Record deployed Vergabe pilot chart and company sign-in evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-12 03:12:45 +02:00
parent fd5e57bc99
commit e8a7ff2547
13 changed files with 479 additions and 88 deletions

View file

@ -1,9 +1,12 @@
# Demo-company sign-in: prepared attended rollout
# Demo-company sign-in: executed attended rollout
2026-09-12, VERGABE-WP-0019-T06 / KEY-WP-0033 / NK-WP-0037.
Source, release images and server dry runs are complete. This packet has not
been applied to the running services. The existing application still serves
its interim local login.
The operator approved and the prepared rollout was applied on 2026-09-12.
All three services are Ready; Helm revision 2 serves the company welcome and
NetKingdom sign-in. Native invited-user/MFA acceptance remains pending.
See docs/evidence/2026-09-12-demo-company-sso-live.md.
The preparation and rollback record follows.
| Component | Source | Published digest |
| --- | --- | --- |
@ -84,3 +87,19 @@ bootstrap commands. Preserve data and the approved client configuration.
This release's native recipient/MFA acceptance is still open. RAPPS-WP-0014-T03
retains the coherent backup/isolated restore and pod-replacement proof;
VERGABE-WP-0019-T04 retains two-user collaboration and pilot acceptance.
2026-09-12 attended rollout executed after explicit operator approval. KeyCape
and password setup are Ready on the prepared digests; exact public client
registration was CAS-applied (config resourceVersion 60123977) with unrelated
config bytes/Secret data preserved. Existing portal and product client both
pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks).
Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain,
and requests remain 60m CPU/256Mi memory. Eleven live product checks pass:
company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only
login start, native issuer redirect, private company/media protection and
invalid callback/confirmation rejection. Initial readback showed zero accounts,
identity mappings and staff accounts. Native invited-user sign-in/MFA and
confirmation are now requested from the operator; no user credential was used
by the agent. Recovery and two-user acceptance remain their existing tasks.
Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.