adr-proposal: ACL resolves its zaaktype by identificatie, not a pinned URL (S-27) #117
Closed
opened 2026-07-22 13:10:38 +00:00 by not
·
0 comments
No Branch/Tag Specified
main
ci/175-deploy-on-merge
feat/177-public-tls-edge
ci/168-helm-chart-ci-gate
docs/169-mkdocs-nav
feat/25-helm-kubernetes-caddy
fix/161-e2e-bounded-and-diagnosable
feat/162-werkbak-live-refresh
feat/132-medewerker-mfa
fix/156-tempo-ingester-healthcheck
feat/153-projection-sourced-from-objecten
feat/152-objecten-publishes-to-nrc
feat/149-acl-writes-registerrecord
feat/141-registerrecord-objecttype
perf/verify-stack-uwsgi-oz-nrc
fix/144-verify-stack-uwsgi
feat/140-objecten-up
feat/139-objecttypen-up
feat/131-default-fill-crud
chore/136-ci-job-summaries
fix/134-verify-stack-scheduling
feat/130-beheer-catalogi
feat/124-metrics-dashboards
ci/127-parallel-jobs
feat/123-distributed-traces
feat/111-self-service-resume
feat/113-acl-zaaktype-by-identificatie
fix/110-compose-local-flow
fix/115-e2e-single-worker
docs/111-backlog-s26
feat/106-close-zaak-on-timeout
feat/103-diploma-upload-documenten
feat/102-document-wait-timeout
feat/14-dmn-diploma-eligibility
feat/15-beoordeling-escalation
fix/portal-nginx-resolver
fix/local-eventsubscriber-acl
feat/12-withdrawal-portal
fix/91-local-compose-parity
feat/12-withdrawal-bff
feat/12-withdrawal-workflow
feat/12-withdrawal
feat/13-behandel-portal
feat/13-behandel-decide
feat/13-behandel-bff-auth-werkbak
feat/13-workflow-user-tasks
feat/13-behandel-decision-model
chore/release-2026.07.0
feat/78-reference-correlation
feat/75-approval-flow
feat/10-openbaar-portal
chore/73-ci-speedups
feat/68-e2e
feat/67-self-service-form
feat/66-api-client
feat/65-nx-workspace
feat/8-bff
feat/6-domain-service
feat/7-event-subscriber-projection
feat/56-nrc-notification-wiring
test/46-acl-openzaak-integration
feat/47-acl-mutation-baseline
ci/30-gitea-actions-ci
feat/5-acl-open-zaak
feat/4-flowable
feat/3-keycloak
feat/2-opennotificaties
feat/2-catalogus-seed
feat/10-openzaak-compose
feat/32-docs-scaffold
feat/31-contributor-workflow
feat/30-gitea-actions-ci
feat/29-bff-docker-compose
chore/remove-bootstrap-scripts
feat/28-bff-health
docs/split-s00
v2026.07.0
Milestone
No items
No Milestone
Iteration 2 — Flow Completeness
Projects
Clear projects
No projects
Assignees
eho (Edwin van den Houdt)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: eho/register-referentie#117
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
ADR-proposal for S-27 (#113) — the design to agree before coding (CLAUDE.md §14).
Context
Today the ACL is handed a pinned zaaktype URL (
Acl__Defaults__ZaaktypeUrl) and informatieobjecttype URL. Those UUIDs are server-assigned by OpenZaak at creation, so every stack must seed the catalogus and then inject the resulting URLs out of band — CI does it inrun-domain-check.sh, and the local stack does it via thelocal-seed→acl.envbootstrap added in ADR-0020 (#110). Brittle, and a placeholder URL fails opaquely (OpenZaak 400).Proposed decision
The ACL resolves its zaaktype (and diploma informatieobjecttype) by stable business key against OpenZaak's Catalogi API, instead of a pinned URL.
Acl__Defaults__ZaaktypeUrl→Acl__Defaults__ZaaktypeIdentificatie(BIG-REGISTRATIE) and…InformatieobjecttypeUrl→…InformatieobjecttypeOmschrijving(Diploma).GET /catalogi/api/v1/zaaktypen?identificatie=BIG-REGISTRATIE&status=definitief→ the published zaaktype URL;GET /catalogi/api/v1/informatieobjecttypen?status=definitiefmatched onomschrijving. Reuses the existingGetCatalogusAsyncmachinery.Consequences
docker-compose.yml/run-domain-check.shstop capturing+injecting the URL, and the locallocal-seedno longer writesacl.env(it still creates/publishes the zaaktype; the ACL just discovers it). Theseed-envvolume + ACL entrypoint shim from ADR-0020 can be removed → simpler local stack.Scope / plan
TDD: red test for the cached resolver + gateway lookup → implement → live integration test (resolve against a real seeded OpenZaak) → remove the pinned-URL injection from both stacks + verify scripts → ADR-0021 file + docs. Supersedes the ADR-0020
acl.envmechanism.Seeking agreement on the lazy+cached timing and the identificatie/omschrijving config keys before implementing.