railiance-apps/workplans/RAPPS-WP-0014-vergabe-invited-pilot.md
tegwick e8a7ff2547
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s
Record deployed Vergabe pilot chart and company sign-in evidence
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 03:12:45 +02:00

208 lines
12 KiB
Markdown

---
id: RAPPS-WP-0014
type: workplan
title: "Deploy and recover the first invited Vergabe company pilot"
domain: financials
repo: railiance-apps
status: active
owner: the-custodian
topic_slug: railiance
created: "2026-09-11"
updated: "2026-09-12"
related: [VERGABE-WP-0019, VERGABE-WP-0018, HFACT-WP-0001, CUST-WP-0071]
state_hub_workstream_id: "c7fdaa7e-cab8-5d1d-86c2-f1aad7927c57"
---
# Invited Vergabe pilot on Railiance
## Prepare a durable and immutable single-company chart
```task
id: RAPPS-WP-0014-T01
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "378e1f1a-701f-531e-aa92-95a09e7a32d3"
```
Extend the existing media PVC support with a distinct issue-facade state PVC,
optional existing claims for restore, retained claims on Helm uninstall and
Recreate rollout when persistent local state is mounted. Pilot mode requires
one replica, both durable stores, distinct claims and a valid OCI image digest.
The legacy opt-in behavior remains available for non-pilot installations.
Seven render regression tests and Helm lint pass. Chart 0.2.0 and the review-only
values template prepare the deployment; no live resources were changed.
## Bind the exact company, release, placement, data and access
```task
id: RAPPS-WP-0014-T02
status: progress
needs_human: false
intervention_note: "DNS, TLS and application placement are verified. Product SSO/welcome and pilot/recovery acceptance remain in the existing owner tasks."
priority: high
assignee: the-custodian
state_hub_task_id: "b00958c8-1401-5ebf-bc22-c0252618d897"
```
Consume VERGABE-WP-0019-T02's login-protected release after live CI/publication.
Record exact image/chart revision, company, user count, host/TLS, dedicated
namespace, database/role, both PVCs and admitted runtime Secret custody. The
user now selects a fresh demo-company workspace (2026-09-11). Existing vergabe_db is not test
data. Resolve target inventory before using historical runbook names: the
checked Railiance cluster has no vergabe-teilnahme namespace or matching
Deployment on 2026-09-11. Do not infer data loss or authorization to recreate it.
The user explicitly accepts a 60m CPU request for one tenant with very few
users on 2026-09-11. This prototype prioritizes the deployment/onboarding path;
60m is not a measured minimum or a production sizing claim. The pilot values
now override the inherited 100m request; CPU limit and memory remain unchanged.
Fresh metadata still shows `databases/apps-pg` healthy (1/1), 3905m requested
against 4000m allocatable and 95m available. A 60m application pod fits that
CPU snapshot with 35m remaining; refresh exact placement and any transient
migration/rollout demand before applying. This supersedes the earlier demand-
measurement prerequisite for this specific prototype, not unrelated allocations.
CUST-WP-0071 is persisted/registered for later measured sizing and a final weekly
assessment setup. STATE-WP-0091 retains release preflight and shared-headroom
work. Neither is a new prerequisite for this accepted pilot. Fresh CNPG metadata reports `vergabe-db` applied for `vergabe_db`/`vergabe`,
two managed consumer roles with 20-connection limits, and a successful apps-pg
backup at 2026-09-11T02:15:11Z. Database contents have not been inspected or
modified; metadata does not select reuse or grant access to that data. See the
dated inventory and pilot allocation receipt.
Use `docs/vergabe-teilnahme-pilot.md` for the review packet. Secret creation,
operator access and placement consume existing platform lanes; they do not
create a parallel identity framework. The public edge needs an admitted login
abuse-control policy and TLS; Django's authentication gate alone is not a rate
limiter. Keep `/media/` behind the app gate.
The user requests a new `demo-company` tenant with `demo-user1`, etc. Apply
NetKingdom ADR-0013 as `tenant:trial:demo-company` and start with two ordinary
demo users. Fresh data is selected; no historical customer import is authorized.
The prepared namespace/database/release and current execution status are in
`docs/vergabe-demo-company-binding.md` and
`helm/vergabe-demo-company-values.proposed.yaml`. The user chose
`https://vergabe-teilnahme.coulomb.social/demo-company`. DNS/TLS is per product
host; the exact company prefix selects its isolated application instance.
The chosen hostname currently resolves to 80.158.43.29 and needs the admitted
Railiance01 route (92.205.62.239) through the edge owner.
Native operator authentication as platform-root succeeded. At 19:03:18 UTC the
operator created demo-company through the native User Engine form; Tenant
Engine readback confirms active, version 1. The chosen first administrator is
present with invited status. A subsequent user was created, but Create login
fails in identity-provisioner at the LLDAP admin authentication step, before
directory mutation. Reloading the existing credential reference preserves this
401. The operator subsequently completed NK-WP-0036-T04's attended repair.
Both the helper receipt and independent consumer verification confirm directory
authentication and read access. Secret resourceVersion is now 60026132; the
provider password and provisioner image are unchanged. Native Create login and
password setup for the existing user remain pending. T05 retains the functional
dependency preflight/error-reporting improvement.
Vergabe source 9345a1b supports APP_BASE_PATH=/demo-company, prefix-aware URL
reversing and cookie scope. All 98 application tests, Vite build and seven
local Chromium path/edge checks pass. CI smoke 43 and publication 44 passed; the proposed values now pin
sha256:cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68
and APP_BASE_PATH=/demo-company. The previous root-path image is superseded. Ordinary demo memberships and
Django accounts remain separate from platform tenant existence. No product SSO
is claimed. The selected URL and successful tenant creation are resolved inputs.
2026-09-12 native milestone:the operator confirms portal login/logout and user
password setup (Password set). Read-only User Engine evidence shows three
demo-company memberships and one linked directory identity; private names,
addresses, passwords and setup links are excluded. USER-WP-0025 deployed visible
operator navigation, protected portal logout and tenant-name selection. Product
identity linkage and a tenant welcome handoff are explicitly VERGABE-WP-0019-T06.
This supersedes the preceding pending-Create-login state; the app itself is not
yet deployed and native identity success does not establish a Django session.
2026-09-12 deployment evidence: the operator added A records for
vergabe-teilnahme.coulomb.social and users.coulomb.social. Authoritative IONOS
and recursive readback both return 92.205.62.239. Both cert-manager certificates
are Ready. The portal now uses https://users.coulomb.social/login; its legacy
nip.io address redirects to the canonical hostname. The exact new callback is
registered alongside the rollback callback; scopes, public client type and PKCE
remain unchanged. Canonical authorization succeeds; unapproved callback and
missing PKCE fail. This supersedes earlier DNS and portal-hostname blockers.
Helm release vergabe-teilnahme revision 1 is deployed in vergabe-demo-company,
chart 0.2.1, pinned product digest cebe8ca6218cc89f903e8a69e06ac50d3812526d4119cf4da485cc173f674b68.
Deployment UID 2152014d-a020-4c5e-a3b0-9575e9f21c44 is Ready 1/1. Its init
migration completed before the web process; both phases share the same 60m CPU /
256Mi memory request. Node requests now total 3965m of 4000m; the 35m remainder
matches the accepted prototype allocation. No unrelated resource requests changed.
RPF-WP-0039 delivered fresh vergabe_demo_company database/role on apps-pg and
runtime Secret vergabe-demo-company/vergabe-demo-env. The app's own connection
confirms that exact database/role. The role is non-superuser, cannot create roles
or databases, has a 20-connection ceiling and 15-second timeouts, and cannot
CONNECT to historical vergabe_db, coulomb_social_db or apps_meta. Both dedicated
PVCs are Bound: 5Gi media and 1Gi issue state. Historical data was not selected
or overwritten; no credentials are recorded here.
Thirteen live Chromium/HTTP checks pass: page and assets, secure tenant-scoped
CSRF cookie, anonymous login gate and media refusal, private operational path
refusal, neighboring/root path refusal, canonical slash, HTTPS redirect and
missing-CSRF POST denial. Migration/app initialization also proves consumer
connectivity. The empty product has zero accounts, including zero staff accounts.
The current login is still the interim Django login, not NetKingdom SSO. Native
recipient login, company welcome and account mapping remain VERGABE-WP-0019-T06.
RAPPS-WP-0014-T03 retains restart and coherent off-host backup/isolated restore;
the latest existing apps-pg base backup predates this new database. No pilot-user
acceptance, shared tenancy, MFA completion or natural factory-worker trace is claimed.
2026-09-12 SSO release preparation: docs/vergabe-demo-company-sso-rollout.md
contains the exact published app/issuer/provisioner digests, server dry runs,
attended sequence and rollback. The new helm/vergabe-demo-company-sso.proposed.yaml
layers over the admitted values and retains the 60m/256Mi allocation. The narrow
issuer-egress policy is also proposed, not applied. The shared KeyCape upgrade
requires the attended window described in its operations document. Native
recipient/MFA and product acceptance stay with VERGABE-WP-0019-T06; recovery
remains T03 here. No live runtime changes were made in this continuation.
2026-09-12 attended rollout executed after explicit operator approval. KeyCape
and password setup are Ready on the prepared digests; exact public client
registration was CAS-applied (config resourceVersion 60123977) with unrelated
config bytes/Secret data preserved. Existing portal and product client both
pass fresh-login forwarding, wrong-callback and missing-PKCE checks (6 checks).
Vergabe Helm revision 2 is Ready; identity migration completed, both PVCs remain,
and requests remain 60m CPU/256Mi memory. Eleven live product checks pass:
company welcome, anonymous gate, no-store, secure scoped CSRF, POST/CSRF-only
login start, native issuer redirect, private company/media protection and
invalid callback/confirmation rejection. Initial readback showed zero accounts,
identity mappings and staff accounts. Native invited-user sign-in/MFA and
confirmation are now requested from the operator; no user credential was used
by the agent. Recovery and two-user acceptance remain their existing tasks.
Evidence: railiance-apps/docs/evidence/2026-09-12-demo-company-sso-live.md.
## Demonstrate restart, isolated restore, rollback and operating ownership
```task
id: RAPPS-WP-0014-T03
status: wait
priority: high
assignee: the-custodian
depends_on: [RAPPS-WP-0014-T02]
blocking_reason: "Placement and data binding are live; verify product account onboarding and run the coherent restart/restore rehearsal before pilot admission."
state_hub_task_id: "dd069c6d-fcc1-5bac-b233-976f2f0d5cd1"
```
With synthetic fixture data on the admitted deployment, prove login and health,
two-user collaboration, document upload/download and issue state across pod
replacement. Establish a consistent recovery point for PostgreSQL, media and
issue-facade SQLite; rehearse recovery into a separate database and separate
claims, repeat the workflow, and record recovery time and checksums without
customer content. Record backup owner/cadence/retention/off-host destination,
restore command revision and monitoring/incident owner. Retained local-path
PVCs are neither off-host backup nor node-failure protection.
Review upgrade/migration effects and exact rollback image/data handling. A
single-writer Recreate release has a short service interruption; do not promise
HA. Return evidence to VERGABE-WP-0019-T03/T04 before customer invitations.
Native factory-produced delivery remains VERGABE-WP-0018/HFACT-WP-0001's separate
claim. Pricing and shared-app tenancy are outside this invited-pilot milestone.