Close Vergabe binding and record remaining recovery blockers
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e3b3-11fe-7ba0-a4a3-92331aab0ba1
This commit is contained in:
tegwick 2026-09-27 18:34:05 +02:00
parent 1839c0ba42
commit cfbc95e11d
6 changed files with 136 additions and 36 deletions

View file

@ -1,7 +1,7 @@
# Vergabe demo-company deployment binding
Updated 2026-09-12 under RAPPS-WP-0014 and VERGABE-WP-0019.
Application placement is live; native product sign-in and recovery acceptance remain open.
Updated 2026-09-27 under RAPPS-WP-0014 and VERGABE-WP-0019.
Release binding is complete (RAPPS-WP-0014-T02). Recovery and invited-recipient acceptance remain open.
| Item | Current binding |
| --- | --- |
@ -18,7 +18,7 @@ Application placement is live; native product sign-in and recovery acceptance re
| Database / role | Fresh vergabe_demo_company / vergabe_demo_company, databases/apps-pg |
| Runtime custody | vergabe-demo-company/vergabe-demo-env; platform helper receipt in RPF-WP-0039 |
| Media / issue state | Separate Bound local-path PVCs, 5Gi / 1Gi; UID/GID/fsGroup 999 |
| Authentication | NetKingdom company welcome and OIDC deployed; initial readback zero accounts. Actual recipient login/MFA pending |
| Authentication | NetKingdom company welcome and OIDC deployed; founder sign-in recorded September 24. Fresh recipient journey and two-user acceptance remain open |
| Remaining handoffs | VERGABE-WP-0019-T06 welcome/SSO; RAPPS-WP-0014-T03 recovery; VERGABE-WP-0019-T04 pilot acceptance |
## Current SSO rollout
@ -89,10 +89,22 @@ on stdin; the durable credential copies are the two exact Kubernetes Secrets.
OpenBao automation remains a later owner improvement. Never rerun historical
bootstrap helpers or substitute apps_admin credentials.
This is the first release in the fresh namespace; there is no previously
accepted application image to roll back to. On a failed next upgrade, stop public
traffic and reconcile schema/image compatibility before reverting. Retain the
Revision 3 is the current binding; revisions 1 and 2 are historical deployment
receipts, not demonstrated safe rollback targets. On a failed next upgrade,
stop public traffic and reconcile schema/image compatibility before reverting. Retain the
claims and database; namespace deletion is not rollback. Pod replacement and
isolated restore must still be proven with matched PostgreSQL/media/SQLite data.
Current recovery rollout: docs/evidence/2026-09-12-account-recovery-live.md.
## Binding review — 2026-09-27
Read-only deployment, Helm, claim, certificate and HTTPS checks match this
binding; see [the verification receipt](evidence/2026-09-27-vergabe-binding-review.md).
The September 25 database restore and pod restart passed, but populated media
and issue-state recovery, an off-host copy, restored two-user workflow and
rollback/support acceptance remain RAPPS-WP-0014-T03. That task is waiting and
the workplan is blocked. Earlier dated sections describe their original
snapshots; the current binding table and this review supersede their pending
DNS, deployment and first-login statements.