net-kingdom/sso-mfa/k8s/user-engine/README.md
tegwick f4f885289e
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
docs: point user-engine apply home at rapp-user-engine
2026-08-18 12:39:24 +02:00

2.6 KiB

user-engine portal on reef-railiance

Apply home moved. The managed package is rapp-user-engine. Render, deploy, verify, and rollback from that repo (make deploy, make verify-live). These files remain migration input until that package is the only checkout operators apply.

This is a stateful rail-kubernetes platform workload. It intentionally has no public Ingress until the KeyCape authorization-code/PKCE edge and user-engine-portal client are configured. Direct access to protected routes must remain impossible because the application accepts identity only from a trusted edge marker plus verified claims.

The portal image is published through the activity-core workload-scoped Forgejo package credential and deployed from forgejo.coulomb.social/coulomb/user-engine by immutable digest. The public package read was verified without an image pull Secret; publishing still uses the ExternalSecret-backed credential and temporary client state.

The CloudNativePG operator creates user-engine-pg-app, including its uri field. OpenBao is authoritative for the portal edge marker and provisioner service token at platform/workloads/user-engine/runtime. The openbao-runtime.yaml stores and ExternalSecrets deliver those values into the existing namespaced Secret names without changing application interfaces.

The audit-core sender and email-connect ingest credentials stay authoritative in their provider namespaces. Run tools/sync-user-engine-delivery-secret.sh from the repository root to copy only those scoped values into user-engine-delivery without printing them. Rerun it after either provider rotates its token, then restart user-engine because the application receives these two values as environment variables.

The desired runtime also projects a short-lived ServiceAccount token with audience flex-auth at /var/run/secrets/flex-auth-caller/token. user-engine re-reads it per policy decision; it is not a Kubernetes API credential and is not copied into a Secret. This manifest must be promoted with a user-engine image that understands USER_ENGINE_FLEX_AUTH_TOKEN_FILE and flex-auth desired state that binds system:serviceaccount:user-engine:user-engine. The current pinned digest predates that coordinated rollout.

kubectl apply -f openbao-runtime.yaml
kubectl apply -f runtime.yaml
kubectl -n user-engine rollout status deployment/user-engine
kubectl -n user-engine get cluster,pod,service,networkpolicy

Rollback sets the Deployment image to the preceding immutable digest. Database migrations are additive and run before serving; restore uses the standard CNPG recovery contract once the offsite object-store reference is attached.