tier_trial group + reconciler paid mapping + end-of-August downgrade runbook #232

Stängd
öppnade 2026-07-28 10:55:05 +00:00 av supernaut · 1 kommentar
Ägare

Part of the sign-up trial epic (bitborg-docs#51). See ADR 0036.

What

Identity + reconciler support for the time-boxed trial.

  • tier_trial Kanidm group: add it, and nest it into the same entitlement groups as the paid
    tier (ent_orgs, ent_runners_shared, ent_runners_priority) so trial members inherit
    organisation creation and Actions/CI without any reconciler special-casing.
  • Reconciler (bitborg-auth-reconciler): read the tier_trial group and map its members to the
    paid quota group (and the pro Renovate cap). This is the only projection code change — org-create
    and Actions come from the entitlement nesting above. Add the group name to reconciler config +
    .env.example; render the env var from the Ansible role.
  • Downgrade runbook + script: an idempotent, operator-triggered batch that moves every
    tier_trial member into the participant group (the reconciler then projects the zero-quota
    downgrade within one run). Includes a dry-run and verification steps.

Cadence note

The reconciler timer stays at 5 minutes — a tighter cadence is not needed for the trial (expiry is a
one-off dated batch, not a poll). Rationale captured in the epic/ADR discussion.

Acceptance

  • A person added to tier_trial gets the paid quota group + org-create + Actions after one reconcile.
  • Emptying tier_trial (downgrade) moves members to the participant zero-quota group after one
    reconcile, with org-create and Actions removed.
  • Reconciler unit tests cover the tier_trial → paid mapping.
Part of the sign-up trial epic (bitborg-docs#51). See ADR 0036. ## What Identity + reconciler support for the time-boxed trial. - **`tier_trial` Kanidm group**: add it, and nest it into the same entitlement groups as the paid tier (`ent_orgs`, `ent_runners_shared`, `ent_runners_priority`) so trial members inherit organisation creation and Actions/CI without any reconciler special-casing. - **Reconciler** (bitborg-auth-reconciler): read the `tier_trial` group and map its members to the `paid` quota group (and the pro Renovate cap). This is the only projection code change — org-create and Actions come from the entitlement nesting above. Add the group name to reconciler config + `.env.example`; render the env var from the Ansible role. - **Downgrade runbook + script**: an idempotent, operator-triggered batch that moves every `tier_trial` member into the participant group (the reconciler then projects the zero-quota downgrade within one run). Includes a dry-run and verification steps. ## Cadence note The reconciler timer stays at 5 minutes — a tighter cadence is not needed for the trial (expiry is a one-off dated batch, not a poll). Rationale captured in the epic/ADR discussion. ## Acceptance - A person added to `tier_trial` gets the paid quota group + org-create + Actions after one reconcile. - Emptying `tier_trial` (downgrade) moves members to the participant zero-quota group after one reconcile, with org-create and Actions removed. - Reconciler unit tests cover the `tier_trial` → paid mapping.
Upphovsperson
Ägare

Merged and deployed to production (2026-07-28). Verified live: sign-up trial checkbox + /trial-terms page serving, Kanidm tier_trial group present and read by the reconciler (GET /v1/group/tier_trial → 200), quota groups healthy, reconciler last_run_status=0 and fresh, no firing alerts. Closing.

Merged and deployed to production (2026-07-28). Verified live: sign-up trial checkbox + /trial-terms page serving, Kanidm tier_trial group present and read by the reconciler (GET /v1/group/tier_trial → 200), quota groups healthy, reconciler last_run_status=0 and fresh, no firing alerts. Closing.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#232
Ingen beskrivning angiven.