Record deployed Vergabe pilot chart and company sign-in evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-12 03:12:45 +02:00
parent fd5e57bc99
commit e8a7ff2547
13 changed files with 479 additions and 88 deletions

View file

@ -0,0 +1,36 @@
# Demo-company deployment receipt
2026-09-12 deployment evidence: the operator added A records for
vergabe-teilnahme.coulomb.social and users.coulomb.social. Authoritative IONOS
and recursive readback both return 92.205.62.239. Both cert-manager certificates
are Ready. The portal now uses https://users.coulomb.social/login; its legacy
nip.io address redirects to the canonical hostname. The exact new callback is
registered alongside the rollback callback; scopes, public client type and PKCE
remain unchanged. Canonical authorization succeeds; unapproved callback and
missing PKCE fail. This supersedes earlier DNS and portal-hostname blockers.
Helm release vergabe-teilnahme revision 1 is deployed in vergabe-demo-company,
chart 0.2.1, pinned product digest cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
Deployment UID 2152014d-a020-4c5e-a3b0-9575e9f21c44 is Ready 1/1. Its init
migration completed before the web process; both phases share the same 60m CPU /
256Mi memory request. Node requests now total 3965m of 4000m; the 35m remainder
matches the accepted prototype allocation. No unrelated resource requests changed.
RPF-WP-0039 delivered fresh vergabe_demo_company database/role on apps-pg and
runtime Secret vergabe-demo-company/vergabe-demo-env. The app's own connection
confirms that exact database/role. The role is non-superuser, cannot create roles
or databases, has a 20-connection ceiling and 15-second timeouts, and cannot
CONNECT to historical vergabe_db, coulomb_social_db or apps_meta. Both dedicated
PVCs are Bound: 5Gi media and 1Gi issue state. Historical data was not selected
or overwritten; no credentials are recorded here.
Thirteen live Chromium/HTTP checks pass: page and assets, secure tenant-scoped
CSRF cookie, anonymous login gate and media refusal, private operational path
refusal, neighboring/root path refusal, canonical slash, HTTPS redirect and
missing-CSRF POST denial. Migration/app initialization also proves consumer
connectivity. The empty product has zero accounts, including zero staff accounts.
The current login is still the interim Django login, not NetKingdom SSO. Native
recipient login, company welcome and account mapping remain VERGABE-WP-0019-T06.
RAPPS-WP-0014-T03 retains restart and coherent off-host backup/isolated restore;
the latest existing apps-pg base backup predates this new database. No pilot-user
acceptance, shared tenancy, MFA completion or natural factory-worker trace is claimed.

View file

@ -0,0 +1,27 @@
# Demo-company sign-in live rollout
Recorded 2026-09-12T01:09:00.835106+00:00
2026-09-12 attended rollout executed after explicit operator approval. KeyCape
and password setup are Ready on the prepared digests; exact public client
registration was CAS-applied (config resourceVersion 60123977) with unrelated
config bytes/Secret data preserved. Existing portal and product client both
pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks).
Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain,
and requests remain 60m CPU/256Mi memory. Eleven live product checks pass:
company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only
login start, native issuer redirect, private company/media protection and
invalid callback/confirmation rejection. Initial readback showed zero accounts,
identity mappings and staff accounts. Native invited-user sign-in/MFA and
confirmation are now requested from the operator; no user credential was used
by the agent. Recovery and two-user acceptance remain their existing tasks.
Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.
| Component | Deployed digest |
| --- | --- |
| Vergabe | sha256:2cb393608a82be2851adfc27f2bf4d8ef5d709f1b0038be5d0999e38c68b039e |
| KeyCape | sha256:5f10f36a5da23ce1aaf3df9b84a8ff98d7926f34ceaa19e63bd3356adb68e01a |
| Password setup | sha256:55f744cc9bc2ec3fe23eb7175fa4b7bfcc7a29469d9b9a1a8eaefc75d790dfc6 |
Cluster UID: a553c742-0115-43d4-99a4-a5ca56fe0786. The operator explicitly approved the prepared attended rollout. Shared issuer startup is proven; authenticated recipient token/account acceptance remains pending.

