Fix plus-address sign-in and finish NK-WP-0041
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 11s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e31f-2bcc-7051-a050-70d8cb2dfa49
This commit is contained in:
tegwick 2026-09-27 16:05:03 +02:00
parent 6700d8f995
commit 2f1e6c3369
7 changed files with 306 additions and 17 deletions

View file

@ -117,3 +117,32 @@ kubectl run -n sso --rm -it auth-test --image=busybox --restart=Never \
# OIDC discovery (should return issuer + endpoints)
curl -s https://auth.coulomb.social/.well-known/openid-configuration | jq .
```
## 4.39 compatibility and regression check
KeyCape needs `preferred_username` in the signed upstream ID token for its
directory and MFA lookup. Authelia 4.39 requires the explicit `keycape`
claims policy in `configmap.yaml`; deploy it together with the pinned image.
KeyCape's in-cluster token requests must also carry the public HTTPS forwarded
scheme and host (KeyCape `3b0446e` or later). Neither a health check nor an
authorization redirect exercises these requirements.
Run the isolated token regression with an Authelia 4.39.28 binary and Python
`requests`, `PyYAML`, and `cryptography` installed:
```bash
python3 sso-mfa/k8s/authelia/tests/probe_claims.py --authelia-bin /path/to/authelia
```
It uses disposable local users, keys and SQLite databases, checks real signed
authorization-code tokens with and without the policy, and terminates the
scratch processes. It uses a file backend, so it does not prove LDAP email
lookup. Live acceptance also requires a fresh plus-addressed email sign-in
through KeyCape to both Vergabe and the account portal, with successful
callback and token issuance evidence.
Before a 4.38 → 4.39 rollout, stop Authelia and preserve the SQLite database
and any sidecar files. Keep the previous ConfigMap and image reference too.
Rollback requires stopping 4.39 and restoring all three: database, ConfigMap,
and image. The migrated database and 4.39 claims policy cannot be used by
4.38. See `NK-WP-0041` for the exercised rollout and backup receipt.