coulomb-social/docs/deploy.md
tegwick 29a9ff735e Complete identity smoke path: id_token claims, registration entry, cutover docs
Prefer verified KeyCape id_token claims when /userinfo returns 401; soft-fail
userinfo. Add CSOC-WP-0003 registration entry (disabled until NetKingdom URL),
AAL step-up hooks, smoke/cutover evidence for tegwick OIDC without MFA.
2026-08-09 22:42:51 +02:00

4.3 KiB

Deploy notes

Shape

Standalone service: commit-SHA images → registry forgejo.coulomb.social/coulomb/coulomb-socialrailiance-apps Helm values → railiance01 (same lane as vergabe-teilnahme).

Chart/values/ingress live in railiance-apps (helm/coulomb-social-values.yaml, docs/coulomb-social.md).

Current cluster status (2026-08-09)

Item State
Namespace coulomb-social Active
Deployment 1/1 Ready, image :7067145
Service ClusterIP :80
Ingress coulomb.social → Traefik, cert-manager annotation
Env secret coulomb-social-env (SECRET_KEY, DATABASE_URL, USER_ENGINE_PROXY_SECRET)
OIDC enabled; issuer https://kc.coulomb.social; public client
Public DNS still Cloudflare / Bubble
TLS secret pending HTTP-01 until DNS points at the cluster

In-cluster smoke (with Host: coulomb.social): /healthz ok, landing 200, /auth/login/ → KeyCape authorize. Full browser session needs cutover.

Runtime secrets (names only)

K8s Secret coulomb-social-env in namespace coulomb-social (chart envFrom):

Key Source
SECRET_KEY generated by env-secret script
DATABASE_URL cnpg app role secret (URL-encoded password)
USER_ENGINE_PROXY_SECRET user-engine/user-engine-runtime
# from railiance-apps:
make coulomb-social-env-secret-dry-run
make coulomb-social-env-secret

# from this repo:
./scripts/create-env-secret.sh --dry-run
./scripts/create-env-secret.sh

OIDC is a public client — no client secret.

Non-secret env (OIDC, ALLOWED_HOSTS, user-engine URL) lives in Helm values.

Health

  • GET /healthz{"status":"ok","service":"coulomb-social"}
  • Probes use Host: coulomb.social (probes.hostHeader)

Build / deploy

SHA=$(git rev-parse --short HEAD)
docker build -t forgejo.coulomb.social/coulomb/coulomb-social:$SHA .
# push, then:
# COULOMB_SOCIAL_IMAGE_TAG=$SHA make coulomb-social-deploy   # in railiance-apps

Cutover checklist (DNS → live Railiance)

Goal: https://coulomb.social serves this app (identity shell), not Bubble.

Preconditions

  1. Image + Helm release healthy
  2. KeyCape client coulomb-social with prod redirect https://coulomb.social/auth/callback/
  3. In-cluster OIDC start redirect works
  4. Local browser OIDC + MFA completed once (proves IdP + user-engine path)
  5. Operator accepts brief public outage / Bubble freeze during DNS switch
  6. Optional: export Bubble data if still needed (CSOC-WP-0001) — not required for identity-only cutover

DNS switch

  1. In Cloudflare (or DNS host): lower TTL on coulomb.social if possible (e.g. 300s) ahead of time.

  2. Point apex (and www if used) A to 92.205.62.239 (railiance01 ingress).

    • Prefer DNS-only (grey cloud) first so LE HTTP-01 and Traefik see real traffic; re-enable proxy only if you understand TLS termination path.
  3. Wait for propagation: dig +short coulomb.social A92.205.62.239.

  4. cert-manager should finish HTTP-01; confirm:

    kubectl -n coulomb-social get certificate coulomb-social-tls
    # READY=True
    
  5. Smoke public HTTPS:

    curl -fsS https://coulomb.social/healthz
    curl -sI https://coulomb.social/auth/login/ | grep -i location
    # Location: https://kc.coulomb.social/authorize?...
    
  6. Browser: Sign in → Authelia MFA → land on /app/ with principal.

  7. Sign out; confirm /app/ requires login.

  8. Second login: same member row / user-engine user_id.

Rollback

  • Point DNS A (or Cloudflare origin) back to Bubble/Cloudflare target.
  • Cluster release can stay; it only receives traffic when DNS aims at the node.

After cutover residuals

Item Note
Bubble freeze Stop editing live Bubble as source of truth
Content/UI CSOC-WP-0001 + design extract — not required for identity shell
flex-auth Service leave FLEX_AUTH_BASE_URL unset (local vocabulary) until PDP exists
apps-pg backup/HA business-app contract
OpenBao CCR replace kubectl-sourced env secret when ready
Image CI Forgejo/Gitea pipeline for SHA tags

Local verification (no cutover)

make test
make run   # offline identity
# or OIDC vars from docs/identity/oidc-client.md