net-kingdom/workplans/NK-WP-0039-flex-auth-access-engine-coordinate-intake.md
tegwick acf0820465
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
chore(consistency): record NK-WP-0039 hub task ids
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 20:02:48 +02:00

5.2 KiB

id type title domain repo status flavor owner topic_slug created updated related state_hub_workstream_id
NK-WP-0039 workplan Take in the flex-auth to access-engine repository-coordinate rename infotech net-kingdom active implementation claude-code netkingdom 2026-09-23 2026-09-23
FLEX-WP-0020
FLEX-DEC-2026-013
NK-WP-0026
284a8ac2-61dc-5bee-b74a-0a62d9808edb

Intake for the flex-auth handoff request (hub message 3bc95c76, surface deployment). flex-auth renames its repository coordinate coulomb/flex-auth to coulomb/access-engine. The repository UUID fda8ad85-a7d7-4055-8f21-902a533e59df and Forge ID 42 stay. Runtime names stay flex-auth (FLEX-DEC-2026-013): namespace, Deployments, Services, labels, token audience, env names and in-image paths are not renamed.

This workplan does not authorize a runtime rename, image-coordinate change or rollout.

Verify live flex-auth Deployments and sso-mfa/k8s

id: NK-WP-0039-T01
status: done
priority: high
state_hub_task_id: "adfaa07d-dd15-50a6-a781-7cee2772fc90"

Read-only check on railiance01 (node 92.205.62.239) on 2026-09-23. The flex-auth namespace runs six Deployments, all 1/1: informed-decision-sitting, informed-decision-t03, ops-warden, secrets-engine, tenant-engine and user-engine, each prefixed flex-auth-. Every one pulls forgejo.coulomb.social/coulomb/flex-auth@sha256:….

NetKingdom declares two of them in sso-mfa/k8s/tenant-engine/runtime.yaml (flex-auth-tenant-engine, flex-auth-user-engine). Everything else under sso-mfa/k8s/** that names flex-auth is a runtime name that stays: the namespace, Service DNS flex-auth-user-engine.flex-auth.svc.cluster.local, the flex-auth-caller projected token and its flex-auth audience, labels, USER_ENGINE_FLEX_AUTH_* env names and /opt/flex-auth/... paths.

The only repository-coordinate references are the two image pins in sso-mfa/k8s/tenant-engine/runtime.yaml and the historical workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md.

Finding, recorded and not changed: the declared image digests differ from the live ones.

Deployment Declared Live
flex-auth-tenant-engine c25fc34a… 05a03a87…
flex-auth-user-engine 1f529037… 138aa347…

Resolved 2026-09-23 (flex-auth reply 28d9c6ca): live is correct. 05a03a87 was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence docs/evidence/2026-09-11-user-portal-tenant-policy.md); 138aa347 has been live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is values/<consumer>.yaml in flex-auth. runtime.yaml now declares the live digests. See T04 for the rest of the drift.

Confirm the image-pull path survives the rename

id: NK-WP-0039-T02
status: done
priority: high
state_hub_task_id: "73e98d7a-bff6-5111-93b1-f36938ab624f"

The image path is coulomb/flex-auth, which is also the repository name. Before the rename lands, flex-auth confirms one of these:

  • the container package is owner-scoped and keeps resolving as coulomb/flex-auth, so digest pulls survive a pod reschedule; or
  • the package moves, and flex-auth names the new coordinate and the cut-over window.

Answered 2026-09-23 (flex-auth 28d9c6ca): the package stays resolvable as coulomb/flex-auth. Forgejo packages are scoped to the owner, not the repository, and FLEX-WP-0020 keeps the package coordinate. There is no new coordinate and no cut-over window. FLEX-WP-0020 T09 verifies publication and pulls after the rename. The image pins do not change because of the rename.

Update repository-coordinate references once access-engine resolves

id: NK-WP-0039-T03
status: wait
priority: medium
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"

Once flex-auth announces that coulomb/access-engine resolves, update references to the repository coordinate. If the image coordinate changes, update the two image pins in sso-mfa/k8s/tenant-engine/runtime.yaml in the same change as the digest reconciliation from T01. Applying that live needs the founder's go-ahead. Leave runtime names and historical records unchanged.

After T02, no in-repo coordinate reference needs to change: the image pins stay, and NK-WP-0026 is a historical record. This task waits only for flex-auth's announcement that access-engine resolves, which confirms that nothing else moved.

Retire or reconcile the stale flex-auth/tenant-engine reference manifest

id: NK-WP-0039-T04
status: todo
priority: high
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"

A read-only kubectl diff of sso-mfa/k8s/tenant-engine/runtime.yaml against railiance01 on 2026-09-23 showed live ahead of the file beyond the digests. flex-auth runs with --caller-auth-mode enforce and caller bindings. tenant-engine runs image a8e8086f… (file: 2249e8c6…) with a different strategy, PVC mount and env. The egress rules also differ. No script applies the file. It now carries a DO-NOT-APPLY header, because applying it would drop caller-auth enforcement.

Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference copy. The recommendation is to replace it with pointers to the owners' declarations (ADR-0015) rather than reconcile it field by field.