Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
5.9 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | state_hub_workstream_id | ||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| VERGABE-WP-0019 | workplan | Admit the first invited company pilot with protected access and recoverable data | communication | vergabe-teilnahme | active | the-custodian | vergabe-teilnahme | 2026-09-11 | 2026-09-11 |
|
85b5f304-d497-5570-bebf-3a3669ef6a7d |
Invited company pilot
Confirm the bounded customer milestone
id: VERGABE-WP-0019-T01
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "5785d35a-6501-57a3-aedf-3885db269e83"
User decision on 2026-09-11: start with an invited pilot, one company and several users, manually onboarded. Pricing is a later improvement and is not an entry gate. Use the existing single-company product: each admitted company has an isolated deployment, database and data volumes. All active company members can collaborate on the company's tenders; the existing v1 domain approval roles remain descriptive. Django staff/superuser administration remains restricted. External partners remain data objects. No public registration or shared-app multitenancy is introduced.
Product readiness proceeds alongside the governed factory runtime. It does not wait for the fourteen-day factory value study. VERGABE-WP-0018-T03 retains the separate claim that the factory can produce and deliver the customer release; HFACT-WP-0001-T05 still needs a natural governed worker trace.
Require invited access across the UI and uploaded documents
id: VERGABE-WP-0019-T02
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "11e67327-aae4-5c83-99eb-86a8c82dd0be"
Use Django's default-deny login middleware with explicit health/login exemptions, German login and password-change forms, CSRF-protected POST logout, and full-page reauthentication for expired HTMX sessions. Protect uploaded files in production and development, serve private attachments only within MEDIA_ROOT, and keep operational issue state outside that downloadable root. Do not cache company responses. Inactive users lose existing session access; ordinary members do not gain Django administration privileges.
The 12 access regressions initially produced 9 failures, including actual anonymous tender read/create. After the fix all 94 application tests pass locally and in the existing container target; Vite assets build, 139 static files collect, and migration drift is absent. New/changed access modules pass Ruff. Source acceptance is not native customer admission.
Publish and prove the isolated deployment and recovery contract
id: VERGABE-WP-0019-T03
status: progress
priority: high
assignee: the-custodian
depends_on: [VERGABE-WP-0019-T02, RAPPS-WP-0014-T02, RAPPS-WP-0014-T03]
state_hub_task_id: "9065d5cb-2c65-561e-a237-e39da4f3b0fd"
RAPPS-WP-0014 owns exact image/chart/host/namespace/database/Secret binding,
persistent media plus distinct issue-facade state, isolated restore rehearsal,
and rollback. The customer app owns live CI and immutable release evidence.
The user now selects a fresh demo-company demo tenant with demo-user1, etc.
Use tenant:trial:demo-company under NetKingdom ADR-0013 and two ordinary demo
accounts initially. Native tenant creation and memberships use the existing
User Engine operator portal; this does not implement Django SSO. Hostname
preference is pending (demo-vergabe.coulomb.social proposed). The concrete
prepared binding lives at railiance-apps/docs/vergabe-demo-company-binding.md.
No password or personal user list belongs in public work records.
The historical vergabe_db is not disposable and must not be overwritten.
The user subsequently accepts a 60m application CPU request for one tenant with very few users as a prototype of HelixForge app delivery and Railiance/NetKingdom onboarding. RAPPS-WP-0014 owns the explicit pilot override; this is an accepted low-allocation experiment, not measured production sizing. CUST-WP-0071 is registered for later metrics-based sizing and a final weekly allocation-review setup. That follow-up does not block this deployment. CPU limits, memory, protected access and company/data isolation remain governed by the pilot packet.
On 2026-09-11 the checked Railiance cluster contains neither the historical vergabe-teilnahme namespace nor any Deployment whose name/image contains vergabe/teilnahme. Treat the old runbook as historical intent, not a live return. Native placement and existing data inventory remain required before cutover.
Accept onboarding, collaboration, recovery and support with pilot users
id: VERGABE-WP-0019-T04
status: wait
priority: high
assignee: the-custodian
depends_on: [VERGABE-WP-0019-T03]
blocking_reason: "Await native demo-company tenant, admitted deployment and demonstrated restore; hostname and operator login remain pending."
state_hub_task_id: "db807f96-f5b8-528d-bc33-75a33fbbf1e4"
Product acceptance: Bernd Worsch and the named company contact. Verify two
separate ordinary-user accounts (demo-user1 and demo-user2 initially) can sign
in, change passwords, create a tender
and lot, collaborate on tasks, upload/download a document, record a v1 domain
approval and submission, and report feedback. Verify anonymous access and a
revoked user fail, health remains available, and pod replacement preserves all
three data stores. Restore a backup into an isolated destination and repeat the
workflow without touching the live database. Record operator/support contact,
incident route, backup cadence/retention and demonstrated recovery time. Use
manual account creation/reset/deactivation through the admitted operator path;
never seed development accounts or put credentials in logs/workplans/chat.
A successful invited pilot does not claim shared multitenancy, paid subscriptions, HA or autonomous production release. Pricing is outside this milestone and will need a later explicit product decision.