Prepare verified Vergabe company sign-in rollout
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
02c29eec53
commit
fd5e57bc99
4 changed files with 172 additions and 3 deletions
86
docs/vergabe-demo-company-sso-rollout.md
Normal file
86
docs/vergabe-demo-company-sso-rollout.md
Normal file
|
|
@ -0,0 +1,86 @@
|
||||||
|
# Demo-company sign-in: prepared attended rollout
|
||||||
|
|
||||||
|
2026-09-12, VERGABE-WP-0019-T06 / KEY-WP-0033 / NK-WP-0037.
|
||||||
|
Source, release images and server dry runs are complete. This packet has not
|
||||||
|
been applied to the running services. The existing application still serves
|
||||||
|
its interim local login.
|
||||||
|
|
||||||
|
| Component | Source | Published digest |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| Vergabe | 8be281025bf57a7aefd1fe98a7e060f2173df5ef | sha256:2cb393608a82be2851adfc27f2bf4d8ef5d709f1b0038be5d0999e38c68b039e |
|
||||||
|
| KeyCape | 8d4336e9448c564ac85f5f10dc75fff3c553564c | sha256:5f10f36a5da23ce1aaf3df9b84a8ff98d7926f34ceaa19e63bd3356adb68e01a |
|
||||||
|
| Password setup | 48a75b1a5456f224b077b73af1b345473823a743 | sha256:55f744cc9bc2ec3fe23eb7175fa4b7bfcc7a29469d9b9a1a8eaefc75d790dfc6 |
|
||||||
|
|
||||||
|
125 local application tests pass, including 27 OIDC cases; assets build and
|
||||||
|
migration drift checks pass. The full KeyCape Go suite passes. Sixteen
|
||||||
|
provisioner tests pass locally and against the published runtime image,
|
||||||
|
including HTTP issuance/completion. Two registration-helper tests pass.
|
||||||
|
|
||||||
|
Vergabe image publication run 51 passed. Acceptance run 49 completed its test
|
||||||
|
stage but failed during image export; its log stops there, so the precise
|
||||||
|
export failure cause is not established. Run 52 acceptance and run 53 smoke
|
||||||
|
both pass on cf50cc55338e298de56f2a6e1929848a4bfbc0ae; its only difference from
|
||||||
|
8be2810 is the generated brief. KeyCape image publication run 45 passed.
|
||||||
|
|
||||||
|
## Why the shared rollout is attended
|
||||||
|
|
||||||
|
`key-cape/docs/operations.md`, section on the two changes after the deployed
|
||||||
|
image, says the live boot "belongs to the attended rollout window and not to
|
||||||
|
a session running against production on its own." The current issuer is
|
||||||
|
source dcebd46 / digest 7ff54c54. The new release includes the accepted browser
|
||||||
|
client startup validation and tenant provenance changes as well as this
|
||||||
|
session's fresh-login forwarding. These affect the shared issuer. The existing
|
||||||
|
one-replica Recreate strategy interrupts pending logins; the provisioner's
|
||||||
|
in-memory setup links also expire on restart. No credential rotation is needed.
|
||||||
|
|
||||||
|
The exact client addition passed the owner's guarded server dry run against
|
||||||
|
sso/keycape-config UID 2e94519d-1550-41c7-9701-2efe47fe1fd3, resourceVersion
|
||||||
|
60090393. The helper preserves unrelated configuration bytes and other Secret
|
||||||
|
data, checks the changed browser-client startup constraint and refuses drift.
|
||||||
|
Repeat inspection immediately before applying; the recorded revision is not a
|
||||||
|
license to replay over a changed configuration.
|
||||||
|
|
||||||
|
## Prepared files and execution order
|
||||||
|
|
||||||
|
1. Inspect/dry-run/apply the exact client with
|
||||||
|
`net-kingdom/sso-mfa/k8s/keycape/vergabe-client-rollout.py`. The public client
|
||||||
|
has only openid/profile/groups and one exact HTTPS callback. It declares no
|
||||||
|
tenant and does not weaken the provider's MFA policy.
|
||||||
|
2. Apply `net-kingdom/sso-mfa/k8s/keycape/vergabe-fresh-login.proposed.patch.yaml`
|
||||||
|
as a strategic patch to sso/keycape. Wait for Ready and verify discovery,
|
||||||
|
existing portal authorization, invalid redirect and missing-PKCE rejection,
|
||||||
|
and propagation of prompt=login to Authelia. On failure, restore the previous
|
||||||
|
image and withhold product activation; preserve the client and all Secrets.
|
||||||
|
3. Apply `net-kingdom/sso-mfa/k8s/identity-provisioner/company-welcome.proposed.patch.yaml`
|
||||||
|
to sso/identity-provisioner. Its 25m/32Mi request and credential references
|
||||||
|
stay unchanged. The fixed tenant map returns successful setup to the company
|
||||||
|
entry without tokens, recipient credentials or automatic product login.
|
||||||
|
4. Apply `helm/vergabe-demo-company-oidc-egress.proposed.yaml`. It admits only
|
||||||
|
issuer HTTPS via the current public IP and its translated Traefik endpoint.
