Record deployed Vergabe pilot chart and company sign-in evidence
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
fd5e57bc99
commit
e8a7ff2547
13 changed files with 479 additions and 88 deletions
36
docs/evidence/2026-09-12-demo-company-deployment.md
Normal file
36
docs/evidence/2026-09-12-demo-company-deployment.md
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
# Demo-company deployment receipt
|
||||
|
||||
2026-09-12 deployment evidence: the operator added A records for
|
||||
vergabe-teilnahme.coulomb.social and users.coulomb.social. Authoritative IONOS
|
||||
and recursive readback both return 92.205.62.239. Both cert-manager certificates
|
||||
are Ready. The portal now uses https://users.coulomb.social/login; its legacy
|
||||
nip.io address redirects to the canonical hostname. The exact new callback is
|
||||
registered alongside the rollback callback; scopes, public client type and PKCE
|
||||
remain unchanged. Canonical authorization succeeds; unapproved callback and
|
||||
missing PKCE fail. This supersedes earlier DNS and portal-hostname blockers.
|
||||
|
||||
Helm release vergabe-teilnahme revision 1 is deployed in vergabe-demo-company,
|
||||
chart 0.2.1, pinned product digest cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
|
||||
Deployment UID 2152014d-a020-4c5e-a3b0-9575e9f21c44 is Ready 1/1. Its init
|
||||
migration completed before the web process; both phases share the same 60m CPU /
|
||||
256Mi memory request. Node requests now total 3965m of 4000m; the 35m remainder
|
||||
matches the accepted prototype allocation. No unrelated resource requests changed.
|
||||
|
||||
RPF-WP-0039 delivered fresh vergabe_demo_company database/role on apps-pg and
|
||||
runtime Secret vergabe-demo-company/vergabe-demo-env. The app's own connection
|
||||
confirms that exact database/role. The role is non-superuser, cannot create roles
|
||||
or databases, has a 20-connection ceiling and 15-second timeouts, and cannot
|
||||
CONNECT to historical vergabe_db, coulomb_social_db or apps_meta. Both dedicated
|
||||
PVCs are Bound: 5Gi media and 1Gi issue state. Historical data was not selected
|
||||
or overwritten; no credentials are recorded here.
|
||||
|
||||
Thirteen live Chromium/HTTP checks pass: page and assets, secure tenant-scoped
|
||||
CSRF cookie, anonymous login gate and media refusal, private operational path
|
||||
refusal, neighboring/root path refusal, canonical slash, HTTPS redirect and
|
||||
missing-CSRF POST denial. Migration/app initialization also proves consumer
|
||||
connectivity. The empty product has zero accounts, including zero staff accounts.
|
||||
The current login is still the interim Django login, not NetKingdom SSO. Native
|
||||
recipient login, company welcome and account mapping remain VERGABE-WP-0019-T06.
|
||||
RAPPS-WP-0014-T03 retains restart and coherent off-host backup/isolated restore;
|
||||
the latest existing apps-pg base backup predates this new database. No pilot-user
|
||||
acceptance, shared tenancy, MFA completion or natural factory-worker trace is claimed.
|
||||
27
docs/evidence/2026-09-12-demo-company-sso-live.md
Normal file
27
docs/evidence/2026-09-12-demo-company-sso-live.md
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
# Demo-company sign-in live rollout
|
||||
|
||||
Recorded 2026-09-12T01:09:00.835106+00:00
|
||||
|
||||
|
||||
2026-09-12 attended rollout executed after explicit operator approval. KeyCape
|
||||
and password setup are Ready on the prepared digests; exact public client
|
||||
registration was CAS-applied (config resourceVersion 60123977) with unrelated
|
||||
config bytes/Secret data preserved. Existing portal and product client both
|
||||
pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks).
|
||||
Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain,
|
||||
and requests remain 60m CPU/256Mi memory. Eleven live product checks pass:
|
||||
company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only
|
||||
login start, native issuer redirect, private company/media protection and
|
||||
invalid callback/confirmation rejection. Initial readback showed zero accounts,
|
||||
identity mappings and staff accounts. Native invited-user sign-in/MFA and
|
||||
confirmation are now requested from the operator; no user credential was used
|
||||
by the agent. Recovery and two-user acceptance remain their existing tasks.
|
||||
Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.
|
||||
|
||||
| Component | Deployed digest |
|
||||
| --- | --- |
|
||||
| Vergabe | sha256:2cb393608a82be2851adfc27f2bf4d8ef5d709f1b0038be5d0999e38c68b039e |
|
||||
| KeyCape | sha256:5f10f36a5da23ce1aaf3df9b84a8ff98d7926f34ceaa19e63bd3356adb68e01a |
|
||||
| Password setup | sha256:55f744cc9bc2ec3fe23eb7175fa4b7bfcc7a29469d9b9a1a8eaefc75d790dfc6 |
|
||||
|
||||
Cluster UID: a553c742-0115-43d4-99a4-a5ca56fe0786. The operator explicitly approved the prepared attended rollout. Shared issuer startup is proven; authenticated recipient token/account acceptance remains pending.
|
||||
Loading…
Add table
Add a link
Reference in a new issue