KES Authenticated Parity Verification
Scope
This sprint closed the remaining authenticated-mutation gap from Sprint 93.
The parity claim here is limited to the first-cut KES HTTP/runtime surface:
- authenticated mutation auth ingress
- authenticated mutation route behavior
- direct old-host vs new-host parity
- gateway path parity under the existing seam
It is not a claim that Kafka relay, projection, idempotency, or DLQ/replay backbone is already KES-local.
Exact Mutation Routes Tested
Direct old host vs new host:
PUT /kes-orchestrator/process-mapPOST /kes-orchestrator/cases
Gateway path verification:
PUT /api/v1/kes/orchestrator/process-mapPOST /api/v1/kes/orchestrator/cases