diff --git a/docs/vergabe-demo-company-binding.md b/docs/vergabe-demo-company-binding.md index 0555f1e..0349a42 100644 --- a/docs/vergabe-demo-company-binding.md +++ b/docs/vergabe-demo-company-binding.md @@ -1,13 +1,13 @@ # Vergabe demo-company deployment binding Prepared 2026-09-11 under RAPPS-WP-0014-T02 and VERGABE-WP-0019-T03/T04. -Native tenant creation is verified; application placement and onboarding remain pending. +Native tenant, user and password setup are verified; application placement and product onboarding remain pending. | Item | Binding / execution status | | --- | --- | | Tenant | `tenant:trial:demo-company`; display `demo-company`; active, version 1; native operator create/readback verified | | Purpose / data | New demo workspace; synthetic data only; no existing data import | -| Initial accounts | `demo-user1`, `demo-user2`, ordinary members; creation and private credential setup pending | +| Initial accounts | Three native memberships; one linked identity with operator-confirmed password setup. Remaining identities, actual login-name mapping and product accounts still require verification | | Operator / acceptance | Bernd Worsch via authenticated existing operator path | | Cluster | Railiance01, kube-system UID `a553c742-0115-43d4-99a4-a5ca56fe0786` | | Proposed namespace | `vergabe-demo-company`; create separately from historical installations | @@ -40,8 +40,10 @@ administrator with invited status. A subsequent Create login failed with an LLDAP service-login 401. The operator completed NK-WP-0036-T04's attended credential-reference repair: provider and consumer login now pass, independently verified with a directory read; the provider password and image are unchanged. -Retry native Create login for the existing intended user and verify password -setup. No directory identity is inferred from the user-domain record. +The operator confirms successful user password setup on 2026-09-12. Independent +read-only User Engine evidence shows three memberships and one linked identity. +USER-WP-0025 also delivered operator navigation, logout and tenant-name selection. +Remaining identity and product access are verified separately. Create two ordinary memberships through User Engine. Confirm how the identity provisioner assigns login names before provisioning the requested demo names; @@ -75,3 +77,19 @@ Validation on 2026-09-11: Helm lint passed. Rendering the proposed values produced the pinned digest, one Recreate replica, 60m CPU request, matching Django/probe hosts, and two distinct retained PVCs. This is local manifest verification; it is not native deployment or tenant-creation evidence. + + +The next product handoff is VERGABE-WP-0019-T06: preserve the invited tenant and +recipient through an allow-listed password-setup return and land on the admitted +demo-company welcome/sign-in path. Product authentication must validate its own +NetKingdom identity and tenant; it must not reuse the operator's portal session +or silently grant staff privileges. No application SSO is implemented yet. + + +Latest DNS evidence, 2026-09-12: both the recursive resolver and authoritative +ns1047.ui-dns.biz return NXDOMAIN for the product hostname (A and AAAA queried +recursively). This supersedes the earlier 80.158.43.29 observation for current +execution. The zone is served by IONOS ui-dns nameservers. The operator was asked +to add only A vergabe-teilnahme.coulomb.social → 92.205.62.239, TTL 300 or default. +No DNS credentials were requested or retrieved; native record readback and TLS +remain pending. Tenant paths continue sharing this one product hostname. diff --git a/docs/vergabe-teilnahme-pilot.md b/docs/vergabe-teilnahme-pilot.md index 0b6e381..b9df12b 100644 --- a/docs/vergabe-teilnahme-pilot.md +++ b/docs/vergabe-teilnahme-pilot.md @@ -9,8 +9,8 @@ the historical deployment is still live. Before native admission, record the following non-secret values in the company binding. The user selects a fresh `demo-company` workspace; see -[its prepared binding](vergabe-demo-company-binding.md). Native tenant creation -and hostname admission are pending; example values do not create a tenant. +[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup is verified; application hostname admission +and product placement remain pending. | Binding | Required evidence | | --- | --- | @@ -150,3 +150,13 @@ NK-WP-0036-T04. Tenant-path application source 9345a1b passes 98 tests and seven local browser checks; image publication 44 passed with digest sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68. Live edge/data admission remains open. See the updated demo-company binding for execution status. + + +2026-09-12 update: directory credential reconciliation succeeded, the operator +confirmed portal login/logout and user password setup, and live records show +three demo-company memberships with one linked identity. Native provisioning +is no longer the current blocker. The product still needs DNS/TLS, fresh data +custody, placement and recovery. VERGABE-WP-0019-T06 now explicitly tracks the +requested tenant welcome and connection to the new NetKingdom identity. The +earlier manually provisioned Django account path remains an interim capability; +it does not make the directory password a product credential or implement SSO. diff --git a/workplans/RAPPS-WP-0014-vergabe-invited-pilot.md b/workplans/RAPPS-WP-0014-vergabe-invited-pilot.md index 1239b77..f7e69db 100644 --- a/workplans/RAPPS-WP-0014-vergabe-invited-pilot.md +++ b/workplans/RAPPS-WP-0014-vergabe-invited-pilot.md @@ -8,7 +8,7 @@ status: active owner: the-custodian topic_slug: railiance created: "2026-09-11" -updated: "2026-09-11" +updated: "2026-09-12" related: [VERGABE-WP-0019, VERGABE-WP-0018, HFACT-WP-0001, CUST-WP-0071] state_hub_workstream_id: "c7fdaa7e-cab8-5d1d-86c2-f1aad7927c57" --- @@ -39,7 +39,7 @@ values template prepare the deployment; no live resources were changed. id: RAPPS-WP-0014-T02 status: progress needs_human: true -intervention_note: "Native demo-company exists; product host/path is selected. NK-WP-0036-T04 credential reconciliation is complete and independently verified. Native Create login/password setup must now be retried for the existing user. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed." +intervention_note: "Native tenant/user/password setup succeeds; three memberships and one linked identity are verified. Product DNS/TLS, fresh database/Secret, application deployment and tenant welcome/sign-in remain. VERGABE-WP-0019-T06 retains the product handoff. No new approval for the 60m prototype is needed." priority: high assignee: the-custodian state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897" @@ -109,6 +109,15 @@ and APP_BASE_PATH=/demo-company. The previous root-path image is superseded. Ord Django accounts remain separate from platform tenant existence. No product SSO is claimed. The selected URL and successful tenant creation are resolved inputs. +2026-09-12 native milestone:the operator confirms portal login/logout and user +password setup (Password set). Read-only User Engine evidence shows three +demo-company memberships and one linked directory identity; private names, +addresses, passwords and setup links are excluded. USER-WP-0025 deployed visible +operator navigation, protected portal logout and tenant-name selection. Product +identity linkage and a tenant welcome handoff are explicitly VERGABE-WP-0019-T06. +This supersedes the preceding pending-Create-login state; the app itself is not +yet deployed and native identity success does not establish a Django session. + ## Demonstrate restart, isolated restore, rollback and operating ownership ```task