Prefer verified KeyCape id_token claims when /userinfo returns 401; soft-fail userinfo. Add CSOC-WP-0003 registration entry (disabled until NetKingdom URL), AAL step-up hooks, smoke/cutover evidence for tegwick OIDC without MFA.
126 lines
4.3 KiB
Markdown
126 lines
4.3 KiB
Markdown
# Deploy notes
|
|
|
|
## Shape
|
|
|
|
Standalone service: commit-SHA images → registry
|
|
`forgejo.coulomb.social/coulomb/coulomb-social` → `railiance-apps` Helm values →
|
|
railiance01 (same lane as `vergabe-teilnahme`).
|
|
|
|
Chart/values/ingress live in **`railiance-apps`**
|
|
(`helm/coulomb-social-values.yaml`, `docs/coulomb-social.md`).
|
|
|
|
## Current cluster status (2026-08-09)
|
|
|
|
| Item | State |
|
|
|------|--------|
|
|
| Namespace | `coulomb-social` Active |
|
|
| Deployment | 1/1 Ready, image `:7067145` |
|
|
| Service | ClusterIP :80 |
|
|
| Ingress | `coulomb.social` → Traefik, cert-manager annotation |
|
|
| Env secret | `coulomb-social-env` (`SECRET_KEY`, `DATABASE_URL`, `USER_ENGINE_PROXY_SECRET`) |
|
|
| OIDC | enabled; issuer `https://kc.coulomb.social`; public client |
|
|
| Public DNS | **still Cloudflare / Bubble** |
|
|
| TLS secret | **pending** HTTP-01 until DNS points at the cluster |
|
|
|
|
In-cluster smoke (with `Host: coulomb.social`): `/healthz` ok, landing 200,
|
|
`/auth/login/` → KeyCape authorize. Full browser session needs cutover.
|
|
|
|
## Runtime secrets (names only)
|
|
|
|
K8s Secret `coulomb-social-env` in namespace `coulomb-social` (chart `envFrom`):
|
|
|
|
| Key | Source |
|
|
|-----|--------|
|
|
| `SECRET_KEY` | generated by env-secret script |
|
|
| `DATABASE_URL` | cnpg app role secret (URL-encoded password) |
|
|
| `USER_ENGINE_PROXY_SECRET` | `user-engine/user-engine-runtime` |
|
|
|
|
```bash
|
|
# from railiance-apps:
|
|
make coulomb-social-env-secret-dry-run
|
|
make coulomb-social-env-secret
|
|
|
|
# from this repo:
|
|
./scripts/create-env-secret.sh --dry-run
|
|
./scripts/create-env-secret.sh
|
|
```
|
|
|
|
OIDC is a **public** client — no client secret.
|
|
|
|
Non-secret env (OIDC, ALLOWED_HOSTS, user-engine URL) lives in Helm values.
|
|
|
|
## Health
|
|
|
|
- `GET /healthz` → `{"status":"ok","service":"coulomb-social"}`
|
|
- Probes use `Host: coulomb.social` (`probes.hostHeader`)
|
|
|
|
## Build / deploy
|
|
|
|
```bash
|
|
SHA=$(git rev-parse --short HEAD)
|
|
docker build -t forgejo.coulomb.social/coulomb/coulomb-social:$SHA .
|
|
# push, then:
|
|
# COULOMB_SOCIAL_IMAGE_TAG=$SHA make coulomb-social-deploy # in railiance-apps
|
|
```
|
|
|
|
## Cutover checklist (DNS → live Railiance)
|
|
|
|
**Goal:** `https://coulomb.social` serves this app (identity shell), not Bubble.
|
|
|
|
### Preconditions
|
|
|
|
1. [x] Image + Helm release healthy
|
|
2. [x] KeyCape client `coulomb-social` with prod redirect `https://coulomb.social/auth/callback/`
|
|
3. [x] In-cluster OIDC start redirect works
|
|
4. [ ] Local browser OIDC + MFA completed once (proves IdP + user-engine path)
|
|
5. [ ] Operator accepts brief public outage / Bubble freeze during DNS switch
|
|
6. [ ] Optional: export Bubble data if still needed (CSOC-WP-0001) — not required for identity-only cutover
|
|
|
|
### DNS switch
|
|
|
|
1. In Cloudflare (or DNS host): lower TTL on `coulomb.social` if possible (e.g. 300s) ahead of time.
|
|
2. Point apex (and `www` if used) **A** to **`92.205.62.239`** (railiance01 ingress).
|
|
- Prefer DNS-only (grey cloud) first so LE HTTP-01 and Traefik see real traffic; re-enable proxy only if you understand TLS termination path.
|
|
3. Wait for propagation: `dig +short coulomb.social A` → `92.205.62.239`.
|
|
4. cert-manager should finish HTTP-01; confirm:
|
|
|
|
```bash
|
|
kubectl -n coulomb-social get certificate coulomb-social-tls
|
|
# READY=True
|
|
```
|
|
|
|
5. Smoke public HTTPS:
|
|
|
|
```bash
|
|
curl -fsS https://coulomb.social/healthz
|
|
curl -sI https://coulomb.social/auth/login/ | grep -i location
|
|
# Location: https://kc.coulomb.social/authorize?...
|
|
```
|
|
|
|
6. **Browser:** Sign in → Authelia MFA → land on `/app/` with principal.
|
|
7. Sign out; confirm `/app/` requires login.
|
|
8. Second login: same member row / user-engine user_id.
|
|
|
|
### Rollback
|
|
|
|
- Point DNS A (or Cloudflare origin) back to Bubble/Cloudflare target.
|
|
- Cluster release can stay; it only receives traffic when DNS aims at the node.
|
|
|
|
### After cutover residuals
|
|
|
|
| Item | Note |
|
|
|------|------|
|
|
| Bubble freeze | Stop editing live Bubble as source of truth |
|
|
| Content/UI | CSOC-WP-0001 + design extract — not required for identity shell |
|
|
| flex-auth Service | leave `FLEX_AUTH_BASE_URL` unset (local vocabulary) until PDP exists |
|
|
| apps-pg backup/HA | business-app contract |
|
|
| OpenBao CCR | replace kubectl-sourced env secret when ready |
|
|
| Image CI | Forgejo/Gitea pipeline for SHA tags |
|
|
|
|
## Local verification (no cutover)
|
|
|
|
```bash
|
|
make test
|
|
make run # offline identity
|
|
# or OIDC vars from docs/identity/oidc-client.md
|
|
```
|