docs: record native user setup and product handoff requirements
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
effd0a3170
commit
02c29eec53
3 changed files with 45 additions and 8 deletions
|
|
@ -1,13 +1,13 @@
|
|||
# Vergabe demo-company deployment binding
|
||||
|
||||
Prepared 2026-09-11 under RAPPS-WP-0014-T02 and VERGABE-WP-0019-T03/T04.
|
||||
Native tenant creation is verified; application placement and onboarding remain pending.
|
||||
Native tenant, user and password setup are verified; application placement and product onboarding remain pending.
|
||||
|
||||
| Item | Binding / execution status |
|
||||
| --- | --- |
|
||||
| Tenant | `tenant:trial:demo-company`; display `demo-company`; active, version 1; native operator create/readback verified |
|
||||
| Purpose / data | New demo workspace; synthetic data only; no existing data import |
|
||||
| Initial accounts | `demo-user1`, `demo-user2`, ordinary members; creation and private credential setup pending |
|
||||
| Initial accounts | Three native memberships; one linked identity with operator-confirmed password setup. Remaining identities, actual login-name mapping and product accounts still require verification |
|
||||
| Operator / acceptance | Bernd Worsch via authenticated existing operator path |
|
||||
| Cluster | Railiance01, kube-system UID `a553c742-0115-43d4-99a4-a5ca56fe0786` |
|
||||
| Proposed namespace | `vergabe-demo-company`; create separately from historical installations |
|
||||
|
|
@ -40,8 +40,10 @@ administrator with invited status. A subsequent Create login failed with an
|
|||
LLDAP service-login 401. The operator completed NK-WP-0036-T04's attended
|
||||
credential-reference repair: provider and consumer login now pass, independently
|
||||
verified with a directory read; the provider password and image are unchanged.
|
||||
Retry native Create login for the existing intended user and verify password
|
||||
setup. No directory identity is inferred from the user-domain record.
|
||||
The operator confirms successful user password setup on 2026-09-12. Independent
|
||||
read-only User Engine evidence shows three memberships and one linked identity.
|
||||
USER-WP-0025 also delivered operator navigation, logout and tenant-name selection.
|
||||
Remaining identity and product access are verified separately.
|
||||
|
||||
Create two ordinary memberships through User Engine. Confirm how the identity
|
||||
provisioner assigns login names before provisioning the requested demo names;
|
||||
|
|
@ -75,3 +77,19 @@ Validation on 2026-09-11: Helm lint passed. Rendering the proposed values
|
|||
produced the pinned digest, one Recreate replica, 60m CPU request, matching
|
||||
Django/probe hosts, and two distinct retained PVCs. This is local manifest
|
||||
verification; it is not native deployment or tenant-creation evidence.
|
||||
|
||||
|
||||
The next product handoff is VERGABE-WP-0019-T06: preserve the invited tenant and
|
||||
recipient through an allow-listed password-setup return and land on the admitted
|
||||
demo-company welcome/sign-in path. Product authentication must validate its own
|
||||
NetKingdom identity and tenant; it must not reuse the operator's portal session
|
||||
or silently grant staff privileges. No application SSO is implemented yet.
|
||||
|
||||
|
||||
Latest DNS evidence, 2026-09-12: both the recursive resolver and authoritative
|
||||
ns1047.ui-dns.biz return NXDOMAIN for the product hostname (A and AAAA queried
|
||||
recursively). This supersedes the earlier 80.158.43.29 observation for current
|
||||
execution. The zone is served by IONOS ui-dns nameservers. The operator was asked
|
||||
to add only A vergabe-teilnahme.coulomb.social → 92.205.62.239, TTL 300 or default.
|
||||
No DNS credentials were requested or retrieved; native record readback and TLS
|
||||
remain pending. Tenant paths continue sharing this one product hostname.
|
||||
|
|
|
|||
|
|
@ -9,8 +9,8 @@ the historical deployment is still live.
|
|||
|
||||
Before native admission, record the following non-secret values in the company
|
||||
binding. The user selects a fresh `demo-company` workspace; see
|
||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant creation
|
||||
and hostname admission are pending; example values do not create a tenant.
|
||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup is verified; application hostname admission
|
||||
and product placement remain pending.
|
||||
|
||||
| Binding | Required evidence |
|
||||
| --- | --- |
|
||||
|
|
@ -150,3 +150,13 @@ NK-WP-0036-T04. Tenant-path application source 9345a1b passes 98 tests and seven
|
|||
local browser checks; image publication 44 passed with digest
|
||||
sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
|
||||
Live edge/data admission remains open. See the updated demo-company binding for execution status.
|
||||
|
||||
|
||||
2026-09-12 update: directory credential reconciliation succeeded, the operator
|
||||
confirmed portal login/logout and user password setup, and live records show
|
||||
three demo-company memberships with one linked identity. Native provisioning
|
||||
is no longer the current blocker. The product still needs DNS/TLS, fresh data
|
||||
custody, placement and recovery. VERGABE-WP-0019-T06 now explicitly tracks the
|
||||
requested tenant welcome and connection to the new NetKingdom identity. The
|
||||
earlier manually provisioned Django account path remains an interim capability;
|
||||
it does not make the directory password a product credential or implement SSO.
|
||||
|
|
|
|||
|
|
@ -8,7 +8,7 @@ status: active
|
|||
owner: the-custodian
|
||||
topic_slug: railiance
|
||||
created: "2026-09-11"
|
||||
updated: "2026-09-11"
|
||||
updated: "2026-09-12"
|
||||
related: [VERGABE-WP-0019, VERGABE-WP-0018, HFACT-WP-0001, CUST-WP-0071]
|
||||
state_hub_workstream_id: "c7fdaa7e-cab8-5d1d-86c2-f1aad7927c57"
|
||||
---
|
||||
|
|
@ -39,7 +39,7 @@ values template prepare the deployment; no live resources were changed.
|
|||
id: RAPPS-WP-0014-T02
|
||||
status: progress
|
||||
needs_human: true
|
||||
intervention_note: "Native demo-company exists; product host/path is selected. NK-WP-0036-T04 credential reconciliation is complete and independently verified. Native Create login/password setup must now be retried for the existing user. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed."
|
||||
intervention_note: "Native tenant/user/password setup succeeds; three memberships and one linked identity are verified. Product DNS/TLS, fresh database/Secret, application deployment and tenant welcome/sign-in remain. VERGABE-WP-0019-T06 retains the product handoff. No new approval for the 60m prototype is needed."
|
||||
priority: high
|
||||
assignee: the-custodian
|
||||
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
|
||||
|
|
@ -109,6 +109,15 @@ and APP_BASE_PATH=/demo-company. The previous root-path image is superseded. Ord
|
|||
Django accounts remain separate from platform tenant existence. No product SSO
|
||||
is claimed. The selected URL and successful tenant creation are resolved inputs.
|
||||
|
||||
2026-09-12 native milestone:the operator confirms portal login/logout and user
|
||||
password setup (Password set). Read-only User Engine evidence shows three
|
||||
demo-company memberships and one linked directory identity; private names,
|
||||
addresses, passwords and setup links are excluded. USER-WP-0025 deployed visible
|
||||
operator navigation, protected portal logout and tenant-name selection. Product
|
||||
identity linkage and a tenant welcome handoff are explicitly VERGABE-WP-0019-T06.
|
||||
This supersedes the preceding pending-Create-login state; the app itself is not
|
||||
yet deployed and native identity success does not establish a Django session.
|
||||
|
||||
## Demonstrate restart, isolated restore, rollback and operating ownership
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue