019e8f21a7
Deploy explicit Railiance admin role mapping for alert receipts
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 12s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
2026-09-28 11:11:34 +02:00
8ad58baa3f
Pin KeyCape main-8be8065 (discovery/JWKS split-horizon headers) as deployed
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Operator-run rollout 2026-09-27: the previous rollout (911e9de) broke
every KeyCape login on Authelia 4.38 -- the provider-metadata/JWKS
discovery fetch used for ID-token verification never carried the
split-horizon X-Forwarded-Proto/Host headers, only the token exchange
did. Fixed in key-cape 8be8065 with a regression test.
Rollback digest: sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
2026-09-27 20:02:49 +02:00
17a66fe236
Pin KeyCape main-911e9de (fresh-MFA freshness fix) as deployed
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Operator-run rollout 2026-09-27: fixes INFD-IN-0005 — completeAuthorization
was reusing an existing kc_login cookie's IssuedAt as authTime even after
a freshly-validated MFA token in the same request, which understated
freshness for downstream binding-grade checks (flex-auth's 900s review
window denied informed-decision's infd-20260927-b01 approval as a result).
See key-cape commit 911e9de and workplans/ADHOC-2026-09-27.md.
Rollback digest: sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
2026-09-27 19:20:06 +02:00
5385880d19
Stage the KeyCape public-origin headers on Authelia 4.38.
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: grok
Assistant-Session: 01a0e27d-3c2d-7571-a4f8-95442f282b6f
2026-09-27 13:52:45 +02:00
c90e751dd2
Pin the KeyCape image that styles the NetKingdom sign-out page.
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
2026-09-27 00:58:25 +02:00
8ee0f8bf04
Pin KeyCape main-11ce29a (fresh-login fix) as deployed
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Operator-run rollout 2026-09-23 of key-cape@11ce29a (KEY-WP-0033-T02):
prompt=login now reaches Authelia as max_age=10 and KeyCape enforces
freshness itself. Post-rollout: verify-openbao-client PASS; Vergabe
callback+PKCE 302, wrong callback 400, missing PKCE 400.
Rollback digest: sha256:db2c5a13a47839049349e881c8d19bc39f720ee69d8518f9f2eba2b1f98af9d5
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 22:12:14 +02:00
444f2b3fc3
Pin approval-clients rollout tests to their pre-rollout fixture
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
deployment.yaml advanced past the one-shot rollout (P05/P06), so the helper
correctly refused it with prior_image_drift and existing_candidate_env. The
fixture now reconstructs the pre-rollout state, and a new test asserts the
helper refuses the current declaration.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 19:56:55 +02:00
3b14469afb
Retire bao.coulomb.social callbacks from the KeyCape openbao-admin client
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
The name was retired on 2026-09-15. Remove both public UI callbacks from
the code-defined client (openbao-client-config.py, create-secrets.sh), stop
probing them in verify-openbao-client.sh, and fail verification in
openbao-client-config.py and verify-t07.sh if either is registered again.
The CLI and operator-tunneled 127.0.0.1:18200 callbacks remain.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 19:41:35 +02:00
a356f640ac
Stop configure-openbao-oidc.sh from writing the platform-admin role
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
The role's policies, callbacks and bound claims are declared centrally by
railiance-platform (openbao/auth/netkingdom-platform-admin-role.json).
Rerunning the script would have dropped the live operator-custody policy
and re-added the retired bao.coulomb.social callbacks. The script now only
configures the OIDC mounts and fails if the declared role is missing.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 19:39:53 +02:00
dc42b0344c
Record canonical portal hostname and callback cutover
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:16:33 +02:00
bea425cf78
Record deployed P06 policy and completed platform acceptance
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:10:26 +02:00
a5496170cf
Implement scoped P06 authentication policy and guarded optional onboarding
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:00:09 +02:00
d1a169dedd
Record verified P05 rollout and service recovery acceptance
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 22:31:16 +02:00
54a47dd810
Record verified enrollment assurance release and automate provider contract tests
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:03:44 +02:00
37b4d70823
Establish scoped KeyCape factor custody and verified automatic renewal
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:25:33 +02:00
5f57e06cf9
Record provider credential renewal release and remaining owner handoff
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 14:27:35 +02:00
0071dba99e
Pin browser-verified account recovery and provider sign-out
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:50:35 +02:00
4d71e1bd16
Record deployed issuer and company-welcome configuration
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 03:12:45 +02:00
ff1b25f515
Prepare pinned company-welcome and shared-issuer rollout patches
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 02:53:55 +02:00
48a75b1a54
Bind password setup grants to approved company welcome pages
...
