net-kingdom/sso-mfa/k8s/lldap/OPERATOR-GROUPS.md
tegwick a9aec541ec
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s
Implement NK-WP-0021 activity-core ops SSO least-privilege.
Seed LLDAP activity-core-operators, add membership runbook and helper,
restrict Authelia access on activity/temporal.coulomb.social to that
group (member one_factor + domain deny fallback), apply live, and verify
via Authelia check-policy plus unauthenticated edge redirects.
2026-07-22 15:47:26 +02:00

3.2 KiB

Operator groups — membership runbook

Least-privilege app-scoped LLDAP groups that gate browser SSO via Authelia domain rules. Distinct from platform groups (net-kingdom-users / net-kingdom-admins).

Groups

Group Gates (Authelia) Who belongs
activity-core-operators activity.coulomb.social, temporal.coulomb.social Named founders / platform operators who need the activity-core ops console or Temporal UI

Do not auto-add everyone in net-kingdom-admins. Membership is a conscious grant. Platform admin ≠ activity-core operator.

Seed empty groups with ./bootstrap-users.sh (idempotent). Authelia config: sso-mfa/k8s/authelia/configmap.yaml (access_control.rules).

WebUI path

  1. Open https://lldap.coulomb.social (IP-restricted admin UI).
  2. Sign in as admin (password from KeePassXC / custody — never commit it).
  3. Groupsactivity-core-operators → add or remove members.
  4. User must already exist (create via WebUI or ./create-user.sh).
  5. User re-authenticates at Authelia if an old session lacks the group claim (sign out / new browser session).

Scripted path

cd sso-mfa/k8s/lldap

# Add a user to the operator group
./manage-group-members.sh add <uid> activity-core-operators

# Remove
./manage-group-members.sh remove <uid> activity-core-operators

# List members
./manage-group-members.sh list activity-core-operators

Defaults: LLDAP URL https://lldap.coulomb.social, secrets from ../../bootstrap/secrets/lldap/secrets.env. Override:

./manage-group-members.sh add bernd activity-core-operators \
  https://lldap.coulomb.social /path/to/secrets

Live ops without a local secrets file: export LLDAP_ADMIN_PASS from the cluster secret (operator workstation only; do not log or commit):

export LLDAP_ADMIN_PASS="$(kubectl get secret -n sso lldap-secrets \
  -o jsonpath='{.data.LLDAP_LDAP_USER_PASS}' | base64 -d)"
# manage-group-members.sh also accepts LLDAP_ADMIN_PASS when secrets.env is absent

Onboarding checklist (activity-core ops)

  1. User has LLDAP account and is in net-kingdom-users (normal onboarding).
  2. Operator adds them to activity-core-operators (WebUI or script).
  3. User signs in at https://auth.coulomb.social (password; MFA via KeyCape path when using OIDC apps — ForwardAuth to ops hosts uses Authelia session).
  4. Open https://activity.coulomb.social and https://temporal.coulomb.social — both should pass only for group members.
  5. Offboard: remove from activity-core-operators first; full account offboard remains the platform lifecycle path.

Break-glass (independent of this group)

activity-core ClusterIP port-forward + ACTIVITY_CORE_OPERATOR_TOKEN does not use Authelia groups. Documented in activity-core runbooks. Keep that path for SSO outages; do not gate break-glass on LLDAP group membership.

Adding a future app-operator group

  1. Add the group name to REQUIRED_GROUPS in bootstrap-users.sh.
  2. Document it in this table.
  3. Add Authelia domain rules (member one_factor + domain deny fallback) in sso-mfa/k8s/authelia/configmap.yaml — see Authelia README.
  4. Never invent a KeyCape OIDC client solely for Traefik ForwardAuth apps.