Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
177 lines
7.9 KiB
Markdown
177 lines
7.9 KiB
Markdown
---
|
|
id: NK-WP-0039
|
|
type: workplan
|
|
title: "Take in the flex-auth to access-engine repository-coordinate rename"
|
|
domain: infotech
|
|
repo: net-kingdom
|
|
status: blocked
|
|
flavor: implementation
|
|
owner: claude-code
|
|
topic_slug: netkingdom
|
|
created: "2026-09-23"
|
|
updated: "2026-09-28"
|
|
related: [FLEX-WP-0020, FLEX-DEC-2026-013, NK-WP-0026]
|
|
state_hub_workstream_id: "284a8ac2-61dc-5bee-b74a-0a62d9808edb"
|
|
---
|
|
|
|
Intake for the flex-auth handoff request (hub message `3bc95c76`, surface
|
|
`deployment`). flex-auth renames its repository coordinate
|
|
`coulomb/flex-auth` to `coulomb/access-engine`. The repository UUID
|
|
`fda8ad85-a7d7-4055-8f21-902a533e59df` and Forge ID 42 stay. Runtime names stay
|
|
`flex-auth` (FLEX-DEC-2026-013): namespace, Deployments, Services, labels,
|
|
token audience, env names and in-image paths are not renamed.
|
|
|
|
This workplan does not authorize a runtime rename, image-coordinate change or
|
|
rollout.
|
|
|
|
## Verify live flex-auth Deployments and sso-mfa/k8s
|
|
|
|
```task
|
|
id: NK-WP-0039-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "adfaa07d-dd15-50a6-a781-7cee2772fc90"
|
|
```
|
|
|
|
Read-only check on railiance01 (node `92.205.62.239`) on 2026-09-23. The
|
|
`flex-auth` namespace runs six Deployments, all 1/1:
|
|
`informed-decision-sitting`, `informed-decision-t03`, `ops-warden`,
|
|
`secrets-engine`, `tenant-engine` and `user-engine`, each prefixed
|
|
`flex-auth-`. Every one pulls
|
|
`forgejo.coulomb.social/coulomb/flex-auth@sha256:…`.
|
|
|
|
At the September 23 inventory, NetKingdom declared two of them in `sso-mfa/k8s/tenant-engine/runtime.yaml`
|
|
(`flex-auth-tenant-engine`, `flex-auth-user-engine`). Everything else under
|
|
`sso-mfa/k8s/**` that names flex-auth is a runtime name that stays: the
|
|
namespace, Service DNS `flex-auth-user-engine.flex-auth.svc.cluster.local`,
|
|
the `flex-auth-caller` projected token and its `flex-auth` audience, labels,
|
|
`USER_ENGINE_FLEX_AUTH_*` env names and `/opt/flex-auth/...` paths.
|
|
|
|
The only repository-coordinate references are the two image pins in
|
|
`sso-mfa/k8s/tenant-engine/runtime.yaml` and the historical
|
|
`workplans/NK-WP-0026-flex-auth-caller-identity-rollout.md`.
|
|
|
|
Finding, recorded and not changed: the declared image digests differ from
|
|
the live ones.
|
|
|
|
| Deployment | Declared | Live |
|
|
| --- | --- | --- |
|
|
| `flex-auth-tenant-engine` | `c25fc34a…` | `05a03a87…` |
|
|
| `flex-auth-user-engine` | `1f529037…` | `138aa347…` |
|
|
|
|
Resolved 2026-09-23 (flex-auth reply `28d9c6ca`): live is correct. `05a03a87`
|
|
was promoted 2026-09-11 for NK-WP-0036-T03 (flex-auth evidence
|
|
`docs/evidence/2026-09-11-user-portal-tenant-policy.md`); `138aa347` has been
|
|
live since 2026-08-19 (FLEX-WP-0015-T02). flex-auth's source of truth is
|
|
`values/<consumer>.yaml` in flex-auth. `runtime.yaml` was updated to those live
|
|
digests. T04 later removes the obsolete flex-auth reference objects entirely.
|
|
|
|
## Confirm the image-pull path survives the rename
|
|
|
|
```task
|
|
id: NK-WP-0039-T02
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "73e98d7a-bff6-5111-93b1-f36938ab624f"
|
|
```
|
|
|
|
The image path is `coulomb/flex-auth`, which is also the repository name.
|
|
Before the rename lands, flex-auth confirms one of these:
|
|
|
|
- the container package is owner-scoped and keeps resolving as
|
|
`coulomb/flex-auth`, so digest pulls survive a pod reschedule; or
|
|
- the package moves, and flex-auth names the new coordinate and the cut-over
|
|
window.
|
|
|
|
Answered 2026-09-23 (flex-auth `28d9c6ca`): the package stays resolvable as
|
|
`coulomb/flex-auth`. Forgejo packages are scoped to the owner, not the
|
|
repository, and FLEX-WP-0020 keeps the package coordinate. There is no new
|
|
coordinate and no cut-over window. FLEX-WP-0020 T09 verifies publication and
|
|
pulls after the rename. The image pins do not change because of the rename.
|
|
|
|
## Update repository-coordinate references once access-engine resolves
|
|
|
|
```task
|
|
id: NK-WP-0039-T03
|
|
status: wait
|
|
priority: medium
|
|
state_hub_task_id: "6e62919d-117d-57ab-b55b-1b437a105402"
|
|
```
|
|
|
|
Once flex-auth announces that `coulomb/access-engine` resolves, verify
|
|
repository-coordinate references against the retained runtime/package contract.
|
|
T02 confirms image coordinates stay unchanged; do not schedule image-pin
|
|
changes or a rollout as part of this rename. Leave historical records intact.
|
|
|
|
T04 now introduces explicit owner-repository links in
|
|
`sso-mfa/k8s/tenant-engine/README.md` and a repository coordinate in the YAML
|
|
header. After the rename announcement, update these pointers to the confirmed
|
|
new repository/checkout, verify both value-file paths resolve and preserve the
|
|
runtime/package names. NK-WP-0026 remains a historical record.
|
|
|
|
## Retire or reconcile the stale flex-auth/tenant-engine reference manifest
|
|
|
|
```task
|
|
id: NK-WP-0039-T04
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "2541f523-e433-5900-b119-5825f0e71ef3"
|
|
```
|
|
|
|
**Historical hold, superseded in part by the September 28 review below.** Routed the retire-vs-reconcile question to flex-auth
|
|
(`2c637dc9-14ad-4815-aeb4-43254d01280c`) and tenant-engine
|
|
(`9fc740da-1966-4d39-a28a-79fd4870edb1`). NetKingdom will act on whichever
|
|
answer comes back (retire and point to their authoritative declarations, or
|
|
keep a narrower reference); it should not pre-empt their decision by
|
|
deleting or editing the file first.
|
|
|
|
A read-only `kubectl diff` of `sso-mfa/k8s/tenant-engine/runtime.yaml`
|
|
against railiance01 on 2026-09-23 showed live ahead of the file beyond the
|
|
digests. flex-auth runs with `--caller-auth-mode enforce` and caller
|
|
bindings. tenant-engine runs image `a8e8086f…` (file: `2249e8c6…`) with a
|
|
different strategy, PVC mount and env. The egress rules also differ. No script
|
|
applies the file. It now carries a DO-NOT-APPLY header, because applying it
|
|
would drop caller-auth enforcement.
|
|
|
|
Decide with flex-auth and tenant-engine whether NetKingdom keeps a reference
|
|
copy. The recommendation is to replace it with pointers to the owners'
|
|
declarations (ADR-0015) rather than reconcile it field by field.
|
|
|
|
### Implementation — 2026-09-28
|
|
|
|
The approved flex-auth portion is complete. Removed seven reference objects:
|
|
the flex-auth Namespace and both consumers' Deployment, Service and
|
|
NetworkPolicy objects. Added exact links to `flex-auth/values/tenant-engine.yaml`,
|
|
`flex-auth/values/user-engine.yaml` and `charts/flex-auth` in the adjacent README.
|
|
Their caller enforcement and bindings stay owned by those declarations.
|
|
|
|
The five tenant-engine objects are structurally unchanged and retain the
|
|
DO-NOT-APPLY header. Repository script/workflow/Makefile searches found no
|
|
consumer of this combined manifest; the user-engine verifier uses its own
|
|
separate runtime file. Parsed before/after YAML proves only the seven approved
|
|
objects were removed. Owner links resolve locally and both value files declare
|
|
`callerAuth.mode: enforce`. No cluster apply, rollout or runtime rename occurred.
|
|
|
|
T04 returns to `wait` solely for tenant-engine's disposition of its remaining
|
|
objects; T03 waits for the repository rename. With no remaining locally
|
|
executable task in this plan, its status is `blocked` again.
|
|
|
|
## Infrastructure review — 2026-09-28
|
|
|
|
Flex-auth replied September 27 in message
|
|
`77b26d1e-550b-4926-9610-44fc3a566273`: no objection to replacing its
|
|
reference objects with pointers to authoritative `values/<consumer>.yaml`.
|
|
At the review baseline, T04 had a locally actionable flex-auth portion and
|
|
was `todo`; the plan was `active`. The implementation above supersedes that
|
|
status. Preserve the DO-NOT-APPLY guard. Retire only those flex-auth reference
|
|
objects when implementing that portion, with exact owner pointers and a check
|
|
that no application path consumes them. Tenant-engine's portion still awaits
|
|
its owner answer; do not treat flex-auth's response as authority over it.
|
|
T04 closes only when both portions are resolved.
|
|
|
|
Live read-only checks confirm all six flex-auth Deployments are ready and
|
|
enforce caller authentication. Applying the stale reference would risk losing
|
|
that protection. FLEX-WP-0020 still holds rename execution at T06; T03 stays
|
|
`wait`, independently of this reference cleanup.
|
|
|
|
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).
|