Skip to content

Configurator MVP: publish immutable application templates per tenant #92

Description

@lweberru

Current Status (2026-10-06)

Tenant-bound draft/publish persistence, immutable versions, strict parameter policies and fork-free Application Owner catalogue/ordering are implemented locally. Explicit retirement and durable version-bound deployment policy are now implemented and locally validated. Customer publication acceptance under authoritative verified tenancy is complete in the intended local runtime; ordering is not cloud execution.

  • Persist tenant-bound drafts and publication with server-side Platform Engineer permission checks.
  • Add explicit retirement and server-side visibility/order rejection for retired offers, preserving historic versions and existing instances.
  • Publish immutable versions bound to reviewed compiler/Accelerator metadata and a compatible approved platform-contract version.
  • Enforce allowed input schema/options/defaults. Fixed organisation, target and role policies cannot be overridden by a client or chat.
  • Expose only permitted published templates to Application Owners without a GitHub fork.
  • Use the honest application-project-with-base-services contract; do not advertise VM/cluster creation that is not implemented.
  • Persist direct versus approval-required deployment policy and enforce it server-side; the current approval-required/customer-Apply restriction must remain enforced.
  • Test unpublished visibility, tenant isolation, immutable versions and attempted parameter/policy overrides.
  • Add retirement/direct-policy regressions, including concurrent retirement/order, immutable policy snapshots, rejected overrides and explicit Apply restrictions.
  • Complete customer publication acceptance under authoritative verified tenancy (Configurator MVP: verify organisation tenants and STACKIT user bindings #91).

Existing instances retain their selected immutable version. Publishing/retiring a template does not upgrade or destroy existing instances. Upgrades are separate explicit operations (#93).

Historical Evidence and Next Step (before current activation)

Current implementation: landing-zone-configurator/app/apps/api/src/applications/ and its persistence/tests, plus the Application Owner and project-template UI. Documentation: landing-zone-configurator/docs/project-template-drafts.md, template-parameters-and-bindings.md, plan-execution.md.

Final local gates: 312 unit tests, 28 isolated PostgreSQL identity/catalogue cases and all 148 desktop/mobile browser cases passed. Retirement is immutable/idempotent, hides offers from new AO orders and preserves existing instances/replays. Policy-only publication changes create a new version; clients cannot override order policy. Direct policy still reports executionEnabled:false, cloudPlanExecuted:false and requiresExplicitApplyApproval:true.

Evidence is recorded in the readiness/runtime reports. Migrations 021/022 are not activated in the running customer API; the bilingual UI uses capability flags for older APIs. Current additions are uncommitted/unreleased. Next required acceptance: authoritative tenancy (#91), activation and customer publication verification. No customer Apply, package rebinding, release or merge occurred.

Final Publication Acceptance (2026-10-06)

The existing Public template was actually published as immutable version 1 from the saved configuration, with the approved current server-derived platform contract, eu01/public-eu01 target, default Application Owners group and approval-required policy. It persists in the real catalogue after reload. No duplicate version or cloud resources were created.

Group CRUD is now in User management, not an extra Applications tab. Adding/removing members and deleting a temporary group passed through the actual protected UI and survived reload. Default membership and workspace users remain intact; assigned template ACLs block group deletion. Role updates preserve custom memberships. Both actual group members display confirmed STACKIT email addresses rather than UUIDs; foreign sessions/tenants and non-managers cannot obtain the email list.

All required publication criteria listed in this issue are complete. Production OIDC/two-organization security rollout stays in #91, actual Application Plan/Apply/quotas/upgrades/recovery in #93 and release gates in #95. Closing #92 does not claim the entire MVP or cloud execution is complete.

Local-only commits: a8447b6 (#91), 53b806b (#92), 798661a (#93). Final validation: 403 unit tests, 30 real isolated identity/PostgreSQL cases, 49 platform broker cases and all 32 desktop/mobile management/publication/proof flows passed. Schema 039 activated after fresh private backup, full restore, repeated migration and unchanged operational-table verification. No push, merge, release or new Application cloud execution.

Dependencies

Verified tenancy (#91) is required before production customer publication. Consumed by instances (#93); chat (#94) must use identical policies. Symbolic network binding remains blocked until #96 qualifies the actual egress path.

Historical Milestones

Draft authoring: 0e62c5e. Parameter contract/order preview: 244e936 (2026-10-01). Their earlier statements that publication/order were still absent and their test counts describe those historical revisions, not the current implementation. Native blocked capabilities remain blocked.

