net-kingdom/workplans/NK-WP-0024-user-engine-portal-integration-expansion.md
custodian-sync b9f5fbd2f0 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-13:
  - NK-WP-0024-T03: wait → progress
2026-08-13 14:58:04 +02:00

158 lines
6.7 KiB
Markdown

---
id: NK-WP-0024
type: workplan
title: "Expand user-engine platform integrations beyond the Binky MVP"
domain: infotech
repo: net-kingdom
status: active
owner: codex
topic_slug: netkingdom
created: "2026-07-30"
updated: "2026-08-13"
depends_on:
- NK-WP-0023
- USER-WP-0021
- FLEX-WP-0009
- AUDIT-WP-0003
- EMAIL-WP-0004
state_hub_workstream_id: "9bd05700-a839-4014-8f88-8a78f2757721"
---
# NK-WP-0024 - Portal integration expansion
## 2026-08-13 completion review
This workplan was blocked at review time. On 2026-08-13 AUDIT-WP-0005
finished: the PostgreSQL-backed `audit-core` workload is Ready with archive
custody, OpenBao-backed sender/database lanes, restart/rollback evidence, and
a live failure matrix (12 passed, 0 failed, 3 production-disruption skips).
The workplan is active again.
The audit dependency recorded above is stale operationally: AUDIT-WP-0003
finished only after cancelling its deployment tasks. Production custody and
the live matrix moved to the now-finished AUDIT-WP-0005.
A consumer-side credential-isolation defect was found and fixed before
activation. The previous user-engine `HTTPOutboxDeliveryAdapter` accepted one
`USER_ENGINE_DELIVERY_TOKEN` for both receivers. audit-core and email-connect
are separately scoped receivers and must not share a bearer credential; the
adapter now accepts distinct event and mail tokens.
Track deferred integration breadth separately from the completed live MVP.
Activate with the corresponding user-engine product-expansion tasks.
Provider workplans established 2026-08-08:
- `FLEX-WP-0009` provides the user-engine policy package and cluster service.
- `AUDIT-WP-0003` provides authenticated durable event ingestion.
- `EMAIL-WP-0004` provides transactional invitation-mail delivery.
This workplan remains the consumer-side coordination and deployed integration
gate; provider implementation status stays authoritative in the owning repos.
## T01 - Establish flex-auth production authorization
```task
id: NK-WP-0024-T01
status: progress
priority: high
state_hub_task_id: "7dff0ac6-c5eb-486c-83db-a1400f30f77d"
```
Define self, tenant-admin, and platform-admin resource/action vocabulary,
deploy the policy package, replace user-engine's local runtime adapter with a
fail-closed flex-auth HTTP adapter, and correlate decision IDs with audit.
2026-08-08 implementation: added the fail-closed flex-auth HTTP adapter in
user-engine, including request mapping, decision-ID propagation, timeout and
malformed-response denial tests. The role/resource contract and safe rollout
gate are recorded in `docs/user-engine-platform-expansion-contract.md`.
Deployment remains pending because no cluster-local flex-auth Service or
validated user-engine policy package currently exists on railiance01.
2026-08-09 deployment: the validated user-engine policy is live at
`flex-auth-user-engine.flex-auth.svc.cluster.local:8080`; an in-namespace live
probe produced self-service allow and cross-tenant deny decisions. The portal
runtime switch remains coupled to the event/mail activation gate below.
## T02 - Add invitation and verification mail delivery
```task
id: NK-WP-0024-T02
status: progress
priority: medium
state_hub_task_id: "9d5f272b-115c-404d-8387-7f987cee65ea"
```
Deliver invitation and verification messages through approved custody and
mail lanes. Mailbox ownership remains evidence, never authorization.
2026-08-08 implementation: added authenticated, idempotent invitation-mail
delivery from durable outbox events. The delivery token is a required runtime
secret and the NetKingdom contract pins it to the existing OpenBao runtime
lane. Live completion waits for an approved mail receiver and its custody
entry; production is deliberately not pointed at a fabricated endpoint.
## T03 - Operate durable event delivery
```task
id: NK-WP-0024-T03
status: progress
priority: high
state_hub_task_id: "17d6390b-05a8-436c-879b-4e0331d85be5"
```
Connect the user-engine transactional outbox to the platform event lane with
bounded retries, replay, dead-letter visibility, redaction, and correlation.
2026-08-08 implementation: added an authenticated HTTP event adapter carrying
event ID, tenant, correlation, occurrence time, and redacted domain payload.
It uses `Idempotency-Key`; the existing durable store supplies bounded retry,
dead-letter, diagnostics, and replay. Live completion waits for a selected
cluster event receiver and scoped delivery credential.
## T04 - Run expanded integration failure matrix
```task
id: NK-WP-0024-T04
status: wait
priority: high
state_hub_task_id: "4c54e8e4-19d9-4470-bb43-3d43cf27af71"
```
Prove flex-auth denial/unavailability, mail failure, identity-provider outage,
partial provisioning recovery, invitation replay/expiry, and cross-tenant
negative behavior through the deployed path.
2026-08-08 source matrix: user-engine's full suite passes 119 tests with three
external-provider tests skipped. New coverage proves flex-auth allow mapping,
decision correlation, fail-closed unavailability, invitation mail routing,
event routing, and idempotency. Existing USER-WP-0021 coverage proves provider
outage, recovery, invitation expiry/replay, dead-letter/replay, and
cross-tenant denial. The deployed-path matrix remains pending on the three
production endpoints above.
2026-08-12 EMAIL-WP-0004-T04 hand-back: transactional invitation mail receiver
is live on railiance01 at
`http://email-connect.email-connect.svc.cluster.local:8080`. Failure contract
and non-secret evidence (retryable vs permanent codes, duplicate/resend,
suppression, evidence ceilings, redaction) are in
`email-connect/docs/EMAIL-WP-0004-T04-failure-evidence.md`. user-engine must
mount only `EMAIL_CONNECT_INGEST_TOKEN` (not SMTP). Provider acceptance and
mailbox challenges are not authorization.
2026-08-13 review: reopening gates are (1) split user-engine's event and mail
bearer configuration, (2) finish and deploy AUDIT-WP-0005 with its OpenBao
dynamic database and sender lanes, (3) mount both independently scoped sender
credentials, roll out the current user-engine image, and (4) run the combined
deployed failure matrix. Until then, marking any of T01-T04 done would claim a
runtime cutover that has not occurred.
2026-08-13 resumed: user-engine now has distinct `USER_ENGINE_EVENT_TOKEN`
and `USER_ENGINE_MAIL_TOKEN` inputs; adapter tests assert that audit-core and
email-connect receive different Authorization headers and that mail delivery
fails closed without its token. The full source suite passes 132 tests with 3
external-provider skips. NetKingdom's runtime manifest now declares both
cluster-local endpoints, separate Secret keys, and audit-core egress. The
remaining gate is custody delivery of those two scoped values, image publish,
rollout, and the combined live matrix.