Prefer verified KeyCape id_token claims when /userinfo returns 401; soft-fail userinfo. Add CSOC-WP-0003 registration entry (disabled until NetKingdom URL), AAL step-up hooks, smoke/cutover evidence for tegwick OIDC without MFA.
4.3 KiB
Deploy notes
Shape
Standalone service: commit-SHA images → registry
forgejo.coulomb.social/coulomb/coulomb-social → railiance-apps Helm values →
railiance01 (same lane as vergabe-teilnahme).
Chart/values/ingress live in railiance-apps
(helm/coulomb-social-values.yaml, docs/coulomb-social.md).
Current cluster status (2026-08-09)
| Item | State |
|---|---|
| Namespace | coulomb-social Active |
| Deployment | 1/1 Ready, image :7067145 |
| Service | ClusterIP :80 |
| Ingress | coulomb.social → Traefik, cert-manager annotation |
| Env secret | coulomb-social-env (SECRET_KEY, DATABASE_URL, USER_ENGINE_PROXY_SECRET) |
| OIDC | enabled; issuer https://kc.coulomb.social; public client |
| Public DNS | still Cloudflare / Bubble |
| TLS secret | pending HTTP-01 until DNS points at the cluster |
In-cluster smoke (with Host: coulomb.social): /healthz ok, landing 200,
/auth/login/ → KeyCape authorize. Full browser session needs cutover.
Runtime secrets (names only)
K8s Secret coulomb-social-env in namespace coulomb-social (chart envFrom):
| Key | Source |
|---|---|
SECRET_KEY |
generated by env-secret script |
DATABASE_URL |
cnpg app role secret (URL-encoded password) |
USER_ENGINE_PROXY_SECRET |
user-engine/user-engine-runtime |
# from railiance-apps:
make coulomb-social-env-secret-dry-run
make coulomb-social-env-secret
# from this repo:
./scripts/create-env-secret.sh --dry-run
./scripts/create-env-secret.sh
OIDC is a public client — no client secret.
Non-secret env (OIDC, ALLOWED_HOSTS, user-engine URL) lives in Helm values.
Health
GET /healthz→{"status":"ok","service":"coulomb-social"}- Probes use
Host: coulomb.social(probes.hostHeader)
Build / deploy
SHA=$(git rev-parse --short HEAD)
docker build -t forgejo.coulomb.social/coulomb/coulomb-social:$SHA .
# push, then:
# COULOMB_SOCIAL_IMAGE_TAG=$SHA make coulomb-social-deploy # in railiance-apps
Cutover checklist (DNS → live Railiance)
Goal: https://coulomb.social serves this app (identity shell), not Bubble.
Preconditions
- Image + Helm release healthy
- KeyCape client
coulomb-socialwith prod redirecthttps://coulomb.social/auth/callback/ - In-cluster OIDC start redirect works
- Local browser OIDC + MFA completed once (proves IdP + user-engine path)
- Operator accepts brief public outage / Bubble freeze during DNS switch
- Optional: export Bubble data if still needed (CSOC-WP-0001) — not required for identity-only cutover
DNS switch
-
In Cloudflare (or DNS host): lower TTL on
coulomb.socialif possible (e.g. 300s) ahead of time. -
Point apex (and
wwwif used) A to92.205.62.239(railiance01 ingress).- Prefer DNS-only (grey cloud) first so LE HTTP-01 and Traefik see real traffic; re-enable proxy only if you understand TLS termination path.
-
Wait for propagation:
dig +short coulomb.social A→92.205.62.239. -
cert-manager should finish HTTP-01; confirm:
kubectl -n coulomb-social get certificate coulomb-social-tls # READY=True -
Smoke public HTTPS:
curl -fsS https://coulomb.social/healthz curl -sI https://coulomb.social/auth/login/ | grep -i location # Location: https://kc.coulomb.social/authorize?... -
Browser: Sign in → Authelia MFA → land on
/app/with principal. -
Sign out; confirm
/app/requires login. -
Second login: same member row / user-engine user_id.
Rollback
- Point DNS A (or Cloudflare origin) back to Bubble/Cloudflare target.
- Cluster release can stay; it only receives traffic when DNS aims at the node.
After cutover residuals
| Item | Note |
|---|---|
| Bubble freeze | Stop editing live Bubble as source of truth |
| Content/UI | CSOC-WP-0001 + design extract — not required for identity shell |
| flex-auth Service | leave FLEX_AUTH_BASE_URL unset (local vocabulary) until PDP exists |
| apps-pg backup/HA | business-app contract |
| OpenBao CCR | replace kubectl-sourced env secret when ready |
| Image CI | Forgejo/Gitea pipeline for SHA tags |
Local verification (no cutover)
make test
make run # offline identity
# or OIDC vars from docs/identity/oidc-client.md