net-kingdom/sso-mfa/k8s/user-engine/README.md
tegwick 49f727c54c
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Deploy internal user-engine portal foundation
2026-07-27 23:24:36 +02:00

26 lines
1.2 KiB
Markdown

# user-engine portal on reef-railiance
This is a stateful `rail-kubernetes` platform workload. It intentionally has
no public Ingress until the KeyCape authorization-code/PKCE edge and
`user-engine-portal` client are configured. Direct access to protected routes
must remain impossible because the application accepts identity only from a
trusted edge marker plus verified claims.
For the current pre-production bootstrap the image is imported directly into
k3s and uses `imagePullPolicy: Never`. Replace it with the immutable Forgejo
OCI digest after the OpenBao package-publisher lane is available.
The CloudNativePG operator creates `user-engine-pg-app`, including its `uri`
field. `user-engine-runtime` contains only the generated edge marker and must
be replaced by an ExternalSecret before public exposure.
```bash
kubectl apply -f runtime.yaml
kubectl -n user-engine rollout status deployment/user-engine
kubectl -n user-engine get cluster,pod,service,networkpolicy
```
Rollback sets the Deployment image to the preceding immutable digest.
Database migrations are additive and run before serving; restore uses the
standard CNPG recovery contract once the offsite object-store reference is
attached.