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 02:43:31 +02:00
6cd89f0a7a
fix: restore native user portal login and track tenant integration
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-11 20:55:30 +02:00
303a584bd0
feat: accept KeyCape approval clients with tested recovery
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 02:18:12 +02:00
ce826cfa8d
feat: exercise contained KeyCape approval client rollout
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 01:32:45 +02:00
ad9979b159
Add contained issuer-only configuration check and revision-guarded pin
...
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 00:23:21 +02:00
4e07d60ff1
Validate cadence contract and require functional MFA verification
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
2026-09-05 01:28:05 +02:00
9781102e29
Deploy KeyCape canonical subject fix
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:03:08 +02:00
61aeafef71
feat(NK-WP-0032): admit OpenBao operator loopback callback
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b90-83bf-75c2-81c8-aa705414e4d4
2026-08-23 14:01:57 +02:00
83508915db
Register app.coulomb.social OIDC redirect for coulomb-social
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Parallel public host while apex stays Bubble; keep apex redirect for later.
2026-08-09 23:20:30 +02:00
0e3a24d888
Deploy KeyCape client MFA override for coulomb-social
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Register coulomb-social with mfaRequired: false, roll key-cape image that
honors client policy, and track NK-WP-0025 public registration orchestration.
2026-08-09 22:42:51 +02:00
27656916db
Add KeyCape client registration for coulomb.social
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Idempotent patch of sso/keycape-config with public PKCE client and
redirect URIs for local :8008 and production coulomb.social callbacks.
2026-08-09 01:50:52 +02:00
2fdf21c379
Deploy platform-root claim mapping
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 21:31:54 +02:00
5b8f52749e
Deploy identity administration lifecycle images
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:30:39 +02:00
9a486c3531
Deploy KeyCape-backed portal login edge
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 00:39:22 +02:00
11a14648c4
Register rapp-qonto KeyCape client
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-27 20:17:56 +02:00
3875d546bc
Expose OIDC auth mounts to unauthenticated OpenBao UI listing
...
Set listing_visibility=unauth on netkingdom and keycape during OIDC configure
so the browser login mask can select KeyCape instead of falling back to token.
2026-06-19 21:04:31 +02:00
efbdab4652
feat(keycape): add netkingdom OIDC mount and bao.coulomb.social callbacks
...
Configure OpenBao auth for both netkingdom and keycape mounts with browser
redirect URIs; update verify scripts and runtime architecture notes.
2026-06-18 01:23:02 +02:00
8a3d7a8aff
chore: make T06 verify scripts executable (chmod +x for check-mfa and keycape-verify used in dry-run evidence)
2026-06-03 02:03:03 +02:00
c48e076429
Close OpenBao OIDC admin bootstrap path
2026-06-01 21:20:53 +02:00
7ce5f5bab0
Simplify KeyCape MFA token refresh
2026-05-29 03:21:58 +02:00
ed991860fa
Fix interactive MFA repair prompt
2026-05-29 03:18:44 +02:00
c7b82df267
Add KeyCape privacyIDEA token repair flow
2026-05-29 03:07:17 +02:00
cac59a37c1
openbao and itsec tooling integration
2026-05-27 18:56:30 +02:00
1edcfbb17d
Use helper for OpenBao OIDC auth setup
2026-05-26 03:02:08 +02:00
a47c707a9a
Verify KeyCape discovery without container wget
2026-05-26 02:47:01 +02:00
59c924bc18
Patch KeyCape OpenBao client without bootstrap secrets
2026-05-26 02:36:04 +02:00
1267df148a
Harden KeyCape OpenBao client action
2026-05-26 02:22:24 +02:00
f3c8d70270
Split OpenBao admin identity tasks
2026-05-26 02:13:55 +02:00
dc70cd9fab
Configure KeyCape LLDAP people OU
2026-05-25 00:32:43 +02:00
5af876eb8c
Enable KeyCape bootstrap MFA mode
2026-05-25 00:16:05 +02:00
4cc22bec9e
Record Railiance KeyCape rollout
2026-05-24 18:12:41 +02:00