Pin KeyCape main-8be8065 (discovery/JWKS split-horizon headers) as deployed
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Operator-run rollout 2026-09-27: the previous rollout (911e9de) broke
every KeyCape login on Authelia 4.38 -- the provider-metadata/JWKS
discovery fetch used for ID-token verification never carried the
split-horizon X-Forwarded-Proto/Host headers, only the token exchange
did. Fixed in key-cape 8be8065 with a regression test.
Rollback digest: sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
This commit is contained in:
tegwick 2026-09-27 20:02:49 +02:00
parent 17a66fe236
commit 8ad58baa3f

View file

@ -51,11 +51,12 @@ spec:
containers: containers:
- name: keycape - name: keycape
# Image published to the self-hosted Forgejo OCI registry (KEY-WP-0002). # Image published to the self-hosted Forgejo OCI registry (KEY-WP-0002).
# key-cape@911e9de: completeAuthorization no longer backdates a # key-cape@8be8065: the provider-metadata/JWKS discovery fetch now
# freshly-verified MFA to a stale kc_login cookie's IssuedAt # carries the same split-horizon X-Forwarded-Proto/Host headers as
# (INFD-IN-0005). # the token exchange (ADHOC-2026-09-27-T02) -- the prior image
# Rollback: sha256:7aefcee9b79eb3285997066b323ae1772e13d58f875aacc6eb5e9407bd1c1185 # (911e9de) broke every login on Authelia 4.38 without this.
image: forgejo.coulomb.social/coulomb/key-cape@sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e # Rollback: sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e
image: forgejo.coulomb.social/coulomb/key-cape@sha256:61b5f222a35c6ee1dc0273ea581bdad3d8d98e58b2c37327ac169639252e8ef5
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports: