net-kingdom/sso-mfa/k8s/README.md
tegwick 63e3bb6f7d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 12s
Refresh operating guidance and standardize new workplan naming
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:10 +02:00

4 KiB

NetKingdom Kubernetes integration guidance

This directory holds bootstrap tooling, integration references and migration history. Current managed deployment belongs to the service/package owners under ADR-0015. The original foundation procedure is retained as historical material, including its old prerequisites and apply commands.

Operating baseline

The September 28 review observed one Ready Railiance01 node at 92.205.62.239, healthy lightweight identity components and single-instance CNPG databases. This is a dated inventory, not an HA, recovery or user-login acceptance claim.

Surface Current role and owner
KeyCape / Authelia / LLDAP (sso) and privacyIDEA (mfa) Lightweight identity composition; issuer implementation in key-cape, integration contracts here
User Engine rapp-user-engine owns managed manifests, rollout and rollback
Tenant Engine rapp-tenant-engine owns managed runtime and database-consumption configuration
flex-auth consumer services Owner values and chart pointers; caller authentication is enforced by the owner declarations
OpenBao and database custody railiance-platform, with managed packages and consumer declarations in their owning repositories
Kubernetes and host substrate railiance-cluster operator runbook and railiance-infra

OpenBao's public browser endpoint bao.coulomb.social is retired. Operators use the named openbao-ui-railiance01 tunnel at http://127.0.0.1:18200; workloads use the internal Service. Follow the platform's operator-only cutover record and credential routing in AGENTS.md. Route access before requesting credentials; never copy tokens or Secret values into evidence.

Read-only orientation

Check the context before interpreting these results. All commands below read resource metadata and readiness; none applies manifests or initiates login.

kubectl config current-context
kubectl get nodes -o wide
kubectl -n sso get deployments
kubectl -n mfa get deployments
kubectl -n user-engine get deployments
kubectl -n tenant-engine get deployments
kubectl -n flex-auth get deployments
kubectl -n openbao get statefulsets,deployments,services,ingresses
kubectl get clusters.postgresql.cnpg.io -A

Ready replicas do not prove negative authorization, actual-user MFA, successful backup restoration or independent failure domains. Use the relevant owner's verification and recovery procedure for those claims.

Deployment and recovery

Start with the owning package's current declaration, immutable image and reviewed rollout/rollback procedure. Do not recursively apply this tree. tenant-engine/runtime.yaml remains REFERENCE ONLY — DO NOT APPLY while its owner decides the disposition of the five retained historical objects. Its obsolete flex-auth objects have been replaced with owner pointers.

The scripts and manifests elsewhere in this directory have individual scopes; their presence here does not make them current production repair commands. The attended procedure inventory records their exercise limits. Use the custody model and current owner runbooks to prepare recovery. A database-only drill does not prove restoration of LLDAP, Authelia, privacyIDEA and its matching encryption material, or all identity database state.

CoulombCore identity cutover is complete; final retained-resource deletion remains gated by NK-WP-0022. Expiration of the retention minimum does not authorize deletion.