Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
4 KiB
NetKingdom Kubernetes integration guidance
This directory holds bootstrap tooling, integration references and migration history. Current managed deployment belongs to the service/package owners under ADR-0015. The original foundation procedure is retained as historical material, including its old prerequisites and apply commands.
Operating baseline
The September 28 review
observed one Ready Railiance01 node at 92.205.62.239, healthy lightweight
identity components and single-instance CNPG databases. This is a dated
inventory, not an HA, recovery or user-login acceptance claim.
| Surface | Current role and owner |
|---|---|
KeyCape / Authelia / LLDAP (sso) and privacyIDEA (mfa) |
Lightweight identity composition; issuer implementation in key-cape, integration contracts here |
| User Engine | rapp-user-engine owns managed manifests, rollout and rollback |
| Tenant Engine | rapp-tenant-engine owns managed runtime and database-consumption configuration |
| flex-auth consumer services | Owner values and chart pointers; caller authentication is enforced by the owner declarations |
| OpenBao and database custody | railiance-platform, with managed packages and consumer declarations in their owning repositories |
| Kubernetes and host substrate | railiance-cluster operator runbook and railiance-infra |
OpenBao's public browser endpoint bao.coulomb.social is retired. Operators
use the named openbao-ui-railiance01 tunnel at http://127.0.0.1:18200;
workloads use the internal Service. Follow the platform's
operator-only cutover record
and credential routing in AGENTS.md. Route access before
requesting credentials; never copy tokens or Secret values into evidence.
Read-only orientation
Check the context before interpreting these results. All commands below read resource metadata and readiness; none applies manifests or initiates login.
kubectl config current-context
kubectl get nodes -o wide
kubectl -n sso get deployments
kubectl -n mfa get deployments
kubectl -n user-engine get deployments
kubectl -n tenant-engine get deployments
kubectl -n flex-auth get deployments
kubectl -n openbao get statefulsets,deployments,services,ingresses
kubectl get clusters.postgresql.cnpg.io -A
Ready replicas do not prove negative authorization, actual-user MFA, successful backup restoration or independent failure domains. Use the relevant owner's verification and recovery procedure for those claims.
Deployment and recovery
Start with the owning package's current declaration, immutable image and
reviewed rollout/rollback procedure. Do not recursively apply this tree.
tenant-engine/runtime.yaml remains REFERENCE ONLY — DO NOT APPLY while
its owner decides the disposition of the five retained historical objects.
Its obsolete flex-auth objects have been replaced with owner pointers.
The scripts and manifests elsewhere in this directory have individual scopes; their presence here does not make them current production repair commands. The attended procedure inventory records their exercise limits. Use the custody model and current owner runbooks to prepare recovery. A database-only drill does not prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption material, or all identity database state.
CoulombCore identity cutover is complete; final retained-resource deletion remains gated by NK-WP-0022. Expiration of the retention minimum does not authorize deletion.