ca): live is correct. 05a03a87
was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence
docs/evidence/2026-09-11-user-portal-tenant-policy.md); 138aa347 has been
live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is
values/<consumer>.yaml in flex-auth. runtime.yaml now declares the live
digests. See T04 for the rest of the drift.
Confirm the image-pull path survives the rename
id: NK-WP-0039-T02
status: done
priority: high
state_hub_task_id: "73e98d7a-bff6-5111-93b1-f36938ab624f"
The image path is coulomb/flex-auth, which is also the repository name.
Before the rename lands, flex-auth confirms one of these:
- the container package is owner-scoped and keeps resolving as
coulomb/flex-auth, so digest pulls survive a pod reschedule; or - the package moves, and flex-auth names the new coordinate and the cut-over window.
Answered 2026-09-23 (flex-auth 28d9c6ca): the package stays resolvable as
coulomb/flex-auth. Forgejo packages are scoped to the owner, not the
repository, and FLEX-WP-0020 keeps the package coordinate. There is no new
coordinate and no cut-over window. FLEX-WP-0020 T09 verifies publication and
pulls after the rename. The image pins do not change because of the rename.
Update repository-coordinate references once access-engine resolves
id: NK-WP-0039-T03
status: wait
priority: medium
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"
Once flex-auth announces that coulomb/access-engine resolves, update
references to the repository coordinate. If the image coordinate
changes, update the two image pins in sso-mfa/k8s/tenant-engine/runtime.yaml
in the same change as the digest reconciliation from T01. Applying that live
needs the founder's go-ahead. Leave runtime names and historical records
unchanged.
After T02, no in-repo coordinate reference needs to change: the image pins
stay, and NK-WP-0026 is a historical record. This task waits only for
flex-auth's announcement that access-engine resolves, which confirms that
nothing else moved.
Retire or reconcile the stale flex-auth/tenant-engine reference manifest
id: NK-WP-0039-T04
status: todo
priority: high
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"
A read-only kubectl diff of sso-mfa/k8s/tenant-engine/runtime.yaml
against railiance01 on 2026-09-23 showed live ahead of the file beyond the
digests. flex-auth runs with --caller-auth-mode enforce and caller
bindings. tenant-engine runs image a8e8086f… (file: 2249e8c6…) with a
different strategy, PVC mount and env. The egress rules also differ. No script
applies the file. It now carries a DO-NOT-APPLY header, because applying it
would drop caller-auth enforcement.
Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference copy. The recommendation is to replace it with pointers to the owners' declarations (ADR-0015) rather than reconcile it field by field.