Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
2.9 KiB
Email acknowledgment implementation — 2026-09-28
Existing task RTEL-WP-0002-T04 holds this work; no task/workplan added. User decision f149e316-4ef4-4855-8453-bc9cdc938aad approves email to bernd.worsch@gmail.com, explicit receipt confirmation, Railiance admin role, audit-core evidence and controlled drills. Subsequent direction selected From platform@coulomb.social and confirmed the mailbox needs setup.
Implemented WSGI acknowledgment, immutable first receipt, atomic SQLite audit outbox, bounded audit transport, OIDC code/PKCE sessions, native Flex Auth binding/digest/lifetime checks, Waitress runtime and background audit draining. GET is inert; POST requires verified human/platform/admin identity, a fresh PDP allow, Origin and CSRF. Email links identify occurrences, not bearer credentials.
Validation: 33 core tests with actual audit-core 3e42ca8 ingestion, including accepted/lost-reply/reopened-store/duplicate; seven runtime tests with signed RSA issuer fixtures, complete browser flow and the actual Flex Auth evaluator. Synthetic identities/credentials do not prove production login or custody. Native Alertmanager 0.28.1 template render passed. Hash-pinned runtime container built; network-isolated read-only container returned HTTP 200 health and exited cleanly on SIGTERM. Package candidates reside in rapp-telemetry/acknowledgment. Policy and browser client registration candidates reside in integration/.
Native changes: identity-provisioner verified tegwick's requested email and added only railiance-admins, preserving other memberships. KeyCape 1164f65 maps that explicit group to railiance-admin without granting platform-operator. Full Go suite passed. Published immutable image: sha256:6f79a2af1c695d39480173fad013facd84d21e7732860366af519302a2c496b8. NetKingdom manifest server dry-run passed; diff changed only the image (plus metadata). Deployment rolled out successfully. Signed role remains unverified until a real login. No Kubernetes Secret values were read or printed.
Remaining gates: mailbox setup; scoped SMTP/webhook/audit custody and receiver registration; safe OIDC client registration and enforced policy caller admission; application rollout; native login and actual failure/absence emails, Bernd's acknowledgments and independent audit readback; outside-node watchdog and recurring backups. Existing owner client helpers read complete Kubernetes Secrets and cannot be used under the current environment orientation's rule. No live email or acknowledgment is claimed. Workplan stays blocked, T04 wait.
Subsequently the founder created platform@coulomb.social and requested an OpenBao entry, with the password to be added by the founder as a new version. Platform helper scripts/telemetry_smtp_entry.py is silent, CAS=0, never reads credential values, and preserves any existing version. Four unit tests pass. Attended founder OIDC/MFA execution is requested; no native KV creation is yet claimed.