Fix plus-address sign-in and finish NK-WP-0041
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e31f-2bcc-7051-a050-70d8cb2dfa49
This commit is contained in:
parent
6700d8f995
commit
2f1e6c3369
7 changed files with 306 additions and 17 deletions
|
|
@ -117,3 +117,32 @@ kubectl run -n sso --rm -it auth-test --image=busybox --restart=Never \
|
|||
# OIDC discovery (should return issuer + endpoints)
|
||||
curl -s https://auth.coulomb.social/.well-known/openid-configuration | jq .
|
||||
```
|
||||
|
||||
## 4.39 compatibility and regression check
|
||||
|
||||
KeyCape needs `preferred_username` in the signed upstream ID token for its
|
||||
directory and MFA lookup. Authelia 4.39 requires the explicit `keycape`
|
||||
claims policy in `configmap.yaml`; deploy it together with the pinned image.
|
||||
KeyCape's in-cluster token requests must also carry the public HTTPS forwarded
|
||||
scheme and host (KeyCape `3b0446e` or later). Neither a health check nor an
|
||||
authorization redirect exercises these requirements.
|
||||
|
||||
Run the isolated token regression with an Authelia 4.39.28 binary and Python
|
||||
`requests`, `PyYAML`, and `cryptography` installed:
|
||||
|
||||
```bash
|
||||
python3 sso-mfa/k8s/authelia/tests/probe_claims.py --authelia-bin /path/to/authelia
|
||||
```
|
||||
|
||||
It uses disposable local users, keys and SQLite databases, checks real signed
|
||||
authorization-code tokens with and without the policy, and terminates the
|
||||
scratch processes. It uses a file backend, so it does not prove LDAP email
|
||||
lookup. Live acceptance also requires a fresh plus-addressed email sign-in
|
||||
through KeyCape to both Vergabe and the account portal, with successful
|
||||
callback and token issuance evidence.
|
||||
|
||||
Before a 4.38 → 4.39 rollout, stop Authelia and preserve the SQLite database
|
||||
and any sidecar files. Keep the previous ConfigMap and image reference too.
|
||||
Rollback requires stopping 4.39 and restoring all three: database, ConfigMap,
|
||||
and image. The migrated database and 4.39 claims policy cannot be used by
|
||||
4.38. See `NK-WP-0041` for the exercised rollout and backup receipt.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue