487012e961
Complete identity seams and email login
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 23:14:09 +02:00
7171587611
Label authenticator entries by user and realm
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 22:05:08 +02:00
8e7229ae68
Allow user-engine OIDC exchange with KeyCape
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 21:40:52 +02:00
2fdf21c379
Deploy platform-root claim mapping
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 21:31:54 +02:00
d2c59fbf5e
Keep provisioner DNS egress in network policy
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 17:51:13 +02:00
816c5c3773
Deploy reusable password setup handoff
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 17:45:09 +02:00
76270a239e
Add single-use identity password setup
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 17:30:23 +02:00
a58df4c3e6
Advance pre-cutover identity conformance
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 16:48:47 +02:00
43045cbaf5
Verify railiance01 identity dependencies
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 12:59:12 +02:00
2d13ea84b2
Make Authelia certificate lifecycle explicit
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 02:16:07 +02:00
8156525a82
Add login alias and record CoulombCore DNS inventory
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:57:22 +02:00
5b8f52749e
Deploy identity administration lifecycle images
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:30:39 +02:00
c9295d278a
Roll forward normalized provisioning images
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:06:34 +02:00
609a718348
Deploy current user-engine provisioning image
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:00:28 +02:00
ba07dd2acb
Add scoped LLDAP identity provisioner
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 00:57:16 +02:00
9a486c3531
Deploy KeyCape-backed portal login edge
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 00:39:22 +02:00
49f727c54c
Deploy internal user-engine portal foundation
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-27 23:24:36 +02:00
11a14648c4
Register rapp-qonto KeyCape client
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-27 20:17:56 +02:00
a9aec541ec
Implement NK-WP-0021 activity-core ops SSO least-privilege.
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
Seed LLDAP activity-core-operators, add membership runbook and helper,
restrict Authelia access on activity/temporal.coulomb.social to that
group (member one_factor + domain deny fallback), apply live, and verify
via Authelia check-policy plus unauthenticated edge redirects.
2026-07-22 15:47:26 +02:00
85a781b7a4
NET-WP-0020 finished: attended-ceremony + auto-unseal-transit profiles, greenfield init/unseal proof
...
T2: greenfield live proof against a fresh uninitialized OpenBao 2.5.5 —
caught and fixed 'bao operator unseal -' not reading stdin (now
'bao write sys/unseal key=-'); init and reseal-replay paths proven.
T3: attended-ceremony selectable — runbook, non-secret ceremony-record
template + validator, and a lab/production deployment profile that blocks
sops-held-automation in console selection, gates, and the init script.
T4: console gate + evidence flags for auto-unseal-transit (Helm seal stanza
prepared in railiance-platform).
Also: SCOPE.md refreshed to current repo state; adhoc fix for the broken
check-secrets Make target (unescaped $).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 22:08:33 +02:00
951ba07c30
adhoc: creds-bootstrap-agent dry-run no longer dies without age key
...
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 14:08:33 +02:00
67b4677cea
NET-WP-0020-T02: wire OpenBao init/unseal as Phase 7b in creds-bootstrap-agent (operator-reviewed)
...
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 13:32:58 +02:00
60142241a3
NET-WP-0020-T02: SOPS-held OpenBao init/unseal automation helper
...
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 11:01:34 +02:00
3875d546bc
Expose OIDC auth mounts to unauthenticated OpenBao UI listing
...
Set listing_visibility=unauth on netkingdom and keycape during OIDC configure
so the browser login mask can select KeyCape instead of falling back to token.
2026-06-19 21:04:31 +02:00
efbdab4652
feat(keycape): add netkingdom OIDC mount and bao.coulomb.social callbacks
...
Configure OpenBao auth for both netkingdom and keycape mounts with browser
redirect URIs; update verify scripts and runtime architecture notes.
2026-06-18 01:23:02 +02:00
3ab326b597
Clarifications on sops
2026-06-14 19:51:05 +02:00
92bf7d1d1c
NET-WP-0019: implement T05 (OIDC claims helper + integration in script/console) and T06 (add dry-run to runbook_payloads for web-ui exposure; cross-link update in 0018 T07). Update workplan notes.
2026-06-03 07:10:56 +02:00
23af9b0a84
NET-WP-0019: fix arg parsing in orchestrator for --cleanup-only early, fix delegate path in console cleanup command.
2026-06-03 02:21:22 +02:00
140fff6773
NET-WP-0019: register T06-adjacent polish workplan + implement core (orchestrator script, safer secret fallback in create-user, console dry-run + cleanup commands, make targets, cross-link from 0017 T06). See workplan file for task status.