View file

@ -1,95 +1,96 @@
# Vergabe demo-company deployment binding
Prepared 2026-09-11 under RAPPS-WP-0014-T02 and VERGABE-WP-0019-T03/T04.
Native tenant, user and password setup are verified; application placement and product onboarding remain pending.
Updated 2026-09-12 under RAPPS-WP-0014 and VERGABE-WP-0019.
Application placement is live; native product sign-in and recovery acceptance remain open.
| Item | Binding / execution status |
| Item | Current binding |
| --- | --- |
| Tenant | `tenant:trial:demo-company`; display `demo-company`; active, version 1; native operator create/readback verified |
| Purpose / data | New demo workspace; synthetic data only; no existing data import |
| Initial accounts | Three native memberships; one linked identity with operator-confirmed password setup. Remaining identities, actual login-name mapping and product accounts still require verification |
| Operator / acceptance | Bernd Worsch via authenticated existing operator path |
| Cluster | Railiance01, kube-system UID `a553c742-0115-43d4-99a4-a5ca56fe0786` |
| Proposed namespace | `vergabe-demo-company`; create separately from historical installations |
| Helm release | `vergabe-teilnahme` within that namespace |
| Image source | Tenant-path source `9345a1bb1a92ac0ee3b2dc6443a3d299e6754e70`; CI smoke 43 / publication 44 passed |
| Image digest | `forgejo.coulomb.social/coulomb/vergabe-teilnahme@sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68` |
| Chart baseline | 0.2.0 at railiance-apps `9491744e5adab4464070c164d7172a7392ae1e15` |
| Resources | One Recreate replica, CPU request 60m / limit 1000m, memory request 256Mi / limit 1Gi |
| Selected URL | `https://vergabe-teilnahme.coulomb.social/demo-company/`; one product host, exact tenant path |
| Public edge | DNS, TLS and login abuse-control configuration pending; expected target 92.205.62.239 |
| Proposed database / role | Fresh `vergabe_demo_company` / `vergabe_demo_company` on `databases/apps-pg`; platform provisioning/custody pending |
| Runtime Secret | `vergabe-demo-env` in the dedicated namespace; platform delivery pending, no secret values in this packet |
| Media / app state | Separate `vergabe-teilnahme-media` 5Gi and `vergabe-teilnahme-app-state` 1Gi PVCs, local-path; native creation pending |
| Recovery / support | Existing RAPPS-WP-0014-T03 retains off-host recovery point, isolated restore, rollback and operating responsibility evidence |
| Tenant | tenant:trial:demo-company, active/version 1; three native memberships and one linked directory identity |
| Data | Fresh synthetic demo workspace; no historical import |
| Portal | https://users.coulomb.social/login |
| Product | https://vergabe-teilnahme.coulomb.social/demo-company/ |
| DNS / TLS | Both hostnames resolve to 92.205.62.239; certificates Ready |
| Cluster | Railiance01, kube-system UID a553c742-0115-43d4-99a4-a5ca56fe0786 |
| Namespace / release | vergabe-demo-company / vergabe-teilnahme, revision 2 |
| Source / image | 8be281025bf57a7aefd1fe98a7e060f2173df5ef; image 51 / acceptance 52 / smoke 53; sha256:2cb393608a82be2851adfc27f2bf4d8ef5d709f1b0038be5d0999e38c68b039e |
| Chart / rollout | 0.2.1; one Recreate replica; init migration before serving; Ready 1/1 |
| Resources | 60m CPU / 256Mi memory request; 1000m CPU / 1Gi memory limit |
| Database / role | Fresh vergabe_demo_company / vergabe_demo_company, databases/apps-pg |
| Runtime custody | vergabe-demo-company/vergabe-demo-env; platform helper receipt in RPF-WP-0039 |
| Media / issue state | Separate Bound local-path PVCs, 5Gi / 1Gi; UID/GID/fsGroup 999 |
| Authentication | NetKingdom company welcome and OIDC deployed; initial readback zero accounts. Actual recipient login/MFA pending |
| Remaining handoffs | VERGABE-WP-0019-T06 welcome/SSO; RAPPS-WP-0014-T03 recovery; VERGABE-WP-0019-T04 pilot acceptance |
The target database is a proposed new consumer, not permission to reuse or
overwrite `vergabe_db`. Refresh managed-consumer count, placement and migration
demand before applying. Tenant creation itself does not depend on this hostname.
## Current SSO rollout
## Native tenant and identity execution
2026-09-12 attended rollout executed after explicit operator approval. KeyCape
and password setup are Ready on the prepared digests; exact public client
registration was CAS-applied (config resourceVersion 60123977) with unrelated
config bytes/Secret data preserved. Existing portal and product client both
pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks).
Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain,
and requests remain 60m CPU/256Mi memory. Eleven live product checks pass:
company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only
login start, native issuer redirect, private company/media protection and
invalid callback/confirmation rejection. Initial readback showed zero accounts,
identity mappings and staff accounts. Native invited-user sign-in/MFA and
confirmation are now requested from the operator; no user credential was used
by the agent. Recovery and two-user acceptance remain their existing tasks.
Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.
Use the existing User Engine portal at `https://users.92-205-62-239.nip.io`.
Its `/login` uses KeyCape and the registered native callback. The authenticated
platform form creates `tenant:trial:demo-company` through Tenant Engine. Record
the response and read back the exact tenant before creating memberships. Do not
substitute a service actor, fabricate verified claims, or bypass policy on denial.
Native login and operator creation succeeded at 19:03:18 UTC. Tenant Engine
confirms demo-company active/version 1; User Engine contains the first
administrator with invited status. A subsequent Create login failed with an
LLDAP service-login 401. The operator completed NK-WP-0036-T04's attended
credential-reference repair: provider and consumer login now pass, independently
verified with a directory read; the provider password and image are unchanged.
The operator confirms successful user password setup on 2026-09-12. Independent
read-only User Engine evidence shows three memberships and one linked identity.
USER-WP-0025 also delivered operator navigation, logout and tenant-name selection.
Remaining identity and product access are verified separately.
## Initial deployment verification
Create two ordinary memberships through User Engine. Confirm how the identity
provisioner assigns login names before provisioning the requested demo names;
do not invent deliverable email addresses or send invitations to third parties.
The current product uses separately provisioned Django accounts, with no staff
or superuser flags. Preserve the mapping to this tenant's isolated deployment.
This establishes a platform tenant and a bounded app pilot, not completed SSO.
2026-09-12 deployment evidence: the operator added A records for
vergabe-teilnahme.coulomb.social and users.coulomb.social. Authoritative IONOS
and recursive readback both return 92.205.62.239. Both cert-manager certificates
are Ready. The portal now uses https://users.coulomb.social/login; its legacy
nip.io address redirects to the canonical hostname. The exact new callback is
registered alongside the rollback callback; scopes, public client type and PKCE
remain unchanged. Canonical authorization succeeds; unapproved callback and
missing PKCE fail. This supersedes earlier DNS and portal-hostname blockers.
## Hostname and deployment execution
Helm release vergabe-teilnahme revision 1 is deployed in vergabe-demo-company,
chart 0.2.1, pinned product digest cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
Deployment UID 2152014d-a020-4c5e-a3b0-9575e9f21c44 is Ready 1/1. Its init
migration completed before the web process; both phases share the same 60m CPU /
256Mi memory request. Node requests now total 3965m of 4000m; the 35m remainder
matches the accepted prototype allocation. No unrelated resource requests changed.
`helm/vergabe-demo-company-values.proposed.yaml` retains 60m resources and the
selected product host, APP_BASE_PATH=/demo-company and published immutable
digest. The chart does not create ingress or DNS.
The edge must match exactly /demo-company or /demo-company/, canonicalize the
bare path and strip the prefix. It must keep private media on the app route and
apply TLS and the admitted abuse-control policy. Do not route neighboring paths
to this instance. Company/data separation remains the dedicated database and
volumes, not a forwarded header or browser path.
RPF-WP-0039 delivered fresh vergabe_demo_company database/role on apps-pg and
runtime Secret vergabe-demo-company/vergabe-demo-env. The app's own connection
confirms that exact database/role. The role is non-superuser, cannot create roles
or databases, has a 20-connection ceiling and 15-second timeouts, and cannot
CONNECT to historical vergabe_db, coulomb_social_db or apps_meta. Both dedicated
PVCs are Bound: 5Gi media and 1Gi issue state. Historical data was not selected
or overwritten; no credentials are recorded here.
On 2026-09-11 the selected product hostname resolves to 80.158.43.29; Railiance01
is 92.205.62.239. No DNS changes have been made. A single product DNS/certificate
serves this arrangement; tenants do not need their own subdomains.
Thirteen live Chromium/HTTP checks pass: page and assets, secure tenant-scoped
CSRF cookie, anonymous login gate and media refusal, private operational path
refusal, neighboring/root path refusal, canonical slash, HTTPS redirect and
missing-CSRF POST denial. Migration/app initialization also proves consumer
connectivity. The empty product has zero accounts, including zero staff accounts.
The current login is still the interim Django login, not NetKingdom SSO. Native
recipient login, company welcome and account mapping remain VERGABE-WP-0019-T06.
RAPPS-WP-0014-T03 retains restart and coherent off-host backup/isolated restore;
the latest existing apps-pg base backup predates this new database. No pilot-user
acceptance, shared tenancy, MFA completion or natural factory-worker trace is claimed.
Complete platform database/Secret provisioning and the source-backed namespace,
network and public edge manifests before deployment. Then migrate the fresh
database, deploy, provision the demo app accounts, and perform the two-user
workflow plus restart/isolated-restore checks in the existing owner tasks.
Only then record the demo environment as available for use.
## Source and rollback
Validation on 2026-09-11: Helm lint passed. Rendering the proposed values
produced the pinned digest, one Recreate replica, 60m CPU request, matching
Django/probe hosts, and two distinct retained PVCs. This is local manifest
verification; it is not native deployment or tenant-creation evidence.
`helm/vergabe-demo-company-foundation.yaml` owns namespace/network policies and
certificate. `helm/vergabe-demo-company-ingress.yaml` owns the exact host and
company-prefix route, canonical slash, prefix stripping, headers and rate limit
(60 requests/minute/IP, burst 20). Private media stays behind Django. The
existing proposed-values filename now records the admitted binding.
`railiance-platform/tools/provision-vergabe-demo.py` owns the fixed fresh
credential/database lane. It captures all child output and passes values only
on stdin; the durable credential copies are the two exact Kubernetes Secrets.
OpenBao automation remains a later owner improvement. Never rerun historical
bootstrap helpers or substitute apps_admin credentials.
The next product handoff is VERGABE-WP-0019-T06: preserve the invited tenant and
recipient through an allow-listed password-setup return and land on the admitted
demo-company welcome/sign-in path. Product authentication must validate its own
NetKingdom identity and tenant; it must not reuse the operator's portal session
or silently grant staff privileges. No application SSO is implemented yet.
Latest DNS evidence, 2026-09-12: both the recursive resolver and authoritative
ns1047.ui-dns.biz return NXDOMAIN for the product hostname (A and AAAA queried
recursively). This supersedes the earlier 80.158.43.29 observation for current
execution. The zone is served by IONOS ui-dns nameservers. The operator was asked
to add only A vergabe-teilnahme.coulomb.social → 92.205.62.239, TTL 300 or default.
No DNS credentials were requested or retrieved; native record readback and TLS
remain pending. Tenant paths continue sharing this one product hostname.
This is the first release in the fresh namespace; there is no previously
accepted application image to roll back to. On a failed next upgrade, stop public
traffic and reconcile schema/image compatibility before reverting. Retain the
claims and database; namespace deletion is not rollback. Pod replacement and
isolated restore must still be proven with matched PostgreSQL/media/SQLite data.

View file

@ -1,9 +1,12 @@
# Demo-company sign-in: prepared attended rollout
# Demo-company sign-in: executed attended rollout
2026-09-12, VERGABE-WP-0019-T06 / KEY-WP-0033 / NK-WP-0037.
Source, release images and server dry runs are complete. This packet has not
been applied to the running services. The existing application still serves
its interim local login.
The operator approved and the prepared rollout was applied on 2026-09-12.
All three services are Ready; Helm revision 2 serves the company welcome and
NetKingdom sign-in. Native invited-user/MFA acceptance remains pending.
See docs/evidence/2026-09-12-demo-company-sso-live.md.
The preparation and rollback record follows.
| Component | Source | Published digest |
| --- | --- | --- |
@ -84,3 +87,19 @@ bootstrap commands. Preserve data and the approved client configuration.
This release's native recipient/MFA acceptance is still open. RAPPS-WP-0014-T03
retains the coherent backup/isolated restore and pod-replacement proof;
VERGABE-WP-0019-T04 retains two-user collaboration and pilot acceptance.
2026-09-12 attended rollout executed after explicit operator approval. KeyCape
and password setup are Ready on the prepared digests; exact public client
registration was CAS-applied (config resourceVersion 60123977) with unrelated
config bytes/Secret data preserved. Existing portal and product client both
pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks).
Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain,
and requests remain 60m CPU/256Mi memory. Eleven live product checks pass:
company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only
login start, native issuer redirect, private company/media protection and
invalid callback/confirmation rejection. Initial readback showed zero accounts,
identity mappings and staff accounts. Native invited-user sign-in/MFA and
confirmation are now requested from the operator; no user credential was used
by the agent. Recovery and two-user acceptance remain their existing tasks.
Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.

View file

@ -160,3 +160,41 @@ custody, placement and recovery. VERGABE-WP-0019-T06 now explicitly tracks the
requested tenant welcome and connection to the new NetKingdom identity. The
earlier manually provisioned Django account path remains an interim capability;
it does not make the directory password a product credential or implement SSO.
## Live demo placement — 2026-09-12
2026-09-12 deployment evidence: the operator added A records for
vergabe-teilnahme.coulomb.social and users.coulomb.social. Authoritative IONOS
and recursive readback both return 92.205.62.239. Both cert-manager certificates
are Ready. The portal now uses https://users.coulomb.social/login; its legacy
nip.io address redirects to the canonical hostname. The exact new callback is
registered alongside the rollback callback; scopes, public client type and PKCE
remain unchanged. Canonical authorization succeeds; unapproved callback and
missing PKCE fail. This supersedes earlier DNS and portal-hostname blockers.
Helm release vergabe-teilnahme revision 1 is deployed in vergabe-demo-company,
chart 0.2.1, pinned product digest cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
Deployment UID 2152014d-a020-4c5e-a3b0-9575e9f21c44 is Ready 1/1. Its init
migration completed before the web process; both phases share the same 60m CPU /
256Mi memory request. Node requests now total 3965m of 4000m; the 35m remainder
matches the accepted prototype allocation. No unrelated resource requests changed.
RPF-WP-0039 delivered fresh vergabe_demo_company database/role on apps-pg and
runtime Secret vergabe-demo-company/vergabe-demo-env. The app's own connection
confirms that exact database/role. The role is non-superuser, cannot create roles
or databases, has a 20-connection ceiling and 15-second timeouts, and cannot
CONNECT to historical vergabe_db, coulomb_social_db or apps_meta. Both dedicated
PVCs are Bound: 5Gi media and 1Gi issue state. Historical data was not selected
or overwritten; no credentials are recorded here.
Thirteen live Chromium/HTTP checks pass: page and assets, secure tenant-scoped
CSRF cookie, anonymous login gate and media refusal, private operational path
refusal, neighboring/root path refusal, canonical slash, HTTPS redirect and
missing-CSRF POST denial. Migration/app initialization also proves consumer
connectivity. The empty product has zero accounts, including zero staff accounts.
The current login is still the interim Django login, not NetKingdom SSO. Native
recipient login, company welcome and account mapping remain VERGABE-WP-0019-T06.
RAPPS-WP-0014-T03 retains restart and coherent off-host backup/isolated restore;
the latest existing apps-pg base backup predates this new database. No pilot-user
acceptance, shared tenancy, MFA completion or natural factory-worker trace is claimed.