net-kingdom/workplans/NK-WP-0023-user-engine-portal-platform-integration.md
tegwick abc92a1197
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Sequence identity portal before stack cutover
2026-07-27 22:30:02 +02:00

4.1 KiB

id type title domain repo status owner topic_slug created updated depends_on
NK-WP-0023 workplan Integrate and deploy the user-engine onboarding portal infotech net-kingdom ready codex netkingdom 2026-07-27 2026-07-27
USER-WP-0020
KEY-WP-0004

NK-WP-0023 - user-engine portal platform integration

Provide the NetKingdom-owned adapters and production integration required by USER-WP-0020, using the Binky tenant-admin onboarding from KEY-WP-0004-T02 as the first acceptance case.

T01 - Define source-of-truth and provisioning contracts

id: NK-WP-0023-T01
status: todo
priority: high

Ratify lifecycle sequencing and compensation across user-engine, LLDAP, KeyCape, privacyIDEA, flex-auth, email verification, audit, and outbox delivery. user-engine owns user-domain and membership intent; NetKingdom IAM owns credentials, authentication factors, coarse authentication claims, and provider subjects. Define externally-provisioned/federated ownership metadata now so later enterprise directories do not require a domain rewrite.

T02 - Implement the NetKingdom identity provisioning adapter

id: NK-WP-0023-T02
status: wait
priority: high

Implement idempotent create/link/suspend/reactivate/deprovision operations for the lightweight LLDAP + privacyIDEA stack behind user-engine's IdentityProvisioningPort. Use scoped service identity and approved secret transport. Never expose directory admin credentials to the browser or user-engine domain. Add reconciliation, retry, compensation, and drift reporting rather than assuming a distributed transaction.

T03 - Integrate KeyCape login, claims, and MFA handoffs

id: NK-WP-0023-T03
status: wait
priority: high

Register the portal OIDC client with authorization code + PKCE, configure callback/logout routes, verify issuer/audience/tenant/assurance claims, and provide safe password and MFA enrollment/recovery handoffs. Preserve platform-root separation and ensure tenant administration never implies platform authority.

T04 - Integrate authorization, email, audit, and events

id: NK-WP-0023-T04
status: wait
priority: high

Define and implement flex-auth resources/actions for self, tenant-admin, and platform-admin operations; route verification/invitation email without making mailbox ownership an authorization fact; correlate user-engine, IAM, authorization, and platform audit records; and connect durable outbox delivery with replay and dead-letter evidence.

T05 - Deploy on reef-railiance

id: NK-WP-0023-T05
status: wait
priority: high

Package the portal as a managed platform workload on the default rail-kubernetes path on reef-railiance, with Postgres, OpenBao-backed runtime references, NetworkPolicies, TLS ingress, backups, observability, resource limits, rollout/rollback, and availability evidence. Do not place this stateful platform control surface on scale-to-zero Knative.

T06 - Prove role-scoped administration and failure safety

id: NK-WP-0023-T06
status: wait
priority: high

Run end-to-end conformance for registration, login, MFA, tenant creation, first-admin bootstrap, invitations, suspension/reactivation, cross-tenant denial, platform-admin-only actions, provider outages, replay/idempotency, backup restore, and reconciliation after partial failure.

T07 - Complete KEY-WP-0004 through the reusable portal

id: NK-WP-0023-T07
status: wait
priority: high

Use the production portal to onboard bernd.worsch@binky-hedgehog.com into tenant:friendly:binky, complete OIDC/PKCE + MFA, and verify the Binky-only tenant-admin token and lifecycle controls. Publish only non-secret evidence to KEY-WP-0004-T02/T07, then finish that workplan.

T08 - Document enterprise integration extension points

id: NK-WP-0023-T08
status: wait
priority: medium

Document later adapters for customer IdPs/directories, SAML/OIDC federation, SCIM, JIT provisioning, directory group mapping, customer-owned offboarding, and conflict/freshness rules. Keep NK-WP-0011 demand-triggered; this task defines compatibility seams, not enterprise implementation.