|
||||||
|
Use Helm upgrade for the app, layering
|
||||||
|
`helm/vergabe-demo-company-sso.proposed.yaml` over the existing admitted
|
||||||
|
`helm/vergabe-demo-company-values.proposed.yaml`, with the current chart.
|
||||||
|
The new mapping-table migration runs in the existing 60m/256Mi init envelope.
|
||||||
|
Both current PVCs and database remain. The server-side dry run passed in the
|
||||||
|
actual vergabe-demo-company namespace. Keep the 60m request and Recreate.
|
||||||
|
5. Confirm issuer connectivity from the application, welcome/CSRF/prefix/media
|
||||||
|
protection and a rejected platform identity. Then the actual invited user
|
||||||
|
completes fresh login and any required MFA, checks their account on the
|
||||||
|
confirmation page and enters the company workflow. Do not use operator
|
||||||
|
credentials or create a substitute shared Django password.
|
||||||
|
|
||||||
|
## Rollback and remaining acceptance
|
||||||
|
|
||||||
|
Before application activation, all current images remain valid rollback
|
||||||
|
references in the existing deployment receipt. Once OIDC accounts exist they
|
||||||
|
have unusable local passwords. Disable NETKINGDOM_ENABLED or restore the prior
|
||||||
|
app image to return to the interim gate; that is containment, not a credential
|
||||||
|
fallback for these users. Keep the new identity table and all three data stores.
|
||||||
|
|
||||||
|
Restore the provisioner's previous image 5b460f5ca9e329e287939f4707a2bb8d5674b7f94e24cfb5f6d790f54c3f8d06
|
||||||
|
if its rollout fails. Do not rotate its directory credential or rerun historical
|
||||||
|
bootstrap commands. Preserve data and the approved client configuration.
|
||||||
|
|
||||||
|
This release's native recipient/MFA acceptance is still open. RAPPS-WP-0014-T03
|
||||||
|
retains the coherent backup/isolated restore and pod-replacement proof;
|
||||||
|
VERGABE-WP-0019-T04 retains two-user collaboration and pilot acceptance.
|
||||||
27
helm/vergabe-demo-company-oidc-egress.proposed.yaml
Normal file
27
helm/vergabe-demo-company-oidc-egress.proposed.yaml
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: NetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: vergabe-oidc-issuer-egress
|
||||||
|
namespace: vergabe-demo-company
|
||||||
|
spec:
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: vergabe-teilnahme
|
||||||
|
app.kubernetes.io/instance: vergabe-teilnahme
|
||||||
|
policyTypes: [Egress]
|
||||||
|
egress:
|
||||||
|
- to:
|
||||||
|
- ipBlock:
|
||||||
|
cidr: 92.205.62.239/32
|
||||||
|
ports:
|
||||||
|
- {protocol: TCP, port: 443}
|
||||||
|
# The same public TLS route after K3s translates the node destination.
|
||||||
|
- to:
|
||||||
|
- namespaceSelector:
|
||||||
|
matchLabels:
|
||||||
|
kubernetes.io/metadata.name: kube-system
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: traefik
|
||||||
|
ports:
|
||||||
|
- {protocol: TCP, port: 8443}
|
||||||
10
helm/vergabe-demo-company-sso.proposed.yaml
Normal file
10
helm/vergabe-demo-company-sso.proposed.yaml
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
# Layer over the admitted demo-company values during the attended rollout.
|
||||||
|
image:
|
||||||
|
digest: sha256:2cb393608a82be2851adfc27f2bf4d8ef5d709f1b0038be5d0999e38c68b039e
|
||||||
|
env:
|
||||||
|
NETKINGDOM_ENABLED: "true"
|
||||||
|
NETKINGDOM_ISSUER: https://kc.coulomb.social
|
||||||
|
NETKINGDOM_CLIENT_ID: vergabe-demo-company
|
||||||
|
NETKINGDOM_CALLBACK: https://vergabe-teilnahme.coulomb.social/demo-company/accounts/oidc/callback/
|
||||||
|
NETKINGDOM_TENANT: tenant:trial:demo-company
|
||||||
|
COMPANY_DISPLAY_NAME: Demo Company
|
||||||
|
|
@ -38,8 +38,8 @@ values template prepare the deployment; no live resources were changed.
|
||||||
```task
|
```task
|
||||||
id: RAPPS-WP-0014-T02
|
id: RAPPS-WP-0014-T02
|
||||||
status: progress
|
status: progress
|
||||||
needs_human: true
|
needs_human: false
|
||||||
intervention_note: "Native tenant/user/password setup succeeds; three memberships and one linked identity are verified. Product DNS/TLS, fresh database/Secret, application deployment and tenant welcome/sign-in remain. VERGABE-WP-0019-T06 retains the product handoff. No new approval for the 60m prototype is needed."
|
intervention_note: "DNS, TLS and application placement are verified. Product SSO/welcome and pilot/recovery acceptance remain in the existing owner tasks."
|
||||||
priority: high
|
priority: high
|
||||||
assignee: the-custodian
|
assignee: the-custodian
|
||||||
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
|
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
|
||||||
|
|
@ -118,6 +118,52 @@ identity linkage and a tenant welcome handoff are explicitly VERGABE-WP-0019-T06
|
||||||
This supersedes the preceding pending-Create-login state; the app itself is not
|
This supersedes the preceding pending-Create-login state; the app itself is not
|
||||||
yet deployed and native identity success does not establish a Django session.
|
yet deployed and native identity success does not establish a Django session.
|
||||||
|
|
||||||
|
2026-09-12 deployment evidence: the operator added A records for
|
||||||
|
vergabe-teilnahme.coulomb.social and users.coulomb.social. Authoritative IONOS
|
||||||
|
and recursive readback both return 92.205.62.239. Both cert-manager certificates
|
||||||
|
are Ready. The portal now uses https://users.coulomb.social/login; its legacy
|
||||||
|
nip.io address redirects to the canonical hostname. The exact new callback is
|
||||||
|
registered alongside the rollback callback; scopes, public client type and PKCE
|
||||||
|
remain unchanged. Canonical authorization succeeds; unapproved callback and
|
||||||
|
missing PKCE fail. This supersedes earlier DNS and portal-hostname blockers.
|
||||||
|
|
||||||
|
Helm release vergabe-teilnahme revision 1 is deployed in vergabe-demo-company,
|
||||||
|
chart 0.2.1, pinned product digest cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
|
||||||
|
Deployment UID 2152014d-a020-4c5e-a3b0-9575e9f21c44 is Ready 1/1. Its init
|
||||||
|
migration completed before the web process; both phases share the same 60m CPU /
|
||||||
|
256Mi memory request. Node requests now total 3965m of 4000m; the 35m remainder
|
||||||
|
matches the accepted prototype allocation. No unrelated resource requests changed.
|
||||||
|
|
||||||
|
RPF-WP-0039 delivered fresh vergabe_demo_company database/role on apps-pg and
|
||||||
|
runtime Secret vergabe-demo-company/vergabe-demo-env. The app's own connection
|
||||||
|
confirms that exact database/role. The role is non-superuser, cannot create roles
|
||||||
|
or databases, has a 20-connection ceiling and 15-second timeouts, and cannot
|
||||||
|
CONNECT to historical vergabe_db, coulomb_social_db or apps_meta. Both dedicated
|
||||||
|
PVCs are Bound: 5Gi media and 1Gi issue state. Historical data was not selected
|
||||||
|
or overwritten; no credentials are recorded here.
|
||||||
|
|
||||||
|
Thirteen live Chromium/HTTP checks pass: page and assets, secure tenant-scoped
|
||||||
|
CSRF cookie, anonymous login gate and media refusal, private operational path
|
||||||
|
refusal, neighboring/root path refusal, canonical slash, HTTPS redirect and
|
||||||
|
missing-CSRF POST denial. Migration/app initialization also proves consumer
|
||||||
|
connectivity. The empty product has zero accounts, including zero staff accounts.
|
||||||
|
The current login is still the interim Django login, not NetKingdom SSO. Native
|
||||||
|
recipient login, company welcome and account mapping remain VERGABE-WP-0019-T06.
|
||||||
|
RAPPS-WP-0014-T03 retains restart and coherent off-host backup/isolated restore;
|
||||||
|
the latest existing apps-pg base backup predates this new database. No pilot-user
|
||||||
|
acceptance, shared tenancy, MFA completion or natural factory-worker trace is claimed.
|
||||||
|
|
||||||
|
|
||||||
|
2026-09-12 SSO release preparation: docs/vergabe-demo-company-sso-rollout.md
|
||||||
|
contains the exact published app/issuer/provisioner digests, server dry runs,
|
||||||
|
attended sequence and rollback. The new helm/vergabe-demo-company-sso.proposed.yaml
|
||||||
|
layers over the admitted values and retains the 60m/256Mi allocation. The narrow
|
||||||
|
issuer-egress policy is also proposed, not applied. The shared KeyCape upgrade
|
||||||
|
requires the attended window described in its operations document. Native
|
||||||
|
recipient/MFA and product acceptance stay with VERGABE-WP-0019-T06; recovery
|
||||||
|
remains T03 here. No live runtime changes were made in this continuation.
|
||||||
|
|
||||||
|
|
||||||
## Demonstrate restart, isolated restore, rollback and operating ownership
|
## Demonstrate restart, isolated restore, rollback and operating ownership
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
@ -126,7 +172,7 @@ status: wait
|
||||||
priority: high
|
priority: high
|
||||||
assignee: the-custodian
|
assignee: the-custodian
|
||||||
depends_on: [RAPPS-WP-0014-T02]
|
depends_on: [RAPPS-WP-0014-T02]
|
||||||
blocking_reason: "Await exact placement/release/data binding before native rehearsal and admission."
|
blocking_reason: "Placement and data binding are live; verify product account onboarding and run the coherent restart/restore rehearsal before pilot admission."
|
||||||
state_hub_task_id: "dd069c6d-fcc1-5bac-b233-976f2f0d5cd1"
|
state_hub_task_id: "dd069c6d-fcc1-5bac-b233-976f2f0d5cd1"
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue