27656916db
Add KeyCape client registration for coulomb.social
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Idempotent patch of sso/keycape-config with public PKCE client and
redirect URIs for local :8008 and production coulomb.social callbacks.
2026-08-09 01:50:52 +02:00
62b1ea3d59
Deploy tenant authority for user portal
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-09 01:39:57 +02:00
03cc0c5a91
Deploy expanded user-engine portal
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-08-08 23:18:29 +02:00
0ec6f8c75d
Move identity secret stores to local OpenBao
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-08-03 21:37:17 +02:00
39b71d6d96
Complete user-engine runtime custody
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-30 00:40:43 +02:00
f854969a01
Move portal workloads to registry digests
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-30 00:25:16 +02:00
52b57c99f7
Add user-engine backup and rollback verification
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-30 00:00:14 +02:00
12ac63f32c
Deploy identity drift reconciliation
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 23:41:42 +02:00
487012e961
Complete identity seams and email login
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 23:14:09 +02:00
7171587611
Label authenticator entries by user and realm
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 22:05:08 +02:00
8e7229ae68
Allow user-engine OIDC exchange with KeyCape
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 21:40:52 +02:00
2fdf21c379
Deploy platform-root claim mapping
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 21:31:54 +02:00
d2c59fbf5e
Keep provisioner DNS egress in network policy
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 17:51:13 +02:00
816c5c3773
Deploy reusable password setup handoff
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 17:45:09 +02:00
76270a239e
Add single-use identity password setup
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 17:30:23 +02:00
a58df4c3e6
Advance pre-cutover identity conformance
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 16:48:47 +02:00
43045cbaf5
Verify railiance01 identity dependencies
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 12:59:12 +02:00
2d13ea84b2
Make Authelia certificate lifecycle explicit
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 02:16:07 +02:00
8156525a82
Add login alias and record CoulombCore DNS inventory
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:57:22 +02:00
5b8f52749e
Deploy identity administration lifecycle images
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:30:39 +02:00
c9295d278a
Roll forward normalized provisioning images
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:06:34 +02:00
609a718348
Deploy current user-engine provisioning image
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:00:28 +02:00
ba07dd2acb
Add scoped LLDAP identity provisioner
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 00:57:16 +02:00
9a486c3531
Deploy KeyCape-backed portal login edge
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 00:39:22 +02:00
49f727c54c
Deploy internal user-engine portal foundation
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-27 23:24:36 +02:00
11a14648c4
Register rapp-qonto KeyCape client
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-27 20:17:56 +02:00
a9aec541ec
Implement NK-WP-0021 activity-core ops SSO least-privilege.
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
Seed LLDAP activity-core-operators, add membership runbook and helper,
restrict Authelia access on activity/temporal.coulomb.social to that
group (member one_factor + domain deny fallback), apply live, and verify
via Authelia check-policy plus unauthenticated edge redirects.
2026-07-22 15:47:26 +02:00
3875d546bc
Expose OIDC auth mounts to unauthenticated OpenBao UI listing
...
Set listing_visibility=unauth on netkingdom and keycape during OIDC configure
so the browser login mask can select KeyCape instead of falling back to token.
2026-06-19 21:04:31 +02:00
efbdab4652
feat(keycape): add netkingdom OIDC mount and bao.coulomb.social callbacks
...
Configure OpenBao auth for both netkingdom and keycape mounts with browser
redirect URIs; update verify scripts and runtime architecture notes.
2026-06-18 01:23:02 +02:00
92bf7d1d1c
NET-WP-0019: implement T05 (OIDC claims helper + integration in script/console) and T06 (add dry-run to runbook_payloads for web-ui exposure; cross-link update in 0018 T07). Update workplan notes.
2026-06-03 07:10:56 +02:00
23af9b0a84
NET-WP-0019: fix arg parsing in orchestrator for --cleanup-only early, fix delegate path in console cleanup command.