Activity

  1. added
    priority:p1High impact correctness, security or required product capability; schedule first
    effort:lArchitecture, lifecycle or multiple systems; split before implementation
    area:configuratorLanding Zone Configurator application, runtime and its infrastructure
    mvp:requiredRequired acceptance gate for the agreed Configurator MVP; not a merge approval
    on Oct 1, 2026
  2. lweberru commented on Oct 4, 2026

    @lweberru
    CollaboratorAuthor

    MVP audit 2026-10-04: Updated the description and acceptance checklist against the current implementation. Implemented criteria are checked; remaining requirements are retained. Local tests are not a release or live customer acceptance. This issue stays open until its remaining criteria are met. The first remaining safety fix (#89, backend-free initial plans on existing/partial/legacy state) is now implemented locally: 23/23 isolated PostgreSQL tests and the full check gate (310 unit tests) pass. No customer Apply, API restart, native artifact rebind, commit or merge was performed.

  3. lweberru commented on Oct 5, 2026

    @lweberru
    CollaboratorAuthor

    2026-10-05 local implementation evidence: explicit immutable/idempotent retirement (AO visibility/new-order rejection, existing-instance/replay preservation, serialized order/retirement races) and immutable approval-required/direct policy snapshots are implemented. Policy-only changes publish a new version; order overrides and direct SQL mismatches/updates are rejected. Direct policy never bypasses the explicit customer Apply restriction. Gates: 312 unit tests, 28 isolated PostgreSQL cases, all 148 desktop/mobile browser cases; lint/typecheck/build pass. Dynamic DE/EN messages and policy/retirement controls are validated. Migrations 021/022 are not activated in the running customer API; no customer Apply, native package rebinding, commit, release or merge. Original customer publication acceptance under authoritative verified tenancy (#91) remains open, so this issue remains OPEN.

  4. lweberru commented on Oct 6, 2026

    @lweberru
    CollaboratorAuthor

    Local progress: tenant-scoped Application groups and template access are implemented in feature-branch commit 75c5dd3a1cb75b491462f5ebcea13d670c87eba4 (not pushed).

    Every workspace automatically receives an Application Owners default group; AO membership follows current roles. Managers can create custom groups and confirm membership changes. Platform Engineers can select publication groups and separately confirm access changes for an immutable version. AO catalogue/order access, prepared jobs, SQL grant claims and runner tickets enforce current group access; revocation during secret access prevents credential release. No technical credentials or group administration are exposed to AO.

    Validation: full check 388 unit tests passed (45 gated skips); 29 real PostgreSQL integration tests passed, including direct SQL/ticket and secret-access revocation; 4 desktop/mobile Application catalogue flows passed; editor diagnostics clean; staged secret scan clean.

    Migration 035 is qualified only in a disposable synthetic PostgreSQL database. Customer API/database remain on migrations 001–034, with Application execution disabled. No customer state/cloud operation, push, merge or release occurred. Issue remains OPEN: applied-platform integration, real saved Plan/explicit Apply, drift/upgrades and original production acceptance are still pending.

  5. lweberru commented on Oct 6, 2026

    @lweberru
    CollaboratorAuthor

    Final required publication acceptance completed: actual immutable Public template version1, approved current contract, public-eu01, Application Owners and approval-required policy, retained after reload. Group CRUD and confirmed email labels are live in User management; real add/remove/delete checked without changing published ACLs. Commits 53b806b and 798661a; 403 unit,30 real identity/PostgreSQL,32 desktop/mobile flows passed. All checklist items in this issue are complete; production rollout and cloud execution remain separate #91/#93/#95 work. No push/release/cloud execution.

  6. lweberru commented on Oct 6, 2026

    @lweberru
    CollaboratorAuthor

    Lokale Folgekorrektur 8c630b9 (kein Push) fuer den gemeldeten leeren Veroeffentlichungseinstieg: Auch /applications stellt die letzte berechtigte serverseitige Konfiguration direkt wieder her, ohne vorher Deployments zu besuchen. Ohne offenen Entwurf erscheint zuerst der reale Katalog; Veroeffentlichung bietet eine ausdrueckliche Konfigurationsauswahl. Plattformziele sind erst nach Template-Auswahl bedienbar und bleiben nach Region und Public/Corporate gefiltert. Reales Login/Reload bestaetigt: bestehende Version 1 sofort sichtbar, vorhandener Public-Entwurf direkt wiederhergestellt und passendes eu01-Ziel waehlbar. Kein erneutes Publizieren, keine Aenderung bestehender ACLs oder Versionen, keine Cloud-Jobs. Lint/Typen/Build, 403 Unit-Tests und 36 fokussierte Desktop/Mobil-Browserfaelle PASS; beide lokalen Commits secret-geprueft. Urspruengliche Publikationsabnahme bleibt gueltig; andere MVP-Issues bleiben offen.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:configuratorLanding Zone Configurator application, runtime and its infrastructureeffort:lArchitecture, lifecycle or multiple systems; split before implementationmvp:requiredRequired acceptance gate for the agreed Configurator MVP; not a merge approvalpriority:p1High impact correctness, security or required product capability; schedule first

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions