net-kingdom/sso-mfa
Bernd Worsch afbf968c76 fix(privacyidea): bootstrap-realm scope fixes + netpol for PI→LLDAP
bootstrap-realm.sh:
- Remove Content-Type header from GET requests (Werkzeug 3.x BadRequest fix)
- Fix resolver type check — result path is result.value.<name>.type, not .data
- Fix self-enrollment policy scope: 'user' not 'enrollment' (PI 3.12)

NetworkPolicies:
- allow-egress-to-lldap (mfa ns): privacyIDEA → LLDAP :3890
- allow-privacyidea-to-lldap (sso ns): ingress from mfa/privacyIDEA → LLDAP :3890

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:49:26 +00:00
..
bootstrap fix(creds-bootstrap): harden agent bootstrap for non-interactive execution 2026-03-21 12:11:13 +00:00
k8s fix(privacyidea): bootstrap-realm scope fixes + netpol for PI→LLDAP 2026-03-25 11:49:26 +00:00
WORKPLAN.md docs(sso-mfa): record T04 blocker — wrong image reference (ImagePullBackOff) 2026-03-20 17:16:35 +00:00