Validate cadence contract and require functional MFA verification
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
This commit is contained in:
tegwick 2026-09-05 01:28:05 +02:00
parent d4d61b722e
commit 4e07d60ff1
34 changed files with 1640 additions and 364 deletions

View file

@ -40,17 +40,6 @@ printf "LLDAP_LDAP_USER_PASS=%q\n" "$LLDAP_LDAP_USER_PASS" > "$tmp/lldap/secrets
bash "$SCRIPT_DIR/bootstrap-realm.sh" "$tmp" "$PI_URL"
if ! bash "$SSO_MFA_K8S_DIR/verify-t06.sh" "$tmp"; then
cat >&2 <<'WARN'
[WARN] verify-t06 still reports failures. If realm, resolver, policies, and
self-service pass but KeyCape token checks fail, run the KeyCape privacyIDEA
MFA token repair action after platform-root enrollment.
WARN
fi
cat <<'OK'
[OK] privacyIDEA coulomb realm repair command finished. Enroll or re-enroll
platform-root TOTP in privacyIDEA next.
OK
echo "Realm configuration applied; functional verification requires an enrolled OTP token."
bash "$SSO_MFA_K8S_DIR/verify-t06.sh" --pi-url "$PI_URL" --user "${MFA_USER:-platform-root}"
echo "[OK] realm repair and functional MFA verification passed."