d2a7fe3151
fix: keep migration objects on stable role
Build and Publish Container Image / build-and-push (push) Successful in 38s
2026-08-21 00:27:54 +02:00
749461b97b
Implement PostgreSQL production store path
...
Build and Publish Container Image / build-and-push (push) Successful in 41s
Add the PostgreSQL backend, migration and stopped-write transfer tools, lease-aware deployment manifests, tenancy declarations, and shared conformance coverage. Persist grouping mutations in durable stores and separate process liveness from database readiness.
2026-08-19 14:43:08 +02:00
2063470ac8
Send a projected flex-auth caller token on every check
...
Build and Publish Container Image / build-and-push (push) Successful in 1m7s
TENANT_ENGINE_FLEX_AUTH_TOKEN_FILE is read per request so hourly
projection rotation needs no restart. Missing or unreadable file fails
closed as a local deny and never calls flex-auth. Needed before
flex-auth-tenant-engine can enforce (FLEX-WP-0015-T02).
2026-08-19 14:31:39 +02:00
0809af063c
docs: point deploy/ at rapp-tenant-engine as apply home
2026-08-18 13:03:16 +02:00
custodian-sync
aee0971cca
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-18:
- update .custodian-brief.md for tenant-engine
2026-08-18 07:29:09 +02:00
custodian-sync
0a65a4a25c
chore(consistency): renormalize lifecycle state [auto]
...
Updated by fix-consistency on 2026-08-18:
- workplan status: ready → active
2026-08-18 07:29:03 +02:00
b22d4a7294
TEN-WP-0010-T01: mark proposed-and-recorded as done, ratification outstanding
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:53:52 +02:00
custodian-sync
3dd54127f6
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-17:
- update .custodian-brief.md for tenant-engine
2026-08-17 22:53:33 +02:00
bdf9f5f643
Finish TEN-WP-0010: mutable grouping, contract corrected, handoffs sent
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:53:10 +02:00
custodian-sync
2e1c4e15e6
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-17:
- update .custodian-brief.md for tenant-engine
2026-08-17 22:09:41 +02:00
b998ca2332
Finish TEN-WP-0010-T03/T04: audited grouping mutation
...
Build and Publish Container Image / build-and-push (push) Successful in 1m5s
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:09:24 +02:00
custodian-sync
2e11b6a155
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-17:
- update .custodian-brief.md for tenant-engine
2026-08-17 22:06:27 +02:00
1b2526910b
TEN-WP-0010-T02 done, T01 proposed: no consumer parses the grouping segment
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:05:59 +02:00
custodian-sync
fd75bd74cf
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-17:
- update .custodian-brief.md for tenant-engine
2026-08-17 21:41:24 +02:00
20979040b2
Plan mutable grouping (TEN-WP-0010)
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 21:41:05 +02:00
5a9e78f657
TEN-WP-0009-T01: record rapp-postgres acceptance, add postgres-client label
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 10:59:32 +02:00
05d12fe39f
TEN-WP-0009-T01: target platform-pg via rapp-postgres consumer declaration
...
Corrects the credential assumption: shared-cluster access is a broker lease,
not a CNPG-minted secretKeyRef.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 10:44:59 +02:00
custodian-sync
358dc506fa
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 18:59:49 +02:00
cf7ca1a692
TEN-WP-0009: make database placement portable rather than settled
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 18:59:30 +02:00
custodian-sync
121968d65b
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 18:26:00 +02:00
781359e7d4
Plan PostgreSQL production store (TEN-WP-0009)
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 18:25:35 +02:00
custodian-sync
bd61df3ff8
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 18:17:57 +02:00
c05cc704b2
Plan staged-promotion onboarding (TEN-WP-0008)
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 18:17:39 +02:00
a69adb6498
Add deployment pin-drift check (make verify-pin)
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 10:46:26 +02:00
custodian-sync
28539bfce2
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 10:35:00 +02:00
76196aa39f
Finish TEN-WP-0007: guardrail surface live in production
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 10:34:44 +02:00
custodian-sync
b95b317293
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 10:02:53 +02:00
custodian-sync
1020758e83
chore(consistency): renormalize lifecycle state [auto]
...
Updated by fix-consistency on 2026-08-16:
- workplan status: ready → active
2026-08-16 10:02:49 +02:00
611431c2b7
TEN-WP-0007: pin guardrail image, record CI digest and flex-auth nine-action pin
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 10:02:34 +02:00
custodian-sync
4d29b8ce15
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 02:52:34 +02:00
9f1e58a797
Plan guardrail production rollout (TEN-WP-0007)
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:52:05 +02:00
e5c106186d
chore(consistency): refresh WORK-RECORDS.md for TEN-WP-0006 close
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:21:10 +02:00
custodian-sync
628e31dba8
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 02:20:07 +02:00
955fe339fd
Finish TEN-WP-0006: guardrail and quota policy
...
Build and Publish Container Image / build-and-push (push) Successful in 43s
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:19:48 +02:00
d1d9c9a735
TEN-WP-0006-T05: cross-tenant denial and write-path outage conformance
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:18:52 +02:00
b6d016869f
Finish TEN-WP-0006-T04: expose guardrail read and write APIs
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:18:01 +02:00
f631224ab5
Finish TEN-WP-0006-T03: persist guardrails in both stores
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:14:31 +02:00
33ceb882ee
Finish TEN-WP-0006-T02: implement guardrail domain model
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:10:38 +02:00
0d1435c2d2
Finish TEN-WP-0006-T01: specify guardrail model and boundary
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 02:07:42 +02:00
custodian-sync
9f37b3cf6e
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-16:
- update .custodian-brief.md for tenant-engine
2026-08-16 01:50:26 +02:00
b8af02d74d
Plan guardrail and quota policy (TEN-WP-0006)
...
Closes the guardrail/quota concern reserved since repo creation. Notably
ADR-0013 specifies trial tenants default to a zero spend budget; no such
default exists today.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-16 01:50:08 +02:00
77bc207484
chore(consistency): refresh WORK-RECORDS.md for TEN-WP-0005 close
...
Index still listed T01-T04 as todo after the workplan finished. Regenerated
by fix-consistency; committing the file so origin matches the hub.
2026-08-14 01:44:49 +02:00
custodian-sync
6cea67d558
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-14:
- update .custodian-brief.md for tenant-engine
2026-08-14 01:43:56 +02:00
9ed391aec7
Finish TEN-WP-0005-T05: ship lifecycle image and verify production
...
Pin tenant-engine to the CI-built digest from 7e68cc8 , record rollback
digests, and close T05 after live create/update/retire/replay/reactivate
evidence against a disposable production tenant. Hands the 0.1.0 contract
to USER-WP-0021.
2026-08-14 01:42:41 +02:00
7e68cc835e
Start TEN-WP-0005-T05: recover deploy manifests and add CI image build
...
Build and Publish Container Image / build-and-push (push) Successful in 20s
Production still serves the TEN-WP-0004 image, which has no lifecycle
routes. Recover the live railiance01 objects into deploy/ so rollback
does not depend on a cluster annotation, and add the fleet CI image
workflow so the lifecycle image is built from a forge revision.
2026-08-14 01:37:44 +02:00
custodian-sync
baf41a7765
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-10:
- update .custodian-brief.md for tenant-engine
2026-08-10 20:00:59 +02:00
d6fd73bd42
Implement tenant update and reversible retirement API (TEN-WP-0005 T01-T04)
...
Add an explicit tenant lifecycle (active/retired), allow-listed mutable
metadata, record versioning, and lifecycle timestamps to the tenant authority.
- domain: TenantLifecycle, with_metadata/retire/reactivate, immutability and
transition invariants. Identifier stays immutable -- it is the IAM Profile
`tenant` claim key-cape mints into tokens.
- store: mutate_tenant() commits idempotency replay, version CAS, mutation,
and audit event together; durable receipts survive restart. Retired tenants
refuse new grants and plan changes but keep their history.
- sqlite: forward-only idempotent migration; existing rows default to active
at version 1. Reads now take the write lock -- the concurrent-writer test
caught unguarded reads on the shared connection observing mid-transaction
state as a spurious tenant_not_found.
- api: GET/PATCH /tenants/{id}, POST retire|reactivate. Idempotency-Key and
If-Match required, distinct flex-auth actions per operation, stable error
schema, redacted 503s.
- docs/tenant-lifecycle-api.md: consumer contract for user-engine.
Implemented against SQLite, not PostgreSQL as the workplan assumed --
TEN-WP-0004 shipped SQLite on a PVC as the production store.
124 tests pass (was 66); no breaking change to existing endpoints.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 20:00:43 +02:00
7dcccafc03
Plan tenant update and retirement APIs
2026-08-10 18:54:28 +02:00
custodian-sync
ca05cdb172
chore(consistency): sync task status from DB [auto]
...
Updated by fix-consistency on 2026-08-10:
- update .custodian-brief.md for tenant-engine
2026-08-10 18:52:45 +02:00
a48d3711c9
Sync tenant runtime workplan state
2026-08-09 01:49:11 +02:00