generated from coulomb/repo-seed
NK-WP-0001-T04 (privacyIDEA, Keycloak path) -> cancelled, superseded by NK-WP-0003-T04 in the deployed KeyCape stack. T05-T08 (Keycloak SSO, realm/MFA flow, user mgmt, DR) -> cancelled and migrated to NK-WP-0011. NK-WP-0011 reframes the deferred Keycloak work as expanded-mode enterprise federation: Keycloak as an identity broker for Entra ID / AD / SAML that issues IAM Profile-conformant tokens, refined against the current stack (OpenBao runtime secrets, CloudNativePG, flex-auth/Topaz PDP, recursive platform/tenant model) rather than the original greenfield assumptions. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>