net-kingdom/sso-mfa/k8s
tegwick 63e3bb6f7d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 12s
Refresh operating guidance and standardize new workplan naming
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:10 +02:00
..
authelia Fix plus-address sign-in and finish NK-WP-0041 2026-09-27 16:05:03 +02:00
backup Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
cert-manager custodian integration and some cleanuo 2026-03-04 23:31:28 +01:00
identity-provisioner Pin identity-provisioner main-6c4fcaf (password-setup usability) as deployed 2026-09-24 01:19:48 +02:00
keycape Deploy explicit Railiance admin role mapping for alert receipts 2026-09-28 11:11:34 +02:00
lldap ops: record native tenant success and prepare attended identity repair 2026-09-11 21:41:26 +02:00
namespaces feat(sso-mfa): T02 K8s foundations manifests (NK-WP-0001-T02) 2026-03-02 09:49:39 +01:00
network-policies Let the account site read an existing Authelia sign-in. 2026-09-27 00:22:53 +02:00
postgresql Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
privacyidea Implement scoped P06 authentication policy and guarded optional onboarding 2026-09-14 00:00:09 +02:00
storage feat(sso-mfa): T02 K8s foundations manifests (NK-WP-0001-T02) 2026-03-02 09:49:39 +01:00
tenant-engine Reconcile infrastructure workplans and retire stale flex-auth references 2026-09-28 12:40:03 +02:00
user-engine Record verified P05 rollout and service recovery acceptance 2026-09-13 22:31:16 +02:00
FOUNDATIONS-HISTORICAL.md Refresh operating guidance and standardize new workplan naming 2026-09-28 12:40:10 +02:00
README.md Refresh operating guidance and standardize new workplan naming 2026-09-28 12:40:10 +02:00
verify-identity-cutover-dependencies.sh Verify railiance01 identity dependencies 2026-07-28 12:59:12 +02:00
verify-t02.sh Allow user-engine OIDC exchange with KeyCape 2026-07-29 21:40:52 +02:00
verify-t03.sh feat(sso-mfa): T02/T03 live apply — age-encrypted secrets, CNPG cluster (NK-WP-0001-T02/T03) 2026-03-20 02:57:41 +00:00
verify-t04.sh docs(sso-mfa): fix stale Keycloak refs and add T04 apply section to WORKPLAN 2026-03-20 07:33:47 +00:00
verify-t05.sh feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05) 2026-03-19 08:31:51 +00:00
verify-t06.sh Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
verify-t07.sh Retire bao.coulomb.social callbacks from the KeyCape openbao-admin client 2026-09-23 19:41:35 +02:00
verify-t08.sh feat(t09): backup, break-glass, DR drill — NK-WP-0003-T09 done 2026-03-25 23:56:40 +00:00

NetKingdom Kubernetes integration guidance

This directory holds bootstrap tooling, integration references and migration history. Current managed deployment belongs to the service/package owners under ADR-0015. The original foundation procedure is retained as historical material, including its old prerequisites and apply commands.

Operating baseline

The September 28 review observed one Ready Railiance01 node at 92.205.62.239, healthy lightweight identity components and single-instance CNPG databases. This is a dated inventory, not an HA, recovery or user-login acceptance claim.

Surface Current role and owner
KeyCape / Authelia / LLDAP (sso) and privacyIDEA (mfa) Lightweight identity composition; issuer implementation in key-cape, integration contracts here
User Engine rapp-user-engine owns managed manifests, rollout and rollback
Tenant Engine rapp-tenant-engine owns managed runtime and database-consumption configuration
flex-auth consumer services Owner values and chart pointers; caller authentication is enforced by the owner declarations
OpenBao and database custody railiance-platform, with managed packages and consumer declarations in their owning repositories
Kubernetes and host substrate railiance-cluster operator runbook and railiance-infra

OpenBao's public browser endpoint bao.coulomb.social is retired. Operators use the named openbao-ui-railiance01 tunnel at http://127.0.0.1:18200; workloads use the internal Service. Follow the platform's operator-only cutover record and credential routing in AGENTS.md. Route access before requesting credentials; never copy tokens or Secret values into evidence.

Read-only orientation

Check the context before interpreting these results. All commands below read resource metadata and readiness; none applies manifests or initiates login.

kubectl config current-context
kubectl get nodes -o wide
kubectl -n sso get deployments
kubectl -n mfa get deployments
kubectl -n user-engine get deployments
kubectl -n tenant-engine get deployments
kubectl -n flex-auth get deployments
kubectl -n openbao get statefulsets,deployments,services,ingresses
kubectl get clusters.postgresql.cnpg.io -A

Ready replicas do not prove negative authorization, actual-user MFA, successful backup restoration or independent failure domains. Use the relevant owner's verification and recovery procedure for those claims.

Deployment and recovery

Start with the owning package's current declaration, immutable image and reviewed rollout/rollback procedure. Do not recursively apply this tree. tenant-engine/runtime.yaml remains REFERENCE ONLY — DO NOT APPLY while its owner decides the disposition of the five retained historical objects. Its obsolete flex-auth objects have been replaced with owner pointers.

The scripts and manifests elsewhere in this directory have individual scopes; their presence here does not make them current production repair commands. The attended procedure inventory records their exercise limits. Use the custody model and current owner runbooks to prepare recovery. A database-only drill does not prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption material, or all identity database state.

CoulombCore identity cutover is complete; final retained-resource deletion remains gated by NK-WP-0022. Expiration of the retention minimum does not authorize deletion.