net-kingdom/sso-mfa/k8s/tenant-engine/README.md
tegwick 9383b94019 Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:03 +02:00

1.8 KiB

Tenant Engine integration references

runtime.yaml is REFERENCE ONLY — DO NOT APPLY. Its five remaining Tenant Engine objects are historical and differ from the live deployment in image, storage, strategy, environment and egress. Their disposition awaits the Tenant Engine owner under NK-WP-0039-T04.

The obsolete flex-auth objects were removed on 2026-09-28 with the owner's agreement. Use the owner's maintained declarations and deployment procedure:

Consumer Authoritative values in the flex-auth repository
Tenant Engine values/tenant-engine.yaml
User Engine values/user-engine.yaml

The owner Helm chart renders the consumer Deployment, Service and NetworkPolicy, including caller-auth configuration. Both reviewed value files select enforcement and bind the consumer to its own Kubernetes ServiceAccount. Keep those settings at their owner; do not recreate a frozen deployment copy here.

These links assume sibling checkouts. The current repository coordinate is coulomb/flex-auth; its proposed rename to coulomb/access-engine remains gated by FLEX-WP-0020. NK-WP-0039-T03 will update these repository pointers when the owner confirms the new coordinate. The flex-auth namespace, Service DNS, caller-token audience and OCI package coordinate remain unchanged.

Ownership follows ADR-0015. Removing references requires no cluster apply or rollout. Do not use the remaining YAML as a way to provision the two flex-auth consumers.