net-kingdom/workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md
tegwick 9383b94019 Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:03 +02:00

7.9 KiB

id type title domain repo status flavor owner topic_slug created updated related state_hub_workstream_id
NK-WP-0039 workplan Take in the flex-auth to access-engine repository-coordinate rename infotech net-kingdom blocked implementation claude-code netkingdom 2026-09-23 2026-09-28
FLEX-WP-0020
FLEX-DEC-2026-013
NK-WP-0026
284a8ac2-61dc-5bee-b74a-0a62d9808edb

Intake for the flex-auth handoff request (hub message 3bc95c76, surface deployment). flex-auth renames its repository coordinate coulomb/flex-auth to coulomb/access-engine. The repository UUID fda8ad85-a7d7-4055-8f21-902a533e59df and Forge ID 42 stay. Runtime names stay flex-auth (FLEX-DEC-2026-013): namespace, Deployments, Services, labels, token audience, env names and in-image paths are not renamed.

This workplan does not authorize a runtime rename, image-coordinate change or rollout.

Verify live flex-auth Deployments and sso-mfa/k8s

id: NK-WP-0039-T01
status: done
priority: high
state_hub_task_id: "adfaa07d-dd15-50a6-a781-7cee2772fc90"

Read-only check on railiance01 (node 92.205.62.239) on 2026-09-23. The flex-auth namespace runs six Deployments, all 1/1: informed-decision-sitting, informed-decision-t03, ops-warden, secrets-engine, tenant-engine and user-engine, each prefixed flex-auth-. Every one pulls forgejo.coulomb.social/coulomb/flex-auth@sha256:….

At the September 23 inventory, NetKingdom declared two of them in sso-mfa/k8s/tenant-engine/runtime.yaml (flex-auth-tenant-engine, flex-auth-user-engine). Everything else under sso-mfa/k8s/** that names flex-auth is a runtime name that stays: the namespace, Service DNS flex-auth-user-engine.flex-auth.svc.cluster.local, the flex-auth-caller projected token and its flex-auth audience, labels, USER_ENGINE_FLEX_AUTH_* env names and /opt/flex-auth/... paths.

The only repository-coordinate references are the two image pins in sso-mfa/k8s/tenant-engine/runtime.yaml and the historical workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md.

Finding, recorded and not changed: the declared image digests differ from the live ones.

Deployment Declared Live
flex-auth-tenant-engine c25fc34a… 05a03a87…
flex-auth-user-engine 1f529037… 138aa347…

Resolved 2026-09-23 (flex-auth reply 28d9c6ca): live is correct. 05a03a87 was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence docs/evidence/2026-09-11-user-portal-tenant-policy.md); 138aa347 has been live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is values/<consumer>.yaml in flex-auth. runtime.yaml was updated to those live digests. T04 later removes the obsolete flex-auth reference objects entirely.

Confirm the image-pull path survives the rename

id: NK-WP-0039-T02
status: done
priority: high
state_hub_task_id: "73e98d7a-bff6-5111-93b1-f36938ab624f"

The image path is coulomb/flex-auth, which is also the repository name. Before the rename lands, flex-auth confirms one of these:

  • the container package is owner-scoped and keeps resolving as coulomb/flex-auth, so digest pulls survive a pod reschedule; or
  • the package moves, and flex-auth names the new coordinate and the cut-over window.

Answered 2026-09-23 (flex-auth 28d9c6ca): the package stays resolvable as coulomb/flex-auth. Forgejo packages are scoped to the owner, not the repository, and FLEX-WP-0020 keeps the package coordinate. There is no new coordinate and no cut-over window. FLEX-WP-0020 T09 verifies publication and pulls after the rename. The image pins do not change because of the rename.

Update repository-coordinate references once access-engine resolves

id: NK-WP-0039-T03
status: wait
priority: medium
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"

Once flex-auth announces that coulomb/access-engine resolves, verify repository-coordinate references against the retained runtime/package contract. T02 confirms image coordinates stay unchanged; do not schedule image-pin changes or a rollout as part of this rename. Leave historical records intact.

T04 now introduces explicit owner-repository links in sso-mfa/k8s/tenant-engine/README.md and a repository coordinate in the YAML header. After the rename announcement, update these pointers to the confirmed new repository/checkout, verify both value-file paths resolve and preserve the runtime/package names. NK-WP-0026 remains a historical record.

Retire or reconcile the stale flex-auth/tenant-engine reference manifest

id: NK-WP-0039-T04
status: wait
priority: high
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"

Historical hold, superseded in part by the September 28 review below. Routed the retire-vs-reconcile question to flex-auth (2c637dc9-14ad-4815-aeb4-43254d01280c) and tenant-engine (9fc740da-1966-4d39-a28a-79fd4870edb1). NetKingdom will act on whichever answer comes back (retire and point to their authoritative declarations, or keep a narrower reference); it should not pre-empt their decision by deleting or editing the file first.

A read-only kubectl diff of sso-mfa/k8s/tenant-engine/runtime.yaml against railiance01 on 2026-09-23 showed live ahead of the file beyond the digests. flex-auth runs with --caller-auth-mode enforce and caller bindings. tenant-engine runs image a8e8086f… (file: 2249e8c6…) with a different strategy, PVC mount and env. The egress rules also differ. No script applies the file. It now carries a DO-NOT-APPLY header, because applying it would drop caller-auth enforcement.

Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference copy. The recommendation is to replace it with pointers to the owners' declarations (ADR-0015) rather than reconcile it field by field.

Implementation — 2026-09-28

The approved flex-auth portion is complete. Removed seven reference objects: the flex-auth Namespace and both consumers' Deployment, Service and NetworkPolicy objects. Added exact links to flex-auth/values/tenant-engine.yaml, flex-auth/values/user-engine.yaml and charts/flex-auth in the adjacent README. Their caller enforcement and bindings stay owned by those declarations.

The five tenant-engine objects are structurally unchanged and retain the DO-NOT-APPLY header. Repository script/workflow/Makefile searches found no consumer of this combined manifest; the user-engine verifier uses its own separate runtime file. Parsed before/after YAML proves only the seven approved objects were removed. Owner links resolve locally and both value files declare callerAuth.mode: enforce. No cluster apply, rollout or runtime rename occurred.

T04 returns to wait solely for tenant-engine's disposition of its remaining objects; T03 waits for the repository rename. With no remaining locally executable task in this plan, its status is blocked again.

Infrastructure review — 2026-09-28

Flex-auth replied September 27 in message 77b26d1e-550b-4926-9610-44fc3a566273: no objection to replacing its reference objects with pointers to authoritative values/<consumer>.yaml. At the review baseline, T04 had a locally actionable flex-auth portion and was todo; the plan was active. The implementation above supersedes that status. Preserve the DO-NOT-APPLY guard. Retire only those flex-auth reference objects when implementing that portion, with exact owner pointers and a check that no application path consumes them. Tenant-engine's portion still awaits its owner answer; do not treat flex-auth's response as authority over it. T04 closes only when both portions are resolved.

Live read-only checks confirm all six flex-auth Deployments are ready and enforce caller authentication. Applying the stale reference would risk losing that protection. FLEX-WP-0020 still holds rename execution at T06; T03 stays wait, independently of this reference cleanup.

Evidence and cross-plan priorities: estate review.