Use temporal.coulomb.social for Temporal UI SSO host
Prefer clean short hostname temporal.coulomb.social instead of activity-temporal.coulomb.social for Ingress, CORS, and ops UI links.
This commit is contained in:
parent
2acf2baffa
commit
54431db583
9 changed files with 21 additions and 21 deletions
2
SCOPE.md
2
SCOPE.md
|
|
@ -213,7 +213,7 @@ Open product/policy workplan: **ACTIVITY-WP-0022** (IssueSink no-default-Forgejo
|
||||||
| **G7. Credential delivery** | Low (residual) | **FORGEJO_TOKEN** via ESO `actcore-forgejo-admin` (WP-0023-T05, Ready). issue-core `GITEA_BACKEND_TOKEN` still 503 forgejo-inbox for path A rest — **issue-core owner** (WP-0023-T06). |
|
| **G7. Credential delivery** | Low (residual) | **FORGEJO_TOKEN** via ESO `actcore-forgejo-admin` (WP-0023-T05, Ready). issue-core `GITEA_BACKEND_TOKEN` still 503 forgejo-inbox for path A rest — **issue-core owner** (WP-0023-T06). |
|
||||||
| **G8. Live-images hygiene** | Medium (ops) | Multi-cluster `live-images-all.txt` must be refreshed after deploys or prune can delete live tags (incident 2026-07-21, restored). `scripts/refresh_live_images.sh` (T04). |
|
| **G8. Live-images hygiene** | Medium (ops) | Multi-cluster `live-images-all.txt` must be refreshed after deploys or prune can delete live tags (incident 2026-07-21, restored). `scripts/refresh_live_images.sh` (T04). |
|
||||||
| **G9. Evidence federation** | Low | Progress often lands on railiance01 edge/hub; workstation primary hub may not show the same feed without tunnel/outbox health. |
|
| **G9. Evidence federation** | Low | Progress often lands on railiance01 edge/hub; workstation primary hub may not show the same feed without tunnel/outbox health. |
|
||||||
| **G10. API external access** | Medium (in progress) | WP-0025: Traefik + Authelia SSO for `activity.coulomb.social` + `activity-temporal.coulomb.social`; port-forward remains break-glass until DNS/certs Ready. |
|
| **G10. API external access** | Medium (in progress) | WP-0025: Traefik + Authelia SSO for `activity.coulomb.social` + `temporal.coulomb.social`; port-forward remains break-glass until DNS/certs Ready. |
|
||||||
|
|
||||||
### Drift risks
|
### Drift risks
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -10,7 +10,7 @@ Founders / platform operators who already have Authelia accounts under
|
||||||
| Host | Backend | Purpose |
|
| Host | Backend | Purpose |
|
||||||
| --- | --- | --- |
|
| --- | --- | --- |
|
||||||
| `activity.coulomb.social` | `actcore-api:8010` | Ops console `/ops/ui`, JSON `/ops/*`, existing API |
|
| `activity.coulomb.social` | `actcore-api:8010` | Ops console `/ops/ui`, JSON `/ops/*`, existing API |
|
||||||
| `activity-temporal.coulomb.social` | `actcore-temporal-ui:8080` | Temporal Web UI |
|
| `temporal.coulomb.social` | `actcore-temporal-ui:8080` | Temporal Web UI (clean short name) |
|
||||||
|
|
||||||
Both resolve to the railiance01 Traefik LB (`92.205.62.239`) once DNS A records
|
Both resolve to the railiance01 Traefik LB (`92.205.62.239`) once DNS A records
|
||||||
exist (same pattern as `forgejo.coulomb.social`).
|
exist (same pattern as `forgejo.coulomb.social`).
|
||||||
|
|
@ -63,7 +63,7 @@ Create A records (or CNAME to the forgejo host pattern):
|
||||||
|
|
||||||
```text
|
```text
|
||||||
activity.coulomb.social A 92.205.62.239
|
activity.coulomb.social A 92.205.62.239
|
||||||
activity-temporal.coulomb.social A 92.205.62.239
|
temporal.coulomb.social A 92.205.62.239
|
||||||
```
|
```
|
||||||
|
|
||||||
Until DNS exists, cert-manager Certificate will stay Pending and HTTPS will not
|
Until DNS exists, cert-manager Certificate will stay Pending and HTTPS will not
|
||||||
|
|
@ -88,7 +88,7 @@ kubectl apply -f k8s/railiance/31-ingress-ops-sso.yaml
|
||||||
kubectl apply -f k8s/railiance/32-ingress-temporal-sso.yaml
|
kubectl apply -f k8s/railiance/32-ingress-temporal-sso.yaml
|
||||||
# set public Temporal URL on API after cert Ready:
|
# set public Temporal URL on API after cert Ready:
|
||||||
kubectl -n activity-core set env deploy/actcore-api \
|
kubectl -n activity-core set env deploy/actcore-api \
|
||||||
ACTIVITY_CORE_TEMPORAL_UI_URL=https://activity-temporal.coulomb.social
|
ACTIVITY_CORE_TEMPORAL_UI_URL=https://temporal.coulomb.social
|
||||||
kubectl -n activity-core set env deploy/actcore-temporal-ui \
|
kubectl -n activity-core set env deploy/actcore-temporal-ui \
|
||||||
TEMPORAL_CORS_ORIGINS=https://activity-temporal.coulomb.social
|
TEMPORAL_CORS_ORIGINS=https://temporal.coulomb.social
|
||||||
```
|
```
|
||||||
|
|
|
||||||
|
|
@ -110,7 +110,7 @@ the UI** — change definition files and sync.
|
||||||
| UI | URL |
|
| UI | URL |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| Ops console | https://activity.coulomb.social/ops/ui |
|
| Ops console | https://activity.coulomb.social/ops/ui |
|
||||||
| Temporal Web UI | https://activity-temporal.coulomb.social |
|
| Temporal Web UI | https://temporal.coulomb.social |
|
||||||
|
|
||||||
Login via Authelia (`auth.coulomb.social`). Design: `docs/ops-sso-access.md`.
|
Login via Authelia (`auth.coulomb.social`). Design: `docs/ops-sso-access.md`.
|
||||||
Mutations accept SSO identity headers; shared token is break-glass only.
|
Mutations accept SSO identity headers; shared token is break-glass only.
|
||||||
|
|
@ -119,7 +119,7 @@ Mutations accept SSO identity headers; shared token is break-glass only.
|
||||||
|
|
||||||
```text
|
```text
|
||||||
activity.coulomb.social A 92.205.62.239
|
activity.coulomb.social A 92.205.62.239
|
||||||
activity-temporal.coulomb.social A 92.205.62.239
|
temporal.coulomb.social A 92.205.62.239
|
||||||
```
|
```
|
||||||
|
|
||||||
**Break-glass port-forward** (hosteurope kubeconfig):
|
**Break-glass port-forward** (hosteurope kubeconfig):
|
||||||
|
|
@ -134,7 +134,7 @@ kubectl -n activity-core port-forward svc/actcore-temporal-ui 8080:8080
|
||||||
Env overrides:
|
Env overrides:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
ACTIVITY_CORE_TEMPORAL_UI_URL=https://activity-temporal.coulomb.social
|
ACTIVITY_CORE_TEMPORAL_UI_URL=https://temporal.coulomb.social
|
||||||
ACTIVITY_CORE_OPERATOR_TOKEN=… # break-glass; in actcore-runtime-secret
|
ACTIVITY_CORE_OPERATOR_TOKEN=… # break-glass; in actcore-runtime-secret
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -385,4 +385,4 @@ spec:
|
||||||
value: actcore-temporal:7233
|
value: actcore-temporal:7233
|
||||||
- name: TEMPORAL_CORS_ORIGINS
|
- name: TEMPORAL_CORS_ORIGINS
|
||||||
# Include SSO host (ACTIVITY-WP-0025) and local port-forward.
|
# Include SSO host (ACTIVITY-WP-0025) and local port-forward.
|
||||||
value: https://activity-temporal.coulomb.social,http://localhost:8080,http://127.0.0.1:8080
|
value: https://temporal.coulomb.social,http://localhost:8080,http://127.0.0.1:8080
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,5 @@
|
||||||
# HTTPS SSO front door for Temporal Web UI.
|
# HTTPS SSO front door for Temporal Web UI.
|
||||||
# Requires DNS: activity-temporal.coulomb.social A → 92.205.62.239
|
# Requires DNS: temporal.coulomb.social A → 92.205.62.239
|
||||||
# ACTIVITY-WP-0025
|
# ACTIVITY-WP-0025
|
||||||
apiVersion: networking.k8s.io/v1
|
apiVersion: networking.k8s.io/v1
|
||||||
kind: Ingress
|
kind: Ingress
|
||||||
|
|
@ -19,10 +19,10 @@ spec:
|
||||||
ingressClassName: traefik
|
ingressClassName: traefik
|
||||||
tls:
|
tls:
|
||||||
- hosts:
|
- hosts:
|
||||||
- activity-temporal.coulomb.social
|
- temporal.coulomb.social
|
||||||
secretName: actcore-temporal-ui-tls
|
secretName: actcore-temporal-ui-tls
|
||||||
rules:
|
rules:
|
||||||
- host: activity-temporal.coulomb.social
|
- host: temporal.coulomb.social
|
||||||
http:
|
http:
|
||||||
paths:
|
paths:
|
||||||
- path: /
|
- path: /
|
||||||
|
|
|
||||||
|
|
@ -118,17 +118,17 @@ kubectl -n activity-core get svc
|
||||||
```bash
|
```bash
|
||||||
# DNS A records → 92.205.62.239 (once):
|
# DNS A records → 92.205.62.239 (once):
|
||||||
# activity.coulomb.social
|
# activity.coulomb.social
|
||||||
# activity-temporal.coulomb.social
|
# temporal.coulomb.social
|
||||||
|
|
||||||
kubectl apply -f k8s/railiance/30-authelia-middleware.yaml
|
kubectl apply -f k8s/railiance/30-authelia-middleware.yaml
|
||||||
kubectl apply -f k8s/railiance/31-ingress-ops-sso.yaml
|
kubectl apply -f k8s/railiance/31-ingress-ops-sso.yaml
|
||||||
kubectl apply -f k8s/railiance/32-ingress-temporal-sso.yaml
|
kubectl apply -f k8s/railiance/32-ingress-temporal-sso.yaml
|
||||||
kubectl -n activity-core set env deploy/actcore-api \
|
kubectl -n activity-core set env deploy/actcore-api \
|
||||||
ACTIVITY_CORE_TEMPORAL_UI_URL=https://activity-temporal.coulomb.social
|
ACTIVITY_CORE_TEMPORAL_UI_URL=https://temporal.coulomb.social
|
||||||
```
|
```
|
||||||
|
|
||||||
- Ops: https://activity.coulomb.social/ops/ui (Authelia SSO)
|
- Ops: https://activity.coulomb.social/ops/ui (Authelia SSO)
|
||||||
- Temporal: https://activity-temporal.coulomb.social
|
- Temporal: https://temporal.coulomb.social
|
||||||
- Design: `docs/ops-sso-access.md`
|
- Design: `docs/ops-sso-access.md`
|
||||||
|
|
||||||
### Break-glass port-forward
|
### Break-glass port-forward
|
||||||
|
|
|
||||||
|
|
@ -256,7 +256,7 @@ async def auth_status() -> dict[str, Any]:
|
||||||
"sso_docs": "/docs not required — see docs/ops-sso-access.md",
|
"sso_docs": "/docs not required — see docs/ops-sso-access.md",
|
||||||
"public_hosts": {
|
"public_hosts": {
|
||||||
"ops": "https://activity.coulomb.social",
|
"ops": "https://activity.coulomb.social",
|
||||||
"temporal_ui": "https://activity-temporal.coulomb.social",
|
"temporal_ui": "https://temporal.coulomb.social",
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -289,9 +289,9 @@ def temporal_ui_url() -> str:
|
||||||
raw = (
|
raw = (
|
||||||
os.environ.get("ACTIVITY_CORE_TEMPORAL_UI_URL")
|
os.environ.get("ACTIVITY_CORE_TEMPORAL_UI_URL")
|
||||||
or os.environ.get("TEMPORAL_UI_URL")
|
or os.environ.get("TEMPORAL_UI_URL")
|
||||||
or "https://activity-temporal.coulomb.social"
|
or "https://temporal.coulomb.social"
|
||||||
).strip()
|
).strip()
|
||||||
return raw.rstrip("/") or "https://activity-temporal.coulomb.social"
|
return raw.rstrip("/") or "https://temporal.coulomb.social"
|
||||||
|
|
||||||
|
|
||||||
def _page(title: str, body: str) -> HTMLResponse:
|
def _page(title: str, body: str) -> HTMLResponse:
|
||||||
|
|
|
||||||
|
|
@ -218,7 +218,7 @@ async def test_ui_index_renders(ops_app: FastAPI, monkeypatch: pytest.MonkeyPatc
|
||||||
assert "Daily Triage" in res.text
|
assert "Daily Triage" in res.text
|
||||||
assert "Operator token" in res.text
|
assert "Operator token" in res.text
|
||||||
assert "Temporal UI" in res.text
|
assert "Temporal UI" in res.text
|
||||||
assert "activity-temporal.coulomb.social" in res.text
|
assert "temporal.coulomb.social" in res.text
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.asyncio
|
@pytest.mark.asyncio
|
||||||
|
|
|
||||||
|
|
@ -248,7 +248,7 @@ state_hub_task_id: "f73eafbf-ad11-4d7d-b89e-e910c662ce86"
|
||||||
|
|
||||||
| Task | Status | Notes |
|
| Task | Status | Notes |
|
||||||
| --- | --- | --- |
|
| --- | --- | --- |
|
||||||
| T01 | done | Hosts: activity.coulomb.social + activity-temporal.coulomb.social; docs/ops-sso-access.md |
|
| T01 | done | Hosts: activity.coulomb.social + temporal.coulomb.social; docs/ops-sso-access.md |
|
||||||
| T02 | done | Reuse Authelia + Traefik ForwardAuth (sso ns); not oauth2-proxy |
|
| T02 | done | Reuse Authelia + Traefik ForwardAuth (sso ns); not oauth2-proxy |
|
||||||
| T03 | progress | Ingress + middleware manifests landed; **blocked on DNS A records** for cert |
|
| T03 | progress | Ingress + middleware manifests landed; **blocked on DNS A records** for cert |
|
||||||
| T04 | progress | Temporal Ingress manifest + CORS env; same DNS gate |
|
| T04 | progress | Temporal Ingress manifest + CORS env; same DNS gate |
|
||||||
|
|
@ -259,4 +259,4 @@ state_hub_task_id: "f73eafbf-ad11-4d7d-b89e-e910c662ce86"
|
||||||
|
|
||||||
**Operator action required:** create DNS A records for both hosts → 92.205.62.239,
|
**Operator action required:** create DNS A records for both hosts → 92.205.62.239,
|
||||||
then apply `k8s/railiance/30-*.yaml`–`32-*.yaml` and set
|
then apply `k8s/railiance/30-*.yaml`–`32-*.yaml` and set
|
||||||
`ACTIVITY_CORE_TEMPORAL_UI_URL=https://activity-temporal.coulomb.social` on actcore-api.
|
`ACTIVITY_CORE_TEMPORAL_UI_URL=https://temporal.coulomb.social` on actcore-api.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue