user-engine/workplans/USER-WP-0030-platform-admin-journeys.md
tegwick 8d525d959e
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 1s
Account journey acceptance / journeys (push) Successful in 6s
Record deployed P06 policy and completed platform acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:10:24 +02:00

6.8 KiB
Raw Blame History

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
USER-WP-0030 workplan Platform administration and operational recovery communication user-engine finished codex communication 2026-09-13 2026-09-14 ab18c962-4ac4-5cf4-a8d9-edb773afbe8c

Implements docs/account-journeys.md under USER-WP-0027. A passing local suite is not evidence that an external provider flow works live.

Expose scoped audit and delivery recovery

id: USER-WP-0030-T01
status: done
priority: high
state_hub_task_id: "f51e3796-b649-586b-a228-c23f94804500"

P01/P03/P05/P08/T08: authorized browser views of safe audit metadata and delivery state, reference filtering, CSRF replay with readback, no raw payload/credential/error dumps.

Make tenant lifecycle and bootstrap recoverable

id: USER-WP-0030-T02
status: done
priority: high
state_hub_task_id: "09c2d30a-8230-5da2-b2d4-7a161259f557"

P02/P04/P07: preserve first-admin setup on retry without duplication, explicit tenant lifecycle confirmation, stale-version recovery and validation; verify cross-role isolation.

Integrate provider policy and credential operations

id: USER-WP-0030-T03
status: done
priority: high
state_hub_task_id: "07510026-caee-54d7-998c-a8d2b2f17773"

P04P06: owner-approved factor credential delivery/renewal and provider recovery/policy control. Depends on KEY-WP-0035/NK-WP-0033; no secret vending through portal or chat.

Validation: 210 database-enabled regression tests passed with no skips, including independent-connection last-admin protection and nested bootstrap rollback. Thirteen isolated Chromium checks passed. Provider OTP and application access integration remain explicitly open; no complete-journey claim is inferred.

Finish platform support investigation and recovery clarity

id: USER-WP-0030-T04
status: done
priority: high
state_hub_task_id: "09a571d9-e1f3-5289-a2c1-fe1c46d4e8ad"

Prioritize P04/P05/P08: exact support-reference search across authorized platform audit and delivery metadata, tenant narrowing before display limits, honest missing-evidence state, delivery readback links and actionable capability availability. Deny non-operators before recovery preview and explain tenant restoration versus provider factor/account-ownership recovery. Add regression and browser acceptance, publish and verify.

Provider gate rechecked: net-kingdom-privacyidea-admin-token remains non-resolvable. The owner playbook in ops-warden/wiki/playbooks/net-kingdom-sso-bind-credentials.md requires a concrete custody/renewal contract and approved attended action; it does not authorize reading live Secrets. P04 factor recovery/P05 credential operations/P06 effective policy remain T03 until that contract exists.

T04 release evidence: docs/evidence/2026-09-13-platform-admin-support.md. Source b8506ef, 216 regression tests (seven optional skips), 19 platform tests, 16 browser checks; CI and rollout verified. T03 stays waiting; P04/P05/P06 completeness is not claimed.

Provider consumer progress: KeyCape source 632b1f1 implements exclusive adminTokenFile renewal without issuer restart, fresh credential reads for both factor lookup and validation, no stale fallback, bounded/sanitized errors, request timeout and redirect refusal. OTP validation now requires successful provider status as well as a positive value. All Go suites pass; owner custody/issuance and live factor/policy acceptance remain T03. KEY-WP-0035-T04 tracks release evidence.

2026-09-13: the user authorized establishing custody and authenticated through the contained OpenBao lane. RPF-WP-0040 / CCR-2026-0023 now provide a dedicated realm-scoped provider credential, separate issuer custody, automatic renewal, namespace-restricted ESO delivery and KeyCape mounted-file activation. Native scope denial, per-user factor lookup and mounted renewal passed; fourteen offline tests pass and exact-commit CI is configured. This supersedes the earlier missing-owner gate for factor reads. T03 remains in progress for P04 audited factor/account recovery, P05 notification operations and remaining expiry drills, and P06 scoped policy/onboarding acceptance. Historical NK-WP-0033 is separate.

2026-09-13 assurance follow-up: KeyCape 113f3a6 is released with confirmed-enrollment state handling, TOTP/HOTP serial/type evidence required for AAL2, and an inert realm-visibility probe before accepting no-factor responses. This closes three policy failure modes found while implementing P06. Native probe and full Go suites passed; installed-provider isolated tests verify enrollment/cancellation, permission withdrawal/recovery and genuine JWT expiry. Evidence is key-cape/docs/enrollment-assurance-release-2026-09-13.md. P04 audited lost-factor recovery and P06 actual optional-client/self-service activation remain T03.

2026-09-13 P04 implementation: KEY-WP-0036 adds exact-factor recovery preview, shared-identity scope, verified/stale-state-guarded disable, durable provider audit and retry reconciliation. Eight unit tests and the actual installed provider's isolated database/audit contract passed. railiance-platform supplies an attended platform-admin wrapper and runbook with actor-denial tests. Native wrapper acceptance and authenticated portal/browser integration remain live KEY-WP-0036-T02/T03 tasks. No real account was modified; P04 remains incomplete.

2026-09-13 P04 completed: KEY-WP-0036 delivers the recent-MFA platform browser journey, signed exact-factor confirmation, provider-derived actor, durable audit, safe retry and support-reference reconciliation. Production service/portal are rolled out and replacement TOTP possession confirmation is active. Evidence: docs/evidence/2026-09-13-p04-recovery.md. Positive recovery uses disposable-provider acceptance; no real user's factor was disabled. T03 remains in progress only for P05 and P06 scope; routine P04 no longer needs an OpenBao owner handoff.

2026-09-13 P05 completed via USER-WP-0032: checked component health, controlled single-record delivery, durable uncertain-outcome reservations, per-event DB serialization, provider evidence and clear assisted recovery. All source/image CI and deployment/non-sending live checks passed. RPF-WP-0040 expiry/recovery acceptance is finished. Evidence: docs/evidence/2026-09-13-p05-service-operations.md. T03 now remains in progress for P06 only; notification/credential P05 is closed.

2026-09-14: P06 completed with CI-published portal and issuer images, provider guard and scoped client migration. Both services are ready; persistent policy readback confirms the two optional-after-enrollment clients. Evidence: docs/evidence/2026-09-13-p06-authentication-policy.md. Residual customer sign-in, user onboarding and workload propagation remain live in USER-WP-0028, KEY-WP-0034 and VERGABE-WP-0019; this does not close those workplans.