deploy: bind demo company to published tenant-path release
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 21:43:41 +02:00
parent 8f29af4b63
commit 428d0707e0
4 changed files with 62 additions and 30 deletions

View file

@ -39,7 +39,7 @@ values template prepare the deployment; no live resources were changed.
id: RAPPS-WP-0014-T02
status: progress
needs_human: true
intervention_note: "Company and fresh data are selected. Await native User Engine operator login for demo-company creation; proposed hostname preference and DNS/TLS setup remain open. No new approval for the accepted 60m prototype is needed."
intervention_note: "Native demo-company exists; product host/path is selected. Identity-provisioner LLDAP login returns 401 after credential reload; NK-WP-0036-T04 holds attended consumer credential reconciliation. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed."
priority: high
assignee: the-custodian
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
@ -80,18 +80,31 @@ limiter. Keep `/media/` behind the app gate.
The user requests a new `demo-company` tenant with `demo-user1`, etc. Apply
NetKingdom ADR-0013 as `tenant:trial:demo-company` and start with two ordinary
demo users. Fresh data is selected; no historical customer import is authorized.
The exact prepared namespace/database/release and proposed hostname are in
The prepared namespace/database/release and current execution status are in
`docs/vergabe-demo-company-binding.md` and
`helm/vergabe-demo-company-values.proposed.yaml`. The suggested hostname is
`demo-vergabe.coulomb.social`; user preference is pending. Its observed DNS
target is not Railiance01 and must be corrected through the edge owner.
`helm/vergabe-demo-company-values.proposed.yaml`. The user chose
`https://vergabe-teilnahme.coulomb.social/demo-company`. DNS/TLS is per product
host; the exact company prefix selects its isolated application instance.
The chosen hostname currently resolves to 80.158.43.29 and needs the admitted
Railiance01 route (92.205.62.239) through the edge owner.
Tenant Engine creation must use the authenticated User Engine operator portal.
An isolated native KeyCape login window has been opened; operator login,
tenant creation/readback, memberships and app account provisioning are not yet
confirmed. Do not substitute a trusted service actor to bypass a denial.
Platform registration does not add SSO to the Django pilot. Continue execution
on T02; company/data choice is no longer missing input.
Native operator authentication as platform-root succeeded. At 19:03:18 UTC the
operator created demo-company through the native User Engine form; Tenant
Engine readback confirms active, version 1. The chosen first administrator is
present with invited status. A subsequent user was created, but Create login
fails in identity-provisioner at the LLDAP admin authentication step, before
directory mutation. Reloading the existing credential reference preserves this
401. NK-WP-0036-T04 owns the prepared attended consumer-only reconciliation;
T05 retains the functional dependency preflight/error-reporting improvement.
No provider password has been changed, and no failed login create was replayed.
Vergabe source 9345a1b supports APP_BASE_PATH=/demo-company, prefix-aware URL
reversing and cookie scope. All 98 application tests, Vite build and seven
local Chromium path/edge checks pass. CI smoke 43 and publication 44 passed; the proposed values now pin
sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68
and APP_BASE_PATH=/demo-company. The previous root-path image is superseded. Ordinary demo memberships and
Django accounts remain separate from platform tenant existence. No product SSO
is claimed. The selected URL and successful tenant creation are resolved inputs.
## Demonstrate restart, isolated restore, rollback and operating ownership