8ad58baa3f
Pin KeyCape main-8be8065 (discovery/JWKS split-horizon headers) as deployed
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Operator-run rollout 2026-09-27: the previous rollout (911e9de) broke
every KeyCape login on Authelia 4.38 -- the provider-metadata/JWKS
discovery fetch used for ID-token verification never carried the
split-horizon X-Forwarded-Proto/Host headers, only the token exchange
did. Fixed in key-cape 8be8065 with a regression test.
Rollback digest: sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
2026-09-27 20:02:49 +02:00
17a66fe236
Pin KeyCape main-911e9de (fresh-MFA freshness fix) as deployed
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Operator-run rollout 2026-09-27: fixes INFD-IN-0005 — completeAuthorization
was reusing an existing kc_login cookie's IssuedAt as authTime even after
a freshly-validated MFA token in the same request, which understated
freshness for downstream binding-grade checks (flex-auth's 900s review
window denied informed-decision's infd-20260927-b01 approval as a result).
See key-cape commit 911e9de and workplans/ADHOC-2026-09-27.md.
Rollback digest: sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
2026-09-27 19:20:06 +02:00
5385880d19
Stage the KeyCape public-origin headers on Authelia 4.38.
...
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: grok
Assistant-Session: 01a0e27d-3c2d-7571-a4f8-95442f282b6f
2026-09-27 13:52:45 +02:00
c90e751dd2
Pin the KeyCape image that styles the NetKingdom sign-out page.
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
2026-09-27 00:58:25 +02:00
8ee0f8bf04
Pin KeyCape main-11ce29a (fresh-login fix) as deployed
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Operator-run rollout 2026-09-23 of key-cape@11ce29a (KEY-WP-0033-T02):
prompt=login now reaches Authelia as max_age=10 and KeyCape enforces
freshness itself. Post-rollout: verify-openbao-client PASS; Vergabe
callback+PKCE 302, wrong callback 400, missing PKCE 400.
Rollback digest: sha256:db2c5a13a47839049349e881c8d19bc39f720ee69d8518f9f2eba2b1f98af9d5
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
2026-09-23 22:12:14 +02:00
bea425cf78
Record deployed P06 policy and completed platform acceptance
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 00:10:26 +02:00
d1a169dedd
Record verified P05 rollout and service recovery acceptance
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 22:31:16 +02:00
54a47dd810
Record verified enrollment assurance release and automate provider contract tests
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 17:03:44 +02:00
37b4d70823
Establish scoped KeyCape factor custody and verified automatic renewal
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:25:33 +02:00
5f57e06cf9
Record provider credential renewal release and remaining owner handoff
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 14:27:35 +02:00
0071dba99e
Pin browser-verified account recovery and provider sign-out
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 10:50:35 +02:00
4d71e1bd16
Record deployed issuer and company-welcome configuration
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-12 03:12:45 +02:00
303a584bd0
feat: accept KeyCape approval clients with tested recovery
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-09 02:18:12 +02:00
9781102e29
Deploy KeyCape canonical subject fix
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:03:08 +02:00
0e3a24d888
Deploy KeyCape client MFA override for coulomb-social
...
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Register coulomb-social with mfaRequired: false, roll key-cape image that
honors client policy, and track NK-WP-0025 public registration orchestration.
2026-08-09 22:42:51 +02:00
2fdf21c379
Deploy platform-root claim mapping
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-29 21:31:54 +02:00
5b8f52749e
Deploy identity administration lifecycle images
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 01:30:39 +02:00
9a486c3531
Deploy KeyCape-backed portal login edge
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
2026-07-28 00:39:22 +02:00
11a14648c4
Register rapp-qonto KeyCape client
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
2026-07-27 20:17:56 +02:00
c48e076429
Close OpenBao OIDC admin bootstrap path
2026-06-01 21:20:53 +02:00
dc70cd9fab
Configure KeyCape LLDAP people OU
2026-05-25 00:32:43 +02:00
5af876eb8c
Enable KeyCape bootstrap MFA mode
2026-05-25 00:16:05 +02:00
4cc22bec9e
Record Railiance KeyCape rollout
2026-05-24 18:12:41 +02:00
880f89bf98
fix(keycape): NK-WP-0003-T07 — fix deployment image + add demo-app client
...
- deployment.yaml: image → 92.205.130.254:32166/coulomb/key-cape:latest
(Gitea OCI registry, delivered by KEY-WP-0002; imagePullPolicy: Always)
- k3s insecure registry hosts.toml: fixed server endpoint to http:// so
containerd does not attempt HTTPS against the plain-HTTP Gitea NodePort
- create-secrets.sh: add demo-app OIDC client (required for KeyCape to
start; also needed for T08 acceptance tests)
- keycape-config Secret updated in-place (no re-bootstrap needed)
KeyCape pod 1/1 Running; /healthz OK; OIDC discovery live at
https://kc.coulomb.social/.well-known/openid-configuration
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-22 00:30:58 +00:00
0754dc32e6
feat(sso-mfa): T05 SSO stack pivot — Keycloak → Authelia + LLDAP + KeyCape (NK-WP-0001-T05)
...
Replaces the Keycloak+privacyIDEA SSO tier with the lightweight stack built
during KEY-WP-0001: Authelia (password frontend), LLDAP (directory), and
KeyCape (OIDC orchestration). privacyIDEA is retained as the MFA engine.
Stack:
kc.coulomb.social — KeyCape OIDC server (stateless, custom Go)
auth.coulomb.social — Authelia login portal (password auth → Authelia OIDC → KeyCape)
lldap.coulomb.social — LLDAP admin UI (IP-restricted)
pink.coulomb.social — privacyIDEA MFA engine (unchanged)
Changes:
- Remove sso-mfa/k8s/keycloak/ (7 files)
- Add sso-mfa/k8s/lldap/ (pvc, deployment, middleware, ingress, create-secrets, README)
- Add sso-mfa/k8s/authelia/ (pvc, configmap, deployment, ingress, create-secrets, README)
- Add sso-mfa/k8s/keycape/ (deployment, middleware, ingress, create-secrets, create-pi-token, README)
- Update network-policies/netpol-sso.yaml for new component topology
- Update verify-t05.sh: checks LLDAP + Authelia + KeyCape (23 checks)
- Update CONFIG.md: fix CP-NK-004 (KeyCape), add CP-NK-005 (Authelia), CP-NK-006 (LLDAP)
- Update bootstrap/gen-secrets.sh: add LLDAP/Authelia/KeyCape sections, remove Keycloak
- Update k8s/README.md: network policy table reflects new traffic paths
- Add sso-mfa/WORKPLAN.md: resumable task checklist
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-19 08:31:51 +00:00