docs: record native user setup and product handoff requirements
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
effd0a3170
commit
02c29eec53
3 changed files with 45 additions and 8 deletions
|
|
@ -1,13 +1,13 @@
|
||||||
# Vergabe demo-company deployment binding
|
# Vergabe demo-company deployment binding
|
||||||
|
|
||||||
Prepared 2026-09-11 under RAPPS-WP-0014-T02 and VERGABE-WP-0019-T03/T04.
|
Prepared 2026-09-11 under RAPPS-WP-0014-T02 and VERGABE-WP-0019-T03/T04.
|
||||||
Native tenant creation is verified; application placement and onboarding remain pending.
|
Native tenant, user and password setup are verified; application placement and product onboarding remain pending.
|
||||||
|
|
||||||
| Item | Binding / execution status |
|
| Item | Binding / execution status |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Tenant | `tenant:trial:demo-company`; display `demo-company`; active, version 1; native operator create/readback verified |
|
| Tenant | `tenant:trial:demo-company`; display `demo-company`; active, version 1; native operator create/readback verified |
|
||||||
| Purpose / data | New demo workspace; synthetic data only; no existing data import |
|
| Purpose / data | New demo workspace; synthetic data only; no existing data import |
|
||||||
| Initial accounts | `demo-user1`, `demo-user2`, ordinary members; creation and private credential setup pending |
|
| Initial accounts | Three native memberships; one linked identity with operator-confirmed password setup. Remaining identities, actual login-name mapping and product accounts still require verification |
|
||||||
| Operator / acceptance | Bernd Worsch via authenticated existing operator path |
|
| Operator / acceptance | Bernd Worsch via authenticated existing operator path |
|
||||||
| Cluster | Railiance01, kube-system UID `a553c742-0115-43d4-99a4-a5ca56fe0786` |
|
| Cluster | Railiance01, kube-system UID `a553c742-0115-43d4-99a4-a5ca56fe0786` |
|
||||||
| Proposed namespace | `vergabe-demo-company`; create separately from historical installations |
|
| Proposed namespace | `vergabe-demo-company`; create separately from historical installations |
|
||||||
|
|
@ -40,8 +40,10 @@ administrator with invited status. A subsequent Create login failed with an
|
||||||
LLDAP service-login 401. The operator completed NK-WP-0036-T04's attended
|
LLDAP service-login 401. The operator completed NK-WP-0036-T04's attended
|
||||||
credential-reference repair: provider and consumer login now pass, independently
|
credential-reference repair: provider and consumer login now pass, independently
|
||||||
verified with a directory read; the provider password and image are unchanged.
|
verified with a directory read; the provider password and image are unchanged.
|
||||||
Retry native Create login for the existing intended user and verify password
|
The operator confirms successful user password setup on 2026-09-12. Independent
|
||||||
setup. No directory identity is inferred from the user-domain record.
|
read-only User Engine evidence shows three memberships and one linked identity.
|
||||||
|
USER-WP-0025 also delivered operator navigation, logout and tenant-name selection.
|
||||||
|
Remaining identity and product access are verified separately.
|
||||||
|
|
||||||
Create two ordinary memberships through User Engine. Confirm how the identity
|
Create two ordinary memberships through User Engine. Confirm how the identity
|
||||||
provisioner assigns login names before provisioning the requested demo names;
|
provisioner assigns login names before provisioning the requested demo names;
|
||||||
|
|
@ -75,3 +77,19 @@ Validation on 2026-09-11: Helm lint passed. Rendering the proposed values
|
||||||
produced the pinned digest, one Recreate replica, 60m CPU request, matching
|
produced the pinned digest, one Recreate replica, 60m CPU request, matching
|
||||||
Django/probe hosts, and two distinct retained PVCs. This is local manifest
|
Django/probe hosts, and two distinct retained PVCs. This is local manifest
|
||||||
verification; it is not native deployment or tenant-creation evidence.
|
verification; it is not native deployment or tenant-creation evidence.
|
||||||
|
|
||||||
|
|
||||||
|
The next product handoff is VERGABE-WP-0019-T06: preserve the invited tenant and
|
||||||
|
recipient through an allow-listed password-setup return and land on the admitted
|
||||||
|
demo-company welcome/sign-in path. Product authentication must validate its own
|
||||||
|
NetKingdom identity and tenant; it must not reuse the operator's portal session
|
||||||
|
or silently grant staff privileges. No application SSO is implemented yet.
|
||||||
|
|
||||||
|
|
||||||
|
Latest DNS evidence, 2026-09-12: both the recursive resolver and authoritative
|
||||||
|
ns1047.ui-dns.biz return NXDOMAIN for the product hostname (A and AAAA queried
|
||||||
|
recursively). This supersedes the earlier 80.158.43.29 observation for current
|
||||||
|
execution. The zone is served by IONOS ui-dns nameservers. The operator was asked
|
||||||
|
to add only A vergabe-teilnahme.coulomb.social → 92.205.62.239, TTL 300 or default.
|
||||||
|
No DNS credentials were requested or retrieved; native record readback and TLS
|
||||||
|
remain pending. Tenant paths continue sharing this one product hostname.
