Skip to content

rename: tutorials-poc -> tutorials-ims (Tier 2: MTA id + Tier 3: xsappname) — pre-production cutover #635

Description

@jung-thomas

Context

The codebase identifies itself as tutorials-poc in three identity domains. Tier 1 (cosmetic / package metadata) was cleaned up in #TBD-PR-FOR-CURRENT-BRANCH — that fixed the "Serving tutorials-poc undefined" message on the CAP welcome page. The remaining two tiers carry real deployment + identity consequences and must be planned + executed as a coordinated cutover, ideally before the PROD cutover end-of-July 2026.

Tier 2 — MTA deployment identity

Files that still say tutorials-poc:

  • mta.yaml:2 — ID: tutorials-poc
  • .deploy/mta.yaml:2 — ID: tutorials-poc
  • .deploy/DEPLOY.md — references to mta_archives/tutorials-poc_1.0.0.mtar
  • .github/workflows/deploy.yml:385,393,606 — cf deploy mta_archives/tutorials-poc_*.mtar, cf mta-ops | grep tutorials-poc, MTAR_FILE=...
  • docs/developers/operations/{mta-deployment,deployment,production-ready,qa-channel-bootstrap,github-dispatch-pat-rotation}.md — tutorials-poc_1.0.0.mtar filename references + ID: tutorials-poc-prod / extends: tutorials-poc
  • docs/developers/getting-started.md:163 — same
  • docs/developers/architecture/build.md:51 — mermaid diagram label

Consequence

The MTA ID is the identity key Cloud Foundry uses to track a deployment. If we change the ID to tutorials-ims and run cf deploy mta_archives/tutorials-ims_1.0.0.mtar:

  • CF treats it as a NEW MTA, not an update.
  • The existing tutorials-poc MTA is NOT automatically replaced — it stays running alongside.
  • All service instances bound to the old MTA (HANA HDI containers, XSUAA, Destination Service, credstore, Application Logs, AI Core) get recreated under the new MTA → HANA schema teardown, fresh HDI deploy.
  • Data loss risk if HDI tries to drop schemas during the side-by-side window.

Cutover procedure (DEV first, then PROD)

  1. Schedule a downtime window.
  2. Snapshot HANA schemas (DEV → backup HDI container, PROD → MDC backup).
  3. cf undeploy tutorials-poc --delete-services --delete-service-keys --delete-service-brokers on the target space.
  4. Update mta.yaml, .deploy/mta.yaml, all docs, .github/workflows/deploy.yml in one PR.
  5. mbt build && cf deploy mta_archives/tutorials-ims_1.0.0.mtar -e ../deploy/<env>.mtaext -f.
  6. Restore HANA data from snapshot if HDI did a destructive deploy.
  7. Smoke test full path: approuter → CAP → HANA → content serve → admin UI → display dashboard → scanner → analytics.

Estimate

DEV cutover: ~1 hour wall-clock (most of it the HDI redeploy + content republish).
PROD cutover: include in the AEM→IMS PROD cutover plan for end-of-July 2026.

Tier 3 — XSUAA application identity (xsappname)

Files that still say tutorials-poc:

  • xs-security.json:2 — "xsappname": "tutorials-poc"
  • .deploy/xs-security.json:2 — "xsappname": "tutorials-poc"
  • docs/developers/architecture/authentication.md:63 — example scope literal tutorials-poc.DeveloperApp, tutorials-poc.Everyone

Consequence

xsappname is the prefix on every XSUAA scope issued to JWT tokens. So tutorials-poc.Admin, tutorials-poc.Tutorial.Author, tutorials-poc.DisplayApp, tutorials-poc.DeveloperApp, tutorials-poc.Everyone — every scope name carries it.

If we change xsappname to tutorials-ims:

  • Every BTP role-collection assignment must be re-bound. The current tutorial-system subaccount has assignments riding on tutorials-poc.* scopes. They will not auto-transfer.
  • In-flight JWTs continue to assert old-prefix scopes until users log out + log back in. Users will see 403s until they refresh.
  • Every @requires literal in CDS that names a scope must be updated in lockstep (search srv/ for 'tutorials-poc.').
  • Admin UI tile / button visibility that gates on scope name will misbehave during the transition.

Cutover procedure

Must be done as part of Tier 2 cutover (same downtime window — cf undeploy tutorials-poc recreates the XSUAA service instance anyway):

  1. Pre-stage role-collection updates: every collection currently bound to tutorials-poc.* scopes needs a parallel binding to the same scope name with the new prefix. Script: scripts/migrate-btp-roles.js (already exists for the subaccount migration — extend for prefix migration).
  2. Update both xs-security.json files + every @requires literal in srv/.
  3. After Tier 2 redeploy, run the role-collection rebind script.
  4. Force-logout all users (set token TTL to 0 momentarily, or wait for current TTL to expire — default 12h).
  5. Document the change in docs/developers/architecture/authentication.md.

Estimate

Same downtime window as Tier 2. Add ~30 min for role-collection rebinding + ~1 day of user re-login lag.

Out-of-scope items still on tutorials-poc

These are correct as long as Tier 2/3 are not yet done — don't touch in isolation:

  • TUTORIALS_POC_DISPATCH_TOKEN secret name in every *-Contribution GitHub repo (rotation must be coordinated; tracked separately in docs/developers/operations/qa-channel-bootstrap.md).
  • Local filesystem path d:/projects/tutorials-poc/... in scripts/git-hooks/pre-commit, docs/developers/operations/agent-isolation-hooks.md, docs/developers/operations/mta-deployment.md — this is the actual on-disk folder name on Tom's machine. Folder rename is a separate physical operation; covered in CLAUDE.md memory project_folder_vs_repo_name already.
  • docs/superpowers/ historical specs + plans — intentionally preserved as point-in-time records of how decisions were made.

Done when

  • mta.yaml, .deploy/mta.yaml, all docs, .github/workflows/deploy.yml updated in lockstep.
  • Both xs-security.json files updated.
  • All srv/**/*.cds @requires literals migrated.
  • scripts/migrate-btp-roles.js extended (or new script written) to remap collection bindings.
  • DEV cutover executed + verified (full smoke).
  • PROD cutover scheduled into the AEM→IMS end-of-July 2026 plan.
  • CLAUDE.md project_folder_vs_repo_name memory updated to note that local folder rename is the last remaining gap.

Related

  • Tier 1 PR: TBD (this branch — package.json + comment + User-Agent string + repo-name bug fix in notify-qa.yml.template)
  • CLAUDE.md memory: project_btp_subaccount_migration, project_prod_cutover_july_2026, project_folder_vs_repo_name

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

BlockedWaiting on someone or something else

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions