coulomb-social/docs/identity/smoke.md
tegwick f5537d8365 Serve the rebuild on app.coulomb.social; defer apex Bubble cutover
Document parallel-host strategy: Railiance on app.*, Bubble remains on
coulomb.social until data and self-registration are ready.
2026-08-09 23:20:30 +02:00

3.5 KiB

Identity smoke checklist

Evidence updated: 2026-08-09.

Offline (dev claims) — passed

uv sync && uv run manage.py migrate && make run
# OIDC_ENABLED=false (default), DEBUG=true
Step Result
Open /Sign in /auth/dev-login/
Dev form subject smoke-1 302 → /app/
Shell shows display name + subject OK
Sign out session cleared
/app/ after logout 302 → login
Second login same subject single Member row (idempotent)
make test 15 passed

Automated POST probe (2026-08-09):

dev_login_post → /app/ 200 with subject smoke-1
logout → app 302 to /auth/login/?next=/app/

Cluster in-cluster (port-forward) — passed (start of OIDC)

DNS for coulomb.social still points at Cloudflare/Bubble; TLS ACME is blocked until cutover. Smoke via:

kubectl -n coulomb-social port-forward svc/coulomb-social 18088:80
curl -H 'Host: coulomb.social' http://127.0.0.1:18088/healthz
# {"status": "ok", "service": "coulomb-social"}
Check Result
Image forgejo.coulomb.social/coulomb/coulomb-social:7067145
OIDC_ENABLED true (values)
GET /healthz + Host 200 JSON ok
GET / + Host 200 landing shell
GET /auth/login/ + Host 302https://kc.coulomb.social/authorize?... with client_id=coulomb-social, redirect_uri=https://coulomb.social/auth/callback/, PKCE S256
Session cookie HttpOnly; Secure; SameSite=Lax (prod settings)

Full browser login against the cluster redirect URI requires public HTTPS on coulomb.social (Secure cookie + callback host). Use local OIDC below before DNS cutover, or complete browser MFA after cutover.

Platform OIDC (local redirect) — ready for human MFA

Client registration and authorize handoff verified; human Authelia + MFA is the remaining interactive step.

export OIDC_ENABLED=true
export OIDC_ISSUER=https://kc.coulomb.social
export OIDC_CLIENT_ID=coulomb-social
export OIDC_REDIRECT_URI=http://127.0.0.1:8008/auth/callback/
export OIDC_SCOPES="openid profile email groups"
# optional live user-engine (else stub):
# export USER_ENGINE_BASE_URL=https://users.92-205-62-239.nip.io
# export USER_ENGINE_PROXY_SECRET="$(kubectl -n user-engine get secret user-engine-runtime \
#   -o jsonpath='{.data.proxy-secret}' | base64 -d)"
make run
Step Expected
Open http://127.0.0.1:8008/ → Sign in redirect KeyCape → Authelia
Complete MFA callback → /app/ with subject / display name
Sign out landing; /app/ requires login
Second login same Member / user_engine user_id

Authorize probe (no browser) 2026-08-09:

redirect_uri KeyCape
http://127.0.0.1:8008/auth/callback/ 302 → Authelia OIDC
https://coulomb.social/auth/callback/ 302 → Authelia OIDC

Unregistered redirects still fail with invalid_profile_usage (T03).

Automated

make test

Public host (parallel to Bubble)

Strategy: live Railiance app on app.coulomb.social; apex coulomb.social stays Bubble until content + self-registration cutover.

Check Detail
Cluster host app.coulomb.social (Helm + ingress)
OIDC redirect https://app.coulomb.social/auth/callback/
DNS operator: app.coulomb.social A → 92.205.62.239
Apex do not repoint until Bubble retirement

See docs/deploy.md.