2026-06-03 02:17:55 +02:00
8a3d7a8aff
chore: make T06 verify scripts executable (chmod +x for check-mfa and keycape-verify used in dry-run evidence)
2026-06-03 02:03:03 +02:00
c48e076429
Close OpenBao OIDC admin bootstrap path
2026-06-01 21:20:53 +02:00
7ce5f5bab0
Simplify KeyCape MFA token refresh
2026-05-29 03:21:58 +02:00
ed991860fa
Fix interactive MFA repair prompt
2026-05-29 03:18:44 +02:00
c7b82df267
Add KeyCape privacyIDEA token repair flow
2026-05-29 03:07:17 +02:00
ab99380dec
Align Authelia KeyCape token auth method
2026-05-29 02:50:29 +02:00
cac59a37c1
openbao and itsec tooling integration
2026-05-27 18:56:30 +02:00
1edcfbb17d
Use helper for OpenBao OIDC auth setup
2026-05-26 03:02:08 +02:00
a47c707a9a
Verify KeyCape discovery without container wget
2026-05-26 02:47:01 +02:00
59c924bc18
Patch KeyCape OpenBao client without bootstrap secrets
2026-05-26 02:36:04 +02:00
1267df148a
Harden KeyCape OpenBao client action
2026-05-26 02:22:24 +02:00
f3c8d70270
Split OpenBao admin identity tasks
2026-05-26 02:13:55 +02:00
dc70cd9fab
Configure KeyCape LLDAP people OU
2026-05-25 00:32:43 +02:00
5af876eb8c
Enable KeyCape bootstrap MFA mode
2026-05-25 00:16:05 +02:00
4cc22bec9e
Record Railiance KeyCape rollout
2026-05-24 18:12:41 +02:00
d555a33695
bootstrapping guidance ui and missing stuff
2026-05-24 17:04:15 +02:00
c054241a5c
feat(t09): backup, break-glass, DR drill — NK-WP-0003-T09 done
...
- Apply SQLite backup CronJobs (LLDAP, Authelia, privacyIDEA) — all verified running
- Fix authelia-backup: remove scale-down/up dance; concurrent local-path PVC mount
works on single-node k3s, sqlite3 .backup is safe for concurrent access
- Fix privacyidea-backup: add supplementalGroups: [999] so uid=1000 can read enckey
- Add allow-backup-to-kube-api NetworkPolicy (backup pod → 10.43.0.1:443)
- Create break-glass LLDAP account (net-kingdom-admins); fix ((PASS++)) set-e trap
- SQLite restore drill: LLDAP backup valid (2 users, all tables)
- verify-t08.sh: PASS=15, FAIL=0; fix counter bug + enckey PVC path (/etc/privacyidea)
- Update DR-RUNBOOK.md Authelia restore procedure
- T09 deferred: CNPG backup (needs MinIO/S3), Prometheus (needs kube-prometheus-stack)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 23:56:40 +00:00
331eeaf378
fix(lldap): fix gql() brace bug + use LDAP for password setting
...
Three fixes:
1. gql() default vars '${2:-{}}' — bash parsed first '}' as closing the
parameter expansion, appending a stray '}' to every caller's vars.
Fixed by storing '{}' in a local variable first.
2. make_vars() — add VAR_INT_KEYS support so groupId is emitted as a
JSON integer (Int!) rather than a string, matching LLDAP's schema.
3. Password setting — LLDAP has no GraphQL mutation for admin password
reset. Replace the broken resetUserPasswordFromAdmin mutation with
an RFC 3062 LDAP Password Modify operation via kubectl port-forward
to the in-cluster LLDAP service, using ldap3.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:49:26 +00:00
3a76774dec
feat(lldap): add --test flag to create-user.sh for auto-derived passwords
...
--test derives the password from the display name (spaces → hyphens, append -Pwd),
e.g. "Test User" → "Test-User-Pwd". Skips the interactive prompt.
Useful for provisioning test accounts in a non-interactive flow.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:49:26 +00:00
ca69f6bb73
fix(lldap): use env vars in create-user.sh to avoid shell injection
...
Pass GraphQL query/variables and group names via environment variables
to python3 instead of shell argument interpolation. Prevents breakage
when display names, emails, or passwords contain quotes or spaces.
Also adds --admin flag support and interactive password prompt.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:49:26 +00:00
e802fe3a9d
feat(lldap): add create-user.sh for user provisioning
...
Creates a user in LLDAP via GraphQL, adds them to net-kingdom-users,
optionally net-kingdom-admins (--admin flag), and sets a password interactively.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:49:26 +00:00