Commit graph

68 commits

Author SHA1 Message Date
d2a7fe3151 fix: keep migration objects on stable role
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 38s
2026-08-21 00:27:54 +02:00
749461b97b Implement PostgreSQL production store path
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 41s
Add the PostgreSQL backend, migration and stopped-write transfer tools, lease-aware deployment manifests, tenancy declarations, and shared conformance coverage. Persist grouping mutations in durable stores and separate process liveness from database readiness.
2026-08-19 14:43:08 +02:00
2063470ac8 Send a projected flex-auth caller token on every check
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 1m7s
TENANT_ENGINE_FLEX_AUTH_TOKEN_FILE is read per request so hourly
projection rotation needs no restart. Missing or unreadable file fails
closed as a local deny and never calls flex-auth. Needed before
flex-auth-tenant-engine can enforce (FLEX-WP-0015-T02).
2026-08-19 14:31:39 +02:00
0809af063c docs: point deploy/ at rapp-tenant-engine as apply home 2026-08-18 13:03:16 +02:00
custodian-sync
aee0971cca chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-18:
  - update .custodian-brief.md for tenant-engine
2026-08-18 07:29:09 +02:00
custodian-sync
0a65a4a25c chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-08-18:
  - workplan status: ready → active
2026-08-18 07:29:03 +02:00
b22d4a7294 TEN-WP-0010-T01: mark proposed-and-recorded as done, ratification outstanding
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:53:52 +02:00
custodian-sync
3dd54127f6 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-17:
  - update .custodian-brief.md for tenant-engine
2026-08-17 22:53:33 +02:00
bdf9f5f643 Finish TEN-WP-0010: mutable grouping, contract corrected, handoffs sent
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:53:10 +02:00
custodian-sync
2e1c4e15e6 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-17:
  - update .custodian-brief.md for tenant-engine
2026-08-17 22:09:41 +02:00
b998ca2332 Finish TEN-WP-0010-T03/T04: audited grouping mutation
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 1m5s
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:09:24 +02:00
custodian-sync
2e11b6a155 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-17:
  - update .custodian-brief.md for tenant-engine
2026-08-17 22:06:27 +02:00
1b2526910b TEN-WP-0010-T02 done, T01 proposed: no consumer parses the grouping segment
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:05:59 +02:00
custodian-sync
fd75bd74cf chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-17:
  - update .custodian-brief.md for tenant-engine
2026-08-17 21:41:24 +02:00
20979040b2 Plan mutable grouping (TEN-WP-0010)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 21:41:05 +02:00
5a9e78f657 TEN-WP-0009-T01: record rapp-postgres acceptance, add postgres-client label
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 10:59:32 +02:00
05d12fe39f TEN-WP-0009-T01: target platform-pg via rapp-postgres consumer declaration
Corrects the credential assumption: shared-cluster access is a broker lease,
not a CNPG-minted secretKeyRef.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 10:44:59 +02:00
custodian-sync
358dc506fa chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 18:59:49 +02:00
cf7ca1a692 TEN-WP-0009: make database placement portable rather than settled
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 18:59:30 +02:00
custodian-sync
121968d65b chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 18:26:00 +02:00
781359e7d4 Plan PostgreSQL production store (TEN-WP-0009)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 18:25:35 +02:00
custodian-sync
bd61df3ff8 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 18:17:57 +02:00
c05cc704b2 Plan staged-promotion onboarding (TEN-WP-0008)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 18:17:39 +02:00
a69adb6498 Add deployment pin-drift check (make verify-pin)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 10:46:26 +02:00
custodian-sync
28539bfce2 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 10:35:00 +02:00
76196aa39f Finish TEN-WP-0007: guardrail surface live in production
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 10:34:44 +02:00
custodian-sync
b95b317293 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 10:02:53 +02:00
custodian-sync
1020758e83 chore(consistency): renormalize lifecycle state [auto]
Updated by fix-consistency on 2026-08-16:
  - workplan status: ready → active
2026-08-16 10:02:49 +02:00
611431c2b7 TEN-WP-0007: pin guardrail image, record CI digest and flex-auth nine-action pin
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 10:02:34 +02:00
custodian-sync
4d29b8ce15 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 02:52:34 +02:00
9f1e58a797 Plan guardrail production rollout (TEN-WP-0007)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:52:05 +02:00
e5c106186d chore(consistency): refresh WORK-RECORDS.md for TEN-WP-0006 close
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:21:10 +02:00
custodian-sync
628e31dba8 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 02:20:07 +02:00
955fe339fd Finish TEN-WP-0006: guardrail and quota policy
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 43s
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:19:48 +02:00
d1d9c9a735 TEN-WP-0006-T05: cross-tenant denial and write-path outage conformance
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:18:52 +02:00
b6d016869f Finish TEN-WP-0006-T04: expose guardrail read and write APIs
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:18:01 +02:00
f631224ab5 Finish TEN-WP-0006-T03: persist guardrails in both stores
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:14:31 +02:00
33ceb882ee Finish TEN-WP-0006-T02: implement guardrail domain model
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:10:38 +02:00
0d1435c2d2 Finish TEN-WP-0006-T01: specify guardrail model and boundary
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:07:42 +02:00
custodian-sync
9f37b3cf6e chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-16:
  - update .custodian-brief.md for tenant-engine
2026-08-16 01:50:26 +02:00
b8af02d74d Plan guardrail and quota policy (TEN-WP-0006)
Closes the guardrail/quota concern reserved since repo creation. Notably
ADR-0013 specifies trial tenants default to a zero spend budget; no such
default exists today.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 01:50:08 +02:00
77bc207484 chore(consistency): refresh WORK-RECORDS.md for TEN-WP-0005 close
Index still listed T01-T04 as todo after the workplan finished. Regenerated
by fix-consistency; committing the file so origin matches the hub.
2026-08-14 01:44:49 +02:00
custodian-sync
6cea67d558 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-14:
  - update .custodian-brief.md for tenant-engine
2026-08-14 01:43:56 +02:00
9ed391aec7 Finish TEN-WP-0005-T05: ship lifecycle image and verify production
Pin tenant-engine to the CI-built digest from 7e68cc8, record rollback
digests, and close T05 after live create/update/retire/replay/reactivate
evidence against a disposable production tenant. Hands the 0.1.0 contract
to USER-WP-0021.
2026-08-14 01:42:41 +02:00
7e68cc835e Start TEN-WP-0005-T05: recover deploy manifests and add CI image build
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 20s
Production still serves the TEN-WP-0004 image, which has no lifecycle
routes. Recover the live railiance01 objects into deploy/ so rollback
does not depend on a cluster annotation, and add the fleet CI image
workflow so the lifecycle image is built from a forge revision.
2026-08-14 01:37:44 +02:00
custodian-sync
baf41a7765 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-10:
  - update .custodian-brief.md for tenant-engine
2026-08-10 20:00:59 +02:00
d6fd73bd42 Implement tenant update and reversible retirement API (TEN-WP-0005 T01-T04)
Add an explicit tenant lifecycle (active/retired), allow-listed mutable
metadata, record versioning, and lifecycle timestamps to the tenant authority.

- domain: TenantLifecycle, with_metadata/retire/reactivate, immutability and
  transition invariants. Identifier stays immutable -- it is the IAM Profile
  `tenant` claim key-cape mints into tokens.
- store: mutate_tenant() commits idempotency replay, version CAS, mutation,
  and audit event together; durable receipts survive restart. Retired tenants
  refuse new grants and plan changes but keep their history.
- sqlite: forward-only idempotent migration; existing rows default to active
  at version 1. Reads now take the write lock -- the concurrent-writer test
  caught unguarded reads on the shared connection observing mid-transaction
  state as a spurious tenant_not_found.
- api: GET/PATCH /tenants/{id}, POST retire|reactivate. Idempotency-Key and
  If-Match required, distinct flex-auth actions per operation, stable error
  schema, redacted 503s.
- docs/tenant-lifecycle-api.md: consumer contract for user-engine.

Implemented against SQLite, not PostgreSQL as the workplan assumed --
TEN-WP-0004 shipped SQLite on a PVC as the production store.

124 tests pass (was 66); no breaking change to existing endpoints.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 20:00:43 +02:00
7dcccafc03 Plan tenant update and retirement APIs 2026-08-10 18:54:28 +02:00
custodian-sync
ca05cdb172 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-10:
  - update .custodian-brief.md for tenant-engine
2026-08-10 18:52:45 +02:00
a48d3711c9 Sync tenant runtime workplan state 2026-08-09 01:49:11 +02:00