net-kingdom/sso-mfa/k8s/user-engine
tegwick a58df4c3e6
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Advance pre-cutover identity conformance
2026-07-28 16:48:47 +02:00
..
ingress.yaml Deploy KeyCape-backed portal login edge 2026-07-28 00:39:22 +02:00
README.md Deploy internal user-engine portal foundation 2026-07-27 23:24:36 +02:00
runtime.yaml Advance pre-cutover identity conformance 2026-07-28 16:48:47 +02:00

user-engine portal on reef-railiance

This is a stateful rail-kubernetes platform workload. It intentionally has no public Ingress until the KeyCape authorization-code/PKCE edge and user-engine-portal client are configured. Direct access to protected routes must remain impossible because the application accepts identity only from a trusted edge marker plus verified claims.

For the current pre-production bootstrap the image is imported directly into k3s and uses imagePullPolicy: Never. Replace it with the immutable Forgejo OCI digest after the OpenBao package-publisher lane is available.

The CloudNativePG operator creates user-engine-pg-app, including its uri field. user-engine-runtime contains only the generated edge marker and must be replaced by an ExternalSecret before public exposure.

kubectl apply -f runtime.yaml
kubectl -n user-engine rollout status deployment/user-engine
kubectl -n user-engine get cluster,pod,service,networkpolicy

Rollback sets the Deployment image to the preceding immutable digest. Database migrations are additive and run before serving; restore uses the standard CNPG recovery contract once the offsite object-store reference is attached.