docs: unblock demo pilot login provisioning
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 22:00:38 +02:00
parent 428d0707e0
commit effd0a3170
2 changed files with 13 additions and 7 deletions

View file

@ -36,9 +36,12 @@ the response and read back the exact tenant before creating memberships. Do not
substitute a service actor, fabricate verified claims, or bypass policy on denial.
Native login and operator creation succeeded at 19:03:18 UTC. Tenant Engine
confirms demo-company active/version 1; User Engine contains the first
administrator with invited status. A subsequent Create login fails with an
LLDAP service-login 401. NK-WP-0036-T04 owns the attended credential-reference
repair; no directory identity is inferred from the user-domain record.
administrator with invited status. A subsequent Create login failed with an
LLDAP service-login 401. The operator completed NK-WP-0036-T04's attended
credential-reference repair: provider and consumer login now pass, independently
verified with a directory read; the provider password and image are unchanged.
Retry native Create login for the existing intended user and verify password
setup. No directory identity is inferred from the user-domain record.
Create two ordinary memberships through User Engine. Confirm how the identity
provisioner assigns login names before provisioning the requested demo names;

View file

@ -39,7 +39,7 @@ values template prepare the deployment; no live resources were changed.
id: RAPPS-WP-0014-T02
status: progress
needs_human: true
intervention_note: "Native demo-company exists; product host/path is selected. Identity-provisioner LLDAP login returns 401 after credential reload; NK-WP-0036-T04 holds attended consumer credential reconciliation. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed."
intervention_note: "Native demo-company exists; product host/path is selected. NK-WP-0036-T04 credential reconciliation is complete and independently verified. Native Create login/password setup must now be retried for the existing user. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed."
priority: high
assignee: the-custodian
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
@ -94,9 +94,12 @@ Engine readback confirms active, version 1. The chosen first administrator is
present with invited status. A subsequent user was created, but Create login
fails in identity-provisioner at the LLDAP admin authentication step, before
directory mutation. Reloading the existing credential reference preserves this
401. NK-WP-0036-T04 owns the prepared attended consumer-only reconciliation;
T05 retains the functional dependency preflight/error-reporting improvement.
No provider password has been changed, and no failed login create was replayed.
401. The operator subsequently completed NK-WP-0036-T04's attended repair.
Both the helper receipt and independent consumer verification confirm directory
authentication and read access. Secret resourceVersion is now 60026132; the
provider password and provisioner image are unchanged. Native Create login and
password setup for the existing user remain pending. T05 retains the functional
dependency preflight/error-reporting improvement.
Vergabe source 9345a1b supports APP_BASE_PATH=/demo-company, prefix-aware URL
reversing and cookie scope. All 98 application tests, Vite build and seven