railiance-telemetry/history/2026-09-28-alert-acknowledgment.md
tegwick c3800edb6b Record native SMTP credential delivery and accepted email proof
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
2026-09-28 11:27:00 +02:00

60 lines
3.9 KiB
Markdown

# Email acknowledgment implementation — 2026-09-28
Existing task RTEL-WP-0002-T04 holds this work; no task/workplan added.
User decision f149e316-4ef4-4855-8453-bc9cdc938aad approves email to
bernd.worsch@gmail.com, explicit receipt confirmation, Railiance admin role,
audit-core evidence and controlled drills. Subsequent direction selected From
platform@coulomb.social and confirmed the mailbox needs setup.
Implemented WSGI acknowledgment, immutable first receipt, atomic SQLite audit
outbox, bounded audit transport, OIDC code/PKCE sessions, native Flex Auth
binding/digest/lifetime checks, Waitress runtime and background audit draining.
GET is inert; POST requires verified human/platform/admin identity, a fresh PDP
allow, Origin and CSRF. Email links identify occurrences, not bearer credentials.
Validation: 33 core tests with actual audit-core 3e42ca8 ingestion, including
accepted/lost-reply/reopened-store/duplicate; seven runtime tests with signed RSA
issuer fixtures, complete browser flow and the actual Flex Auth evaluator.
Synthetic identities/credentials do not prove production login or custody.
Native Alertmanager 0.28.1 template render passed. Hash-pinned runtime container
built; network-isolated read-only container returned HTTP 200 health and exited
cleanly on SIGTERM. Package candidates reside in rapp-telemetry/acknowledgment.
Policy and browser client registration candidates reside in integration/.
Native changes: identity-provisioner verified tegwick's requested email and added
only railiance-admins, preserving other memberships. KeyCape 1164f65 maps that
explicit group to railiance-admin without granting platform-operator. Full Go
suite passed. Published immutable image:
sha256:6f79a2af1c695d39480173fad013facd84d21e7732860366af519302a2c496b8.
NetKingdom manifest server dry-run passed; diff changed only the image (plus
metadata). Deployment rolled out successfully. Signed role remains unverified
until a real login. No Kubernetes Secret values were read or printed.
Remaining gates: mailbox setup; scoped SMTP/webhook/audit custody and receiver
registration; safe OIDC client registration and enforced policy caller admission;
application rollout; native login and actual failure/absence emails, Bernd's
acknowledgments and independent audit readback; outside-node watchdog and
recurring backups. Existing owner client helpers read complete Kubernetes
Secrets and cannot be used under the current environment orientation's rule.
No live email or acknowledgment is claimed. Workplan stays blocked, T04 wait.
Subsequently the founder created platform@coulomb.social and requested an OpenBao
entry, with the password to be added by the founder as a new version. Platform
helper scripts/telemetry_smtp_entry.py is silent, CAS=0, never reads credential
values, and preserves any existing version. Four unit tests pass. Attended
founder OIDC/MFA execution is requested; no native KV creation is yet claimed.
Founder subsequently confirmed the password was added. Scoped SMTP delivery
resources installed; attended reader admission/authentication helper prepared
and tested (ten custody tests total). Native password/SMTP verification remains
pending attended login; this report is not a credential readback claim.
Attended receipt now verified: KV version 2, IONOS authentication passed, exact
reader admitted, coding-agent deny boundary passed, password unmodified. Native
ClusterSecretStore and ExternalSecret are Ready/SecretSynced. Initial in-cluster
SMTP test failed under existing telemetry egress isolation. Added TCP/587 only
for Alertmanager/test pods to smtp.ionos.de's node-resolved 213.165.67.113/32 and
213.165.67.97/32; dry-run/diff passed. Separate retry Job completed and IONOS
accepted Message-ID <telemetry-smtp-proof-20260928-egress@coulomb.social>. No
Kubernetes Secret values were read. Inbox receipt and audit-backed alert
acknowledgment remain unproved; browser client/PDP/audit admission remains open.