--- id: RAPPS-WP-0014 type: workplan title: "Deploy and recover the first invited Vergabe company pilot" domain: financials repo: railiance-apps status: active owner: the-custodian topic_slug: railiance created: "2026-09-11" updated: "2026-09-11" related: [VERGABE-WP-0019, VERGABE-WP-0018, HFACT-WP-0001, CUST-WP-0071] state_hub_workstream_id: "c7fdaa7e-cab8-5d1d-86c2-f1aad7927c57" --- # Invited Vergabe pilot on Railiance ## Prepare a durable and immutable single-company chart ```task id: RAPPS-WP-0014-T01 status: done priority: high assignee: the-custodian state_hub_task_id: "378e1f1a-701f-531e-aa92-95a09e7a32d3" ``` Extend the existing media PVC support with a distinct issue-facade state PVC, optional existing claims for restore, retained claims on Helm uninstall and Recreate rollout when persistent local state is mounted. Pilot mode requires one replica, both durable stores, distinct claims and a valid OCI image digest. The legacy opt-in behavior remains available for non-pilot installations. Seven render regression tests and Helm lint pass. Chart 0.2.0 and the review-only values template prepare the deployment; no live resources were changed. ## Bind the exact company, release, placement, data and access ```task id: RAPPS-WP-0014-T02 status: progress needs_human: true intervention_note: "Native demo-company exists; product host/path is selected. NK-WP-0036-T04 credential reconciliation is complete and independently verified. Native Create login/password setup must now be retried for the existing user. DNS/TLS, new database/Secret, app deployment and ordinary demo accounts remain. No new approval for the 60m prototype is needed." priority: high assignee: the-custodian state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897" ``` Consume VERGABE-WP-0019-T02's login-protected release after live CI/publication. Record exact image/chart revision, company, user count, host/TLS, dedicated namespace, database/role, both PVCs and admitted runtime Secret custody. The user now selects a fresh demo-company workspace (2026-09-11). Existing vergabe_db is not test data. Resolve target inventory before using historical runbook names: the checked Railiance cluster has no vergabe-teilnahme namespace or matching Deployment on 2026-09-11. Do not infer data loss or authorization to recreate it. The user explicitly accepts a 60m CPU request for one tenant with very few users on 2026-09-11. This prototype prioritizes the deployment/onboarding path; 60m is not a measured minimum or a production sizing claim. The pilot values now override the inherited 100m request; CPU limit and memory remain unchanged. Fresh metadata still shows `databases/apps-pg` healthy (1/1), 3905m requested against 4000m allocatable and 95m available. A 60m application pod fits that CPU snapshot with 35m remaining; refresh exact placement and any transient migration/rollout demand before applying. This supersedes the earlier demand- measurement prerequisite for this specific prototype, not unrelated allocations. CUST-WP-0071 is persisted/registered for later measured sizing and a final weekly assessment setup. STATE-WP-0091 retains release preflight and shared-headroom work. Neither is a new prerequisite for this accepted pilot. Fresh CNPG metadata reports `vergabe-db` applied for `vergabe_db`/`vergabe`, two managed consumer roles with 20-connection limits, and a successful apps-pg backup at 2026-09-11T02:15:11Z. Database contents have not been inspected or modified; metadata does not select reuse or grant access to that data. See the dated inventory and pilot allocation receipt. Use `docs/vergabe-teilnahme-pilot.md` for the review packet. Secret creation, operator access and placement consume existing platform lanes; they do not create a parallel identity framework. The public edge needs an admitted login abuse-control policy and TLS; Django's authentication gate alone is not a rate limiter. Keep `/media/` behind the app gate. The user requests a new `demo-company` tenant with `demo-user1`, etc. Apply NetKingdom ADR-0013 as `tenant:trial:demo-company` and start with two ordinary demo users. Fresh data is selected; no historical customer import is authorized. The prepared namespace/database/release and current execution status are in `docs/vergabe-demo-company-binding.md` and `helm/vergabe-demo-company-values.proposed.yaml`. The user chose `https://vergabe-teilnahme.coulomb.social/demo-company`. DNS/TLS is per product host; the exact company prefix selects its isolated application instance. The chosen hostname currently resolves to 80.158.43.29 and needs the admitted Railiance01 route (92.205.62.239) through the edge owner. Native operator authentication as platform-root succeeded. At 19:03:18 UTC the operator created demo-company through the native User Engine form; Tenant Engine readback confirms active, version 1. The chosen first administrator is present with invited status. A subsequent user was created, but Create login fails in identity-provisioner at the LLDAP admin authentication step, before directory mutation. Reloading the existing credential reference preserves this 401. The operator subsequently completed NK-WP-0036-T04's attended repair. Both the helper receipt and independent consumer verification confirm directory authentication and read access. Secret resourceVersion is now 60026132; the provider password and provisioner image are unchanged. Native Create login and password setup for the existing user remain pending. T05 retains the functional dependency preflight/error-reporting improvement. Vergabe source 9345a1b supports APP_BASE_PATH=/demo-company, prefix-aware URL reversing and cookie scope. All 98 application tests, Vite build and seven local Chromium path/edge checks pass. CI smoke 43 and publication 44 passed; the proposed values now pin sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68 and APP_BASE_PATH=/demo-company. The previous root-path image is superseded. Ordinary demo memberships and Django accounts remain separate from platform tenant existence. No product SSO is claimed. The selected URL and successful tenant creation are resolved inputs. ## Demonstrate restart, isolated restore, rollback and operating ownership ```task id: RAPPS-WP-0014-T03 status: wait priority: high assignee: the-custodian depends_on: [RAPPS-WP-0014-T02] blocking_reason: "Await exact placement/release/data binding before native rehearsal and admission." state_hub_task_id: "dd069c6d-fcc1-5bac-b233-976f2f0d5cd1" ``` With synthetic fixture data on the admitted deployment, prove login and health, two-user collaboration, document upload/download and issue state across pod replacement. Establish a consistent recovery point for PostgreSQL, media and issue-facade SQLite; rehearse recovery into a separate database and separate claims, repeat the workflow, and record recovery time and checksums without customer content. Record backup owner/cadence/retention/off-host destination, restore command revision and monitoring/incident owner. Retained local-path PVCs are neither off-host backup nor node-failure protection. Review upgrade/migration effects and exact rollback image/data handling. A single-writer Recreate release has a short service interruption; do not promise HA. Return evidence to VERGABE-WP-0019-T03/T04 before customer invitations. Native factory-produced delivery remains VERGABE-WP-0018/HFACT-WP-0001's separate claim. Pricing and shared-app tenancy are outside this invited-pilot milestone.