docs: record downstream rotation follow-up
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e3f-7301-7622-9be1-12e5f352881c
This commit is contained in:
tegwick 2026-08-23 14:42:59 +02:00
parent c956ceba19
commit edee5c28ab

View file

@ -111,11 +111,11 @@ identity-provisioner restart, privacyIDEA resolver `lldap-coulomb`, the
Authelia client hash, and the privacyIDEA JWT expiry disposition. Static or
dry-run tests must prove replacements do not enter argv or stdout.
The source-of-truth reconciliation is now in progress: Authelia 4.38 OIDC
client entries cannot consume `*_FILE` environment overrides because clients
are a list. NetKingdom is switching the verifier to Authelia's supported
template filter over the Secret-mounted file before this revision is applied
again.
The source-of-truth reconciliation completed in revision `c956ceb`: Authelia
4.38 OIDC client entries cannot consume `*_FILE` environment overrides because
clients are a list, so the verifier now uses Authelia's supported template
filter over the Secret-mounted file. The revision was applied live and
Authelia returned Ready with startup complete.
Do not use `sso-mfa/bootstrap/creds-rotate.sh` through an agent as currently
written: it prints generated replacement values and its signing-key path
@ -141,7 +141,9 @@ complete.
Completed by the KeyCape owner-controlled recovery path on 2026-08-23. The
owner reported all four affected deployments Ready and positive/negative
checks passing. NetKingdom made no live mutation.
checks passing. NetKingdom additionally restarted identity-provisioner after
the LLDAP bind rotation and applied the Authelia template-filter fix. The
privacyIDEA resolver still awaits attended provider-admin reconciliation.
## T05 — Prove replacement, predecessor rejection, and cleanup