net-kingdom/workplans/NK-WP-0024-user-engine-portal-integration-expansion.md
tegwick c56465e32d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Enable public registration and prove event delivery
2026-08-14 00:42:14 +02:00

8.9 KiB

id type title domain repo status owner topic_slug created updated depends_on state_hub_workstream_id
NK-WP-0024 workplan Expand user-engine platform integrations beyond the Binky MVP infotech net-kingdom active codex netkingdom 2026-07-30 2026-08-13
NK-WP-0023
USER-WP-0021
FLEX-WP-0009
AUDIT-WP-0003
EMAIL-WP-0004
9bd05700-a839-4014-8f88-8a78f2757721

NK-WP-0024 - Portal integration expansion

2026-08-13 completion review

This workplan was blocked at review time. On 2026-08-13 AUDIT-WP-0005 finished: the PostgreSQL-backed audit-core workload is Ready with archive custody, OpenBao-backed sender/database lanes, restart/rollback evidence, and a live failure matrix (12 passed, 0 failed, 3 production-disruption skips). The workplan is active again.

The audit dependency recorded above is stale operationally: AUDIT-WP-0003 finished only after cancelling its deployment tasks. Production custody and the live matrix moved to the now-finished AUDIT-WP-0005.

A consumer-side credential-isolation defect was found and fixed before activation. The previous user-engine HTTPOutboxDeliveryAdapter accepted one USER_ENGINE_DELIVERY_TOKEN for both receivers. audit-core and email-connect are separately scoped receivers and must not share a bearer credential; the adapter now accepts distinct event and mail tokens.

Track deferred integration breadth separately from the completed live MVP. Activate with the corresponding user-engine product-expansion tasks.

Provider workplans established 2026-08-08:

  • FLEX-WP-0009 provides the user-engine policy package and cluster service.
  • AUDIT-WP-0003 provides authenticated durable event ingestion.
  • EMAIL-WP-0004 provides transactional invitation-mail delivery.

This workplan remains the consumer-side coordination and deployed integration gate; provider implementation status stays authoritative in the owning repos.

T01 - Establish flex-auth production authorization

id: NK-WP-0024-T01
status: done
priority: high
state_hub_task_id: "7dff0ac6-c5eb-486c-83db-a1400f30f77d"

Define self, tenant-admin, and platform-admin resource/action vocabulary, deploy the policy package, replace user-engine's local runtime adapter with a fail-closed flex-auth HTTP adapter, and correlate decision IDs with audit.

2026-08-08 implementation: added the fail-closed flex-auth HTTP adapter in user-engine, including request mapping, decision-ID propagation, timeout and malformed-response denial tests. The role/resource contract and safe rollout gate are recorded in docs/user-engine-platform-expansion-contract.md. Deployment remains pending because no cluster-local flex-auth Service or validated user-engine policy package currently exists on railiance01.

2026-08-09 deployment: the validated user-engine policy is live at flex-auth-user-engine.flex-auth.svc.cluster.local:8080; an in-namespace live probe produced self-service allow and cross-tenant deny decisions. The portal runtime switch remains coupled to the event/mail activation gate below.

Done 2026-08-14: the portal is live on the fail-closed HTTP adapter; its platform outbox dispatch was authorized by the deployed flex-auth policy and accepted into audit-core with correlated event IDs. Existing deployed allow, cross-tenant deny, missing-role deny, and wrong-system deny evidence remains valid.

T02 - Add invitation and verification mail delivery

id: NK-WP-0024-T02
status: progress
priority: medium
state_hub_task_id: "9d5f272b-115c-404d-8387-7f987cee65ea"

Deliver invitation and verification messages through approved custody and mail lanes. Mailbox ownership remains evidence, never authorization.

2026-08-08 implementation: added authenticated, idempotent invitation-mail delivery from durable outbox events. The delivery token is a required runtime secret and the NetKingdom contract pins it to the existing OpenBao runtime lane. Live completion waits for an approved mail receiver and its custody entry; production is deliberately not pointed at a fabricated endpoint.

T03 - Operate durable event delivery

id: NK-WP-0024-T03
status: done
priority: high
state_hub_task_id: "17d6390b-05a8-436c-879b-4e0331d85be5"

Connect the user-engine transactional outbox to the platform event lane with bounded retries, replay, dead-letter visibility, redaction, and correlation.

2026-08-08 implementation: added an authenticated HTTP event adapter carrying event ID, tenant, correlation, occurrence time, and redacted domain payload. It uses Idempotency-Key; the existing durable store supplies bounded retry, dead-letter, diagnostics, and replay. Live completion waits for a selected cluster event receiver and scoped delivery credential.

T04 - Run expanded integration failure matrix

id: NK-WP-0024-T04
status: progress
priority: high
state_hub_task_id: "4c54e8e4-19d9-4470-bb43-3d43cf27af71"

Prove flex-auth denial/unavailability, mail failure, identity-provider outage, partial provisioning recovery, invitation replay/expiry, and cross-tenant negative behavior through the deployed path.

2026-08-08 source matrix: user-engine's full suite passes 119 tests with three external-provider tests skipped. New coverage proves flex-auth allow mapping, decision correlation, fail-closed unavailability, invitation mail routing, event routing, and idempotency. Existing USER-WP-0021 coverage proves provider outage, recovery, invitation expiry/replay, dead-letter/replay, and cross-tenant denial. The deployed-path matrix remains pending on the three production endpoints above.

2026-08-12 EMAIL-WP-0004-T04 hand-back: transactional invitation mail receiver is live on railiance01 at http://email-connect.email-connect.svc.cluster.local:8080. Failure contract and non-secret evidence (retryable vs permanent codes, duplicate/resend, suppression, evidence ceilings, redaction) are in email-connect/docs/EMAIL-WP-0004-T04-failure-evidence.md. user-engine must mount only EMAIL_CONNECT_INGEST_TOKEN (not SMTP). Provider acceptance and mailbox challenges are not authorization.

2026-08-13 review: reopening gates are (1) split user-engine's event and mail bearer configuration, (2) finish and deploy AUDIT-WP-0005 with its OpenBao dynamic database and sender lanes, (3) mount both independently scoped sender credentials, roll out the current user-engine image, and (4) run the combined deployed failure matrix. Until then, marking any of T01-T04 done would claim a runtime cutover that has not occurred.

2026-08-13 resumed: user-engine now has distinct USER_ENGINE_EVENT_TOKEN and USER_ENGINE_MAIL_TOKEN inputs; adapter tests assert that audit-core and email-connect receive different Authorization headers and that mail delivery fails closed without its token. The full source suite passes 132 tests with 3 external-provider skips. NetKingdom's runtime manifest now declares both cluster-local endpoints, separate Secret keys, and audit-core egress. The remaining gate is custody delivery of those two scoped values, image publish, rollout, and the combined live matrix.

2026-08-13 rollout: the scoped provider credentials were transferred entirely through Kubernetes APIs into Secret user-engine-delivery, containing exactly event-token and mail-token; no value was printed or persisted outside the cluster. user-engine commit a0f39f5 was published and deployed at immutable digest sha256:4eac10bf157e48eeadef16a2da83a00933914c9d37338f01679692008de21565. The rollout completed, /readyz reports all checks true, and in-pod probes reach flex-auth, audit-core, and email-connect with HTTP 200 through the declared NetworkPolicies. Remaining T04 evidence is application-level outbox delivery and the negative matrix; health reachability alone is not reported as delivery acceptance.

2026-08-14 live outbox proof: nine existing durable non-mail events were dispatched through the deployed user-engine adapter. Three were accepted immediately. Six received HTTP 400 because audit-core's user-engine sender was limited to tenant:friendly:binky; the platform service legitimately emits for multiple tenants. The sender remains write-only and source-bound to user-engine, but its tenant claim scope is now *. After audit-core restart, explicit replay delivered all six with attempt count 2; user-engine reports zero pending events.

The run also exposed a PostgreSQL retry defect: pending_outbox() filtered on failed_at IS NULL, unlike the in-memory contract, so bounded retries stopped after one failure. user-engine commit 0b6a57d selects every undelivered, non-dead-letter event and adds regression coverage; the full suite passes 133 tests with 3 external skips. The corrected immutable image is sha256:1402712e8f3ddc1397e83edb9627251b0ea362f1e3308d252d0d688ac589556e.

T03 is complete: all nine durable source events are delivered, replay is idempotent at audit-core, user-engine reports zero pending events, and the corrected bounded-retry query is live and Ready. T04 remains open for the mail-producing application journey and its attended negative cases.