diff --git a/intakes/intakes.md b/intakes/intakes.md index 3a44e5e..5193991 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -115,3 +115,46 @@ notes: author: tenant-engine created: "2026-09-21" ``` + +--- + +## TEN-IN-0005 — audit-core sender admitted: wire the production drain (NetworkPolicy + env) + +```yaml +id: TEN-IN-0005 +kind: intake +title: "audit-core sender admitted: wire the production drain (NetworkPolicy + env)" +status: open +origin: cross-repo +origin_ref: AUDIT-WP-0010-T05 (AUDIT-IN-0002 promoted); hub message 9ceec8d2-c16c-4730-9d9b-6c56573e33c7 +priority: medium +owner: tenant-engine +requested_by: audit-core +created: "2026-09-21" +updated: "2026-09-21" +description: >- + audit-core admitted tenant-engine as a sender: a tenant-engine-attributed + event was accepted 202 and its duplicate reconciled 200 from namespace + tenant-engine. The proof used a NetworkPolicy applied live, not from this + repository. For an ongoing outbox drain, tenant-engine's own manifests still + need (1) a NetworkPolicy tenant-engine-audit-core-egress to + audit-core.audit-core.svc:8080, and (2) TENANT_ENGINE_AUDIT_CORE_URL= + http://audit-core.audit-core.svc:8080 plus TENANT_ENGINE_AUDIT_CORE_TOKEN_FILE + projected from the credential operator. The application already reads both + variables (src/tenant_engine/config.py); only deploy/ and the credential + projection are missing. +remaining: + - "deploy/base/tenant-engine.yaml: add the egress NetworkPolicy and the two env vars." + - "Credential projection for the token file: route with `warden route find`, + never by requesting a value; no token appears in the message or here." + - "Roll out and confirm the outbox drains (202s on audit-core), then update + layer.yaml non_tooling_clients audit-core-emission note, which still says + sender registration is requested separately." +notes: +- content: >- + Recorded rather than done in the GH-DEC-2026-017 session: the credential + projection path and a live rollout were outside that session's reach. The + hub message was marked read once this record existed. + author: tenant-engine + created: "2026-09-21" +```