Repository navigation
Configurator MVP: publish immutable application templates per tenant #92
Description
Activity
- addedpriority:p1High impact correctness, security or required product capability; schedule firstHigh impact correctness, security or required product capability; schedule firsteffort:lArchitecture, lifecycle or multiple systems; split before implementationArchitecture, lifecycle or multiple systems; split before implementationarea:configuratorLanding Zone Configurator application, runtime and its infrastructureLanding Zone Configurator application, runtime and its infrastructuremvp:requiredRequired acceptance gate for the agreed Configurator MVP; not a merge approvalRequired acceptance gate for the agreed Configurator MVP; not a merge approval
on Oct 1, 2026 MVP audit 2026-10-04: Updated the description and acceptance checklist against the current implementation. Implemented criteria are checked; remaining requirements are retained. Local tests are not a release or live customer acceptance. This issue stays open until its remaining criteria are met. The first remaining safety fix (#89, backend-free initial plans on existing/partial/legacy state) is now implemented locally: 23/23 isolated PostgreSQL tests and the full check gate (310 unit tests) pass. No customer Apply, API restart, native artifact rebind, commit or merge was performed.
2026-10-05 local implementation evidence: explicit immutable/idempotent retirement (AO visibility/new-order rejection, existing-instance/replay preservation, serialized order/retirement races) and immutable approval-required/direct policy snapshots are implemented. Policy-only changes publish a new version; order overrides and direct SQL mismatches/updates are rejected. Direct policy never bypasses the explicit customer Apply restriction. Gates: 312 unit tests, 28 isolated PostgreSQL cases, all 148 desktop/mobile browser cases; lint/typecheck/build pass. Dynamic DE/EN messages and policy/retirement controls are validated. Migrations 021/022 are not activated in the running customer API; no customer Apply, native package rebinding, commit, release or merge. Original customer publication acceptance under authoritative verified tenancy (#91) remains open, so this issue remains OPEN.
Local progress: tenant-scoped Application groups and template access are implemented in feature-branch commit
75c5dd3a1cb75b491462f5ebcea13d670c87eba4(not pushed).Every workspace automatically receives an Application Owners default group; AO membership follows current roles. Managers can create custom groups and confirm membership changes. Platform Engineers can select publication groups and separately confirm access changes for an immutable version. AO catalogue/order access, prepared jobs, SQL grant claims and runner tickets enforce current group access; revocation during secret access prevents credential release. No technical credentials or group administration are exposed to AO.
Validation: full check 388 unit tests passed (45 gated skips); 29 real PostgreSQL integration tests passed, including direct SQL/ticket and secret-access revocation; 4 desktop/mobile Application catalogue flows passed; editor diagnostics clean; staged secret scan clean.
Migration 035 is qualified only in a disposable synthetic PostgreSQL database. Customer API/database remain on migrations 001–034, with Application execution disabled. No customer state/cloud operation, push, merge or release occurred. Issue remains OPEN: applied-platform integration, real saved Plan/explicit Apply, drift/upgrades and original production acceptance are still pending.
Final required publication acceptance completed: actual immutable Public template version1, approved current contract, public-eu01, Application Owners and approval-required policy, retained after reload. Group CRUD and confirmed email labels are live in User management; real add/remove/delete checked without changing published ACLs. Commits 53b806b and 798661a; 403 unit,30 real identity/PostgreSQL,32 desktop/mobile flows passed. All checklist items in this issue are complete; production rollout and cloud execution remain separate #91/#93/#95 work. No push/release/cloud execution.
Lokale Folgekorrektur 8c630b9 (kein Push) fuer den gemeldeten leeren Veroeffentlichungseinstieg: Auch /applications stellt die letzte berechtigte serverseitige Konfiguration direkt wieder her, ohne vorher Deployments zu besuchen. Ohne offenen Entwurf erscheint zuerst der reale Katalog; Veroeffentlichung bietet eine ausdrueckliche Konfigurationsauswahl. Plattformziele sind erst nach Template-Auswahl bedienbar und bleiben nach Region und Public/Corporate gefiltert. Reales Login/Reload bestaetigt: bestehende Version 1 sofort sichtbar, vorhandener Public-Entwurf direkt wiederhergestellt und passendes eu01-Ziel waehlbar. Kein erneutes Publizieren, keine Aenderung bestehender ACLs oder Versionen, keine Cloud-Jobs. Lint/Typen/Build, 403 Unit-Tests und 36 fokussierte Desktop/Mobil-Browserfaelle PASS; beide lokalen Commits secret-geprueft. Urspruengliche Publikationsabnahme bleibt gueltig; andere MVP-Issues bleiben offen.
- added 4 commits that reference this issue
on Oct 6, 2026
Current Status (2026-10-06)
Tenant-bound draft/publish persistence, immutable versions, strict parameter policies and fork-free Application Owner catalogue/ordering are implemented locally. Explicit retirement and durable version-bound deployment policy are now implemented and locally validated. Customer publication acceptance under authoritative verified tenancy is complete in the intended local runtime; ordering is not cloud execution.
Existing instances retain their selected immutable version. Publishing/retiring a template does not upgrade or destroy existing instances. Upgrades are separate explicit operations (#93).
Historical Evidence and Next Step (before current activation)
Current implementation:
landing-zone-configurator/app/apps/api/src/applications/and its persistence/tests, plus the Application Owner and project-template UI. Documentation:landing-zone-configurator/docs/project-template-drafts.md,template-parameters-and-bindings.md,plan-execution.md.Final local gates: 312 unit tests, 28 isolated PostgreSQL identity/catalogue cases and all 148 desktop/mobile browser cases passed. Retirement is immutable/idempotent, hides offers from new AO orders and preserves existing instances/replays. Policy-only publication changes create a new version; clients cannot override order policy. Direct policy still reports executionEnabled:false, cloudPlanExecuted:false and requiresExplicitApplyApproval:true.
Evidence is recorded in the readiness/runtime reports. Migrations 021/022 are not activated in the running customer API; the bilingual UI uses capability flags for older APIs. Current additions are uncommitted/unreleased. Next required acceptance: authoritative tenancy (#91), activation and customer publication verification. No customer Apply, package rebinding, release or merge occurred.
Final Publication Acceptance (2026-10-06)
The existing Public template was actually published as immutable version 1 from the saved configuration, with the approved current server-derived platform contract, eu01/public-eu01 target, default Application Owners group and approval-required policy. It persists in the real catalogue after reload. No duplicate version or cloud resources were created.
Group CRUD is now in User management, not an extra Applications tab. Adding/removing members and deleting a temporary group passed through the actual protected UI and survived reload. Default membership and workspace users remain intact; assigned template ACLs block group deletion. Role updates preserve custom memberships. Both actual group members display confirmed STACKIT email addresses rather than UUIDs; foreign sessions/tenants and non-managers cannot obtain the email list.
All required publication criteria listed in this issue are complete. Production OIDC/two-organization security rollout stays in #91, actual Application Plan/Apply/quotas/upgrades/recovery in #93 and release gates in #95. Closing #92 does not claim the entire MVP or cloud execution is complete.
Local-only commits: a8447b6 (#91), 53b806b (#92), 798661a (#93). Final validation: 403 unit tests, 30 real isolated identity/PostgreSQL cases, 49 platform broker cases and all 32 desktop/mobile management/publication/proof flows passed. Schema 039 activated after fresh private backup, full restore, repeated migration and unchanged operational-table verification. No push, merge, release or new Application cloud execution.
Dependencies
Verified tenancy (#91) is required before production customer publication. Consumed by instances (#93); chat (#94) must use identical policies. Symbolic network binding remains blocked until #96 qualifies the actual egress path.
Historical Milestones
Draft authoring:
0e62c5e. Parameter contract/order preview:244e936(2026-10-01). Their earlier statements that publication/order were still absent and their test counts describe those historical revisions, not the current implementation. Native blocked capabilities remain blocked.