Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 299762@bnt-lap001 Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
3.3 KiB
| id | type | title | domain | repo | status | flavor | owner | topic_slug | created | updated | related | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| NK-WP-0039 | workplan | Take in the flex-auth to access-engine repository-coordinate rename | infotech | net-kingdom | active | implementation | claude-code | netkingdom | 2026-09-23 | 2026-09-23 |
|
Intake for the flex-auth handoff request (hub message 3bc95c76, surface
deployment). flex-auth renames its repository coordinate
coulomb/flex-auth to coulomb/access-engine. The repository UUID
fda8ad85-a7d7-4055-8f21-902a533e59df and Forge ID 42 stay. Runtime names stay
flex-auth (FLEX-DEC-2026-013): namespace, Deployments, Services, labels,
token audience, env names and in-image paths are not renamed.
This workplan does not authorize a runtime rename, image-coordinate change or rollout.
Verify live flex-auth Deployments and sso-mfa/k8s
id: NK-WP-0039-T01
status: done
priority: high
Read-only check on railiance01 (node 92.205.62.239) on 2026-09-23. The
flex-auth namespace runs six Deployments, all 1/1:
informed-decision-sitting, informed-decision-t03, ops-warden,
secrets-engine, tenant-engine and user-engine, each prefixed
flex-auth-. Every one pulls
forgejo.coulomb.social/coulomb/flex-auth@sha256:….
NetKingdom declares two of them in sso-mfa/k8s/tenant-engine/runtime.yaml
(flex-auth-tenant-engine, flex-auth-user-engine). Everything else under
sso-mfa/k8s/** that names flex-auth is a runtime name that stays: the
namespace, Service DNS flex-auth-user-engine.flex-auth.svc.cluster.local,
the flex-auth-caller projected token and its flex-auth audience, labels,
USER_ENGINE_FLEX_AUTH_* env names and /opt/flex-auth/... paths.
The only repository-coordinate references are the two image pins in
sso-mfa/k8s/tenant-engine/runtime.yaml and the historical
workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md.
Finding, recorded and not changed: the declared image digests differ from the live ones.
| Deployment | Declared | Live |
|---|---|---|
flex-auth-tenant-engine |
c25fc34a… |
05a03a87… |
flex-auth-user-engine |
1f529037… |
138aa347… |
Which side is current has not been established. Reconciling them is a separate decision with flex-auth. Re-applying the declared file as it stands would replace the running images.
Confirm the image-pull path survives the rename
id: NK-WP-0039-T02
status: wait
priority: high
The image path is coulomb/flex-auth, which is also the repository name.
Before the rename lands, flex-auth confirms one of these:
- the container package is owner-scoped and keeps resolving as
coulomb/flex-auth, so digest pulls survive a pod reschedule; or - the package moves, and flex-auth names the new coordinate and the cut-over window.
Waiting on flex-auth under FLEX-WP-0020.
Update repository-coordinate references once access-engine resolves
id: NK-WP-0039-T03
status: wait
priority: medium
Once flex-auth announces that coulomb/access-engine resolves, update
references to the repository coordinate. If the image coordinate
changes, update the two image pins in sso-mfa/k8s/tenant-engine/runtime.yaml
in the same change as the digest reconciliation from T01. Applying that live
needs the founder's go-ahead. Leave runtime names and historical records
unchanged.