|
||||||
|
|
|
||||||
|
|
@ -9,8 +9,8 @@ the historical deployment is still live.
|
||||||
|
|
||||||
Before native admission, record the following non-secret values in the company
|
Before native admission, record the following non-secret values in the company
|
||||||
binding. The user selects a fresh `demo-company` workspace; see
|
binding. The user selects a fresh `demo-company` workspace; see
|
||||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant creation
|
[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup is verified; application hostname admission
|
||||||
and hostname admission are pending; example values do not create a tenant.
|
and product placement remain pending.
|
||||||
|
|
||||||
| Binding | Required evidence |
|
| Binding | Required evidence |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
|
|
@ -150,3 +150,13 @@ NK-WP-0036-T04. Tenant-path application source 9345a1b passes 98 tests and seven
|
||||||
local browser checks; image publication 44 passed with digest
|
local browser checks; image publication 44 passed with digest
|
||||||
sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
|
sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
|
||||||
Live edge/data admission remains open. See the updated demo-company binding for execution status.
|
Live edge/data admission remains open. See the updated demo-company binding for execution status.
|
||||||
|
|
||||||
|
|
||||||
|
2026-09-12 update: directory credential reconciliation succeeded, the operator
|
||||||
|
confirmed portal login/logout and user password setup, and live records show
|
||||||
|
three demo-company memberships with one linked identity. Native provisioning
|
||||||
|
is no longer the current blocker. The product still needs DNS/TLS, fresh data
|
||||||
|
custody, placement and recovery. VERGABE-WP-0019-T06 now explicitly tracks the
|
||||||
|
requested tenant welcome and connection to the new NetKingdom identity. The
|
||||||
|
earlier manually provisioned Django account path remains an interim capability;
|
||||||
|
it does not make the directory password a product credential or implement SSO.
|
||||||
|
|
|
||||||
|
|
@ -8,7 +8,7 @@ status: active
|
||||||
owner: the-custodian
|
owner: the-custodian
|
||||||
topic_slug: railiance
|
topic_slug: railiance
|
||||||
created: "2026-09-11"
|
created: "2026-09-11"
|
||||||
updated: "2026-09-11"
|
updated: "2026-09-12"
|
||||||
related: [VERGABE-WP-0019, VERGABE-WP-0018, HFACT-WP-0001, CUST-WP-0071]
|
related: [VERGABE-WP-0019, VERGABE-WP-0018, HFACT-WP-0001, CUST-WP-0071]
|
||||||
state_hub_workstream_id: "c7fdaa7e-cab8-5d1d-86c2-f1aad7927c57"
|
state_hub_workstream_id: "c7fdaa7e-cab8-5d1d-86c2-f1aad7927c57"
|
||||||
---
|
---
|
||||||
|
|
@ -39,7 +39,7 @@ values template prepare the deployment; no live resources were changed.
|
||||||
id: RAPPS-WP-0014-T02
|
id: RAPPS-WP-0014-T02
|
||||||
status: progress
|
status: progress
|
||||||
needs_human: true
|
needs_human: true
|
||||||
intervention_note: "Native demo-company exists; product host/path is selected. NK-WP-0036-T04 credential reconciliation is complete and independently verified. Native Create login/password setup must now be retried for the existing user. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed."
|
intervention_note: "Native tenant/user/password setup succeeds; three memberships and one linked identity are verified. Product DNS/TLS, fresh database/Secret, application deployment and tenant welcome/sign-in remain. VERGABE-WP-0019-T06 retains the product handoff. No new approval for the 60m prototype is needed."
|
||||||
priority: high
|
priority: high
|
||||||
assignee: the-custodian
|
assignee: the-custodian
|
||||||
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
|
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
|
||||||
|
|
@ -109,6 +109,15 @@ and APP_BASE_PATH=/demo-company. The previous root-path image is superseded. Ord
|
||||||
Django accounts remain separate from platform tenant existence. No product SSO
|
Django accounts remain separate from platform tenant existence. No product SSO
|
||||||
is claimed. The selected URL and successful tenant creation are resolved inputs.
|
is claimed. The selected URL and successful tenant creation are resolved inputs.
|
||||||
|
|
||||||
|
2026-09-12 native milestone:the operator confirms portal login/logout and user
|
||||||
|
password setup (Password set). Read-only User Engine evidence shows three
|
||||||
|
demo-company memberships and one linked directory identity; private names,
|
||||||
|
addresses, passwords and setup links are excluded. USER-WP-0025 deployed visible
|
||||||
|
operator navigation, protected portal logout and tenant-name selection. Product
|
||||||
|
identity linkage and a tenant welcome handoff are explicitly VERGABE-WP-0019-T06.
|
||||||
|
This supersedes the preceding pending-Create-login state; the app itself is not
|
||||||
|
yet deployed and native identity success does not establish a Django session.
|
||||||
|
|
||||||
## Demonstrate restart, isolated restore, rollback and operating ownership
|
## Demonstrate restart, isolated restore, rollback and operating ownership
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue