net-kingdom/history/2026-09-28-open-workplan-infrastructure-review.md
tegwick 9383b94019 Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:03 +02:00

13 KiB

Open workplans versus infrastructure — 2026-09-28

Reviewed all ten nonterminal root workplans (eight blocked, two backlog). Initial review result: one finished, one active, six blocked, two backlog. The follow-through section below records subsequent implementation and statuses. Existing task IDs and State Hub UUIDs are preserved. This is a planning reconciliation; no runtime, credential, policy, DNS or destructive change was performed.

Evidence boundary

Read-only kubectl checks against context default found one Ready node at 92.205.62.239, Kubernetes v1.35.1+k3s1. KeyCape, Authelia, LLDAP, privacyIDEA, user-engine, tenant-engine and audit-core each had one ready Deployment replica. All six flex-auth consumer Deployments were ready and contained --caller-auth-mode enforce. This is configuration/readiness proof, not fresh user login, negative authorization or recovery testing.

All eight CNPG clusters reported one instance and one ready instance: apps-pg, forgejo-db, net-kingdom-pg, platform-pg, platform-pg-2, state-hub-db, target-revenue-pg and user-engine-pg. A healthy single-node cluster does not prove HA or off-host recovery. No Keycloak Deployment was present.

OpenBao StatefulSet and UI gateway were ready; gateway/API Services were ClusterIP and the namespace had no Ingress. CoulombCore, retained backup contents, public DNS withdrawal and browser sessions were not reverified. Owner receipts below support historical completion, not a fresh execution. Sibling repositories were inspected as available local checkouts; their state was not assumed to be a newly fetched remote head.

The State Hub inbox supplied flex-auth's September 27 approval of its reference cleanup (77b26d1e-550b-4926-9610-44fc3a566273); it was marked read. The human-needed task query returned no NK-/NET-prefixed records. This does not remove the explicit approval gate written in NK-WP-0022. Topic-wide active workplans include other repositories and are not the NetKingdom plan inventory.

Plan dispositions at the initial review

Plan Updated state and next acceptance gate
0009 tutorials Backlog. Start with existing private OpenBao and SSH paths, caller-auth refusal checks and executable verification. STS tutorial needs an actual owner-backed service.
0011 federation Backlog. Correct issuer to kc.coulomb.social, accepted IAM to v0.3, database admission and managed-package ownership. Require a named enterprise demand before broker implementation.
0022 retirement Blocked. Cutover was completed in July; August 29 retention minimum has elapsed. T08 still needs retained-resource inventory, identity recovery evidence and explicit deletion approval.
0027 reef/posture Blocked. Carrier agreement still absent. Include railiance-infra as substrate owner. Public classification exists upstream; maturity mapping versus synthetic provenance remains unresolved.
0031 freshness Blocked. Audit Core still lacks structured owner/freshness fields; September V1 recovery evidence does not replace August E2 boundary evidence.
0032 Bao callback Finished. T03/T04 closed from September 15 callback/login receipts and September 22 platform handoff. Public callback rollback text is historical.
0035 cadence Blocked. Update upstream version/pin metadata; migrate source envelopes and obtain real observer evidence. Include local-identity's known profile incompatibility.
0039 rename/reference Active. T04 now has an actionable flex-auth reference-cleanup portion. Tenant-engine agreement and T03 rename notification remain separate gates.
0040 execution receipt Blocked. Agree emitter/custodian/schema; require an actual run-to-audit receipt proof, preserving unknown attribution and clock bounds.
0042 step-up Blocked. Reuse delivered P06 enrollment and scoped optional policies; agree and accept one workload's step-up/recovery journey.

The two oldest plans now have one task per second-level section, conforming to the file-backed workplan format. Completed implementation tasks were not reopened merely because their historical validation dates are old.

Necessary changes and conflicts

  1. Stale deployment copies can remove a live security control. sso-mfa/k8s/tenant-engine/runtime.yaml lacks live caller enforcement and other owner changes. Keep DO-NOT-APPLY. Flex-auth approved pointers to its values/<consumer>.yaml; tenant-engine's portion remains separately owned. Repository rename does not rename the runtime, token audience or OCI package. Source: FLEX-WP-0020 (locate by workplan ID if the owner filename changes), inbox receipt above.
  2. Recovery claims must follow the actual failure domain. Reef declarations still omit provider ceilings; one node and single-instance databases cannot establish independent failover. Proposed V0/V1 carrier semantics require owner agreement and workload evidence. A platform database drill does not satisfy full identity restoration for destructive retirement. Sources: reef declaration, provider proposal.
  3. Declared evidence remains behind runtime improvements. Audit Core's tenancy file still describes flex-auth as unauthenticated A0, despite the observed enforcement flags. Its E2 review metadata is unstructured and old. Have the owner reconcile this; do not infer A/E upgrades from flags or tests. Source: audit tenancy.
  4. Generic cadence validity is not profile compliance or observation. Approval Engine and Qonto still fail the owner schema. Local-identity passes that schema but fails the rare-class heartbeat obligation when its source inventory is explicitly supplied. Audit Core holds no local-identity feed. Upstream corrected its candidate bundle digest; profile and declaration metadata need reconciliation without changing historical findings. Sources: local findings, upstream review.
  5. Existing MFA work and proposed generic step-up are different scopes. P06 already delivered optional policies for two clients, enrollment checks and privileged guards. IAM v0.4 remains proposed; it is not evidence of arbitrary workload step-up support. Reuse the implementation and close the pilot UX/interop gap. Sources: USER-WP-0033, KEY-WP-0035 and P06 evidence.
  6. Public Bao is retired. September 24 removed public role callbacks; current client source rejects their return. Do not repeat completed login admission or preserve public URLs as a future default. DNS withdrawal is a railiance-infra residual. Sources: callback receipt, login/retraction receipt, callback pruning, platform closure.
  7. Accepted canon and proposals must stay distinct. IAM v0.3, Playbook Capability v0.1 and security layer v0.7 remain the accepted baselines; proposed amendments do not authorize runtime implementation or replace owner agreement. New federation work must follow ADR-0015 packaging and current tenant identity contracts, not the original greenfield assumptions.

Most valuable future implementation

Recommended order; this is prioritization, not approval of deployment or deletion.

  1. Remove stale reference authority (0039). Small, locally actionable work that prevents a caller-auth regression. Replace the approved flex-auth objects with exact owner pointers; finish tenant-engine's portion after its answer. No rollout is needed.
  2. Close one real workload MFA journey (0042). High user value with existing provider work available. Pick a pilot with its owner, demonstrate enrollment, return to action, recovery and denial with stale/insufficient assurance. Coordinate existing actual-user gates rather than create another onboarding implementation.
  3. Make evidence freshness and emission operational (0031 + 0035). Add authoritative metadata first, then migrate a source already sending to Audit Core and prove heartbeat/reconciliation through its observer. This makes missing or stale security evidence detectable. Resolve local-identity activity-scope incompatibility explicitly; do not force a bootstrap tool into a permanent service just to pass the profile.
  4. Bind a real execution to evidence (0040). Agree the receipt and implement one Railiance emitter/receiver integration with actor, artifact, decision, approval and bounded time. This unblocks clock attribution and gives more value than a schema-only finish.
  5. Mechanize recovery ceilings and finish retirement safely (0027 + 0022). Agree reef provider declarations, implement the three-valued join, and use measured recovery evidence. Prepare the exact old identity deletion package only after its recovery gate passes; approval remains a separate final step.

Tutorials should capture these proven paths incrementally. Enterprise federation is lower priority until a concrete tenant/IdP demand justifies its additional issuer, trust mapping, database and recovery burden.

Validation

  • Current read-only node, Deployment, CNPG and OpenBao resource inventories.
  • Existing cadence checker against the current owner schema: Approval Engine fails with three generic findings; Qonto fails with five. Local-identity is generic-valid; supplying both documented load-bearing/rare classes yields two rare-heartbeat-missing failures. Omitting inventory flags checks no rare-class obligations and must not be used to claim adoption.
  • Existing posture evaluator at explicit 2026-09-28T12:00:00Z confirms unknown owner/freshness and overdue review for audit-core. This is a chosen reproducible evaluation instant, not the observation timestamp.
  • Workplan frontmatter, task-ID preservation, task statuses and local Markdown links checked; authored files pass git diff --check. The generated brief retains its generator's Markdown hard-break whitespace. No application code changed.

State Hub lifecycle reconciliation classifies partially completed 0039 with an actionable task as active; its file follows that convention. Existing NK-WP/NET-WP prefix warnings are retained rather than renumbering historical work records. At the initial review, repository instructions contained conflicting prefix conventions. NK-WP-0043 subsequently standardized new plans on NK-WP while preserving historical IDs.

Follow-through — 2026-09-28

After the user requested implementation, the approved part of NK-WP-0039-T04 was completed: seven obsolete flex-auth objects were removed from the combined reference manifest and replaced with owner links in sso-mfa/k8s/tenant-engine/README.md. Parsed before/after YAML confirms all five tenant-engine objects are unchanged. No repository apply path consumes the combined manifest; the user-engine verifier uses its own file. Owner values enforce caller authentication and bind each consumer to its own ServiceAccount. The remaining YAML stays DO-NOT-APPLY. T04 now waits only for tenant-engine's disposition; T03 still waits for the rename. This returns 0039 to blocked: the current disposition of the original ten is one finished, seven blocked and two backlog.

The locally owned portion of NK-WP-0035-T04 also advanced: corrected the profile's imported document maturity/version/revision and the local-identity candidate bundle pin. The old pin and its correction remain in historical findings. Schema SHA-256 is unchanged. All 15 focused checker tests pass; explicit rare-class revalidation remains generic-valid with exactly two missing-heartbeat failures. The profile stays proposed and source/observer adoption remains open. No runtime or external-owner source was changed.