key-cape/docs
tegwick 7dda967c27
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 45s
Establish the live state and find a rollout precondition for G10
G10 waits on custody and platform owners and cannot close from here. What was
doable: verify the handoffs actually went out, replace a remembered live state
with an observed one, and find out whether main is safe to deploy. The last
question found a defect in this repository's own recent work.

Handoffs verified independently rather than trusted: all seven messages are in
the hub with receipt ids. This gap was reopened once for claimed-but-unsent
delivery, so the claim deserved the same scrutiny.

Live state read from the cluster read-only: image main-153258b, only the Qonto
secret materialized so the approval clients remain unprovisioned, four registered
clients, no tenantEngine block. That also corrects an earlier claim of mine --
the deployed config sets userOU explicitly, so the KEY-WP-0023 default fix was
never a production issue.

The precondition: KEY-WP-0019 discovers the expected issuer from
authelia.tokenBaseURL, and the deployed Authelia derives its advertised issuer
from the request Host, advertising the in-cluster address to KeyCape and the
browser-facing one to browsers. Verification fails closed, so a mismatch breaks
every human login and looks like a broken login rather than a misconfiguration.
Which value the token carries needs a real login against production to settle and
was not determined here.

Two mitigations: docs/operations.md documents pinning authelia.issuer and
jwksUrl, with the curl that reveals what the provider advertises for a given
Host; and the authentication failure event now carries a specific reason, so
id_token_issuer_mismatch is distinguishable from a signature failure or an
unreachable key set. The browser still learns nothing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-08 11:41:42 +02:00
..
adr feat: implement T01-T04 — Go module, canonical model, LDAP validator, error taxonomy 2026-03-13 01:27:54 +01:00
approval-engine-auth-contract.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
approval-engine-provisioning-request.yaml Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00
authorization-code-bindings.md Document the authorization-code bindings for relying parties 2026-09-07 00:17:56 +02:00
native-authentication.md Add native verified login and service-token commands 2026-09-05 01:08:58 +02:00
openbao-service-auth-contract.md Implement KeyCape provider and service identity contracts 2026-08-23 13:10:13 +02:00
operations.md Establish the live state and find a rollout precondition for G10 2026-09-08 11:41:42 +02:00
qonto-runtime-identity-contract.md Define Qonto runtime identity contract 2026-07-26 13:34:56 +02:00
tenant-claim-contract.md Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00