2026-06-03 02:21:22 +02:00
140fff6773
NET-WP-0019: register T06-adjacent polish workplan + implement core (orchestrator script, safer secret fallback in create-user, console dry-run + cleanup commands, make targets, cross-link from 0017 T06). See workplan file for task status.
2026-06-03 02:17:55 +02:00
8a3d7a8aff
chore: make T06 verify scripts executable (chmod +x for check-mfa and keycape-verify used in dry-run evidence)
2026-06-03 02:03:03 +02:00
c48e076429
Close OpenBao OIDC admin bootstrap path
2026-06-01 21:20:53 +02:00
7ce5f5bab0
Simplify KeyCape MFA token refresh
2026-05-29 03:21:58 +02:00
ed991860fa
Fix interactive MFA repair prompt
2026-05-29 03:18:44 +02:00
c7b82df267
Add KeyCape privacyIDEA token repair flow
2026-05-29 03:07:17 +02:00
ab99380dec
Align Authelia KeyCape token auth method
2026-05-29 02:50:29 +02:00
cac59a37c1
openbao and itsec tooling integration
2026-05-27 18:56:30 +02:00
1edcfbb17d
Use helper for OpenBao OIDC auth setup
2026-05-26 03:02:08 +02:00
a47c707a9a
Verify KeyCape discovery without container wget
2026-05-26 02:47:01 +02:00
59c924bc18
Patch KeyCape OpenBao client without bootstrap secrets
2026-05-26 02:36:04 +02:00
1267df148a
Harden KeyCape OpenBao client action
2026-05-26 02:22:24 +02:00
f3c8d70270
Split OpenBao admin identity tasks
2026-05-26 02:13:55 +02:00
dc70cd9fab
Configure KeyCape LLDAP people OU
2026-05-25 00:32:43 +02:00
5af876eb8c
Enable KeyCape bootstrap MFA mode
2026-05-25 00:16:05 +02:00
4cc22bec9e
Record Railiance KeyCape rollout
2026-05-24 18:12:41 +02:00
d555a33695
bootstrapping guidance ui and missing stuff
2026-05-24 17:04:15 +02:00
c054241a5c
feat(t09): backup, break-glass, DR drill — NK-WP-0003-T09 done
...
- Apply SQLite backup CronJobs (LLDAP, Authelia, privacyIDEA) — all verified running
- Fix authelia-backup: remove scale-down/up dance; concurrent local-path PVC mount
works on single-node k3s, sqlite3 .backup is safe for concurrent access
- Fix privacyidea-backup: add supplementalGroups: [999] so uid=1000 can read enckey
- Add allow-backup-to-kube-api NetworkPolicy (backup pod → 10.43.0.1:443)
- Create break-glass LLDAP account (net-kingdom-admins); fix ((PASS++)) set-e trap
- SQLite restore drill: LLDAP backup valid (2 users, all tables)
- verify-t08.sh: PASS=15, FAIL=0; fix counter bug + enckey PVC path (/etc/privacyidea)
- Update DR-RUNBOOK.md Authelia restore procedure
- T09 deferred: CNPG backup (needs MinIO/S3), Prometheus (needs kube-prometheus-stack)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 23:56:40 +00:00
331eeaf378
fix(lldap): fix gql() brace bug + use LDAP for password setting
...
Three fixes:
1. gql() default vars '${2:-{}}' — bash parsed first '}' as closing the
parameter expansion, appending a stray '}' to every caller's vars.
Fixed by storing '{}' in a local variable first.
2. make_vars() — add VAR_INT_KEYS support so groupId is emitted as a
JSON integer (Int!) rather than a string, matching LLDAP's schema.
3. Password setting — LLDAP has no GraphQL mutation for admin password
reset. Replace the broken resetUserPasswordFromAdmin mutation with
an RFC 3062 LDAP Password Modify operation via kubectl port-forward
to the in-cluster LLDAP service, using ldap3.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:49:26 +00:00