docs(identity): record verified live upstream issuer and completed cleanup
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-08 23:50:55 +02:00
parent a94d06dbcf
commit 8f40d73d0f
3 changed files with 157 additions and 7 deletions

View file

@ -113,13 +113,13 @@ Prerequisites before the window opens:
2. KeyCape image that reads both environment names is **built and pinned, not
deployed**. `main-153258b` is not that image.
3. Founder available for the attended OpenBao session.
4. **The Authelia issuer precondition from KeyCape message
`c8b1ad10-dae8-48fb-a0ea-7e2a101c54bf` is settled first.** The same rollout
that lands these clients also lands upstream ID-token verification that fails
closed on issuer mismatch. Confirm the `iss` value and pin `authelia.issuer`
in the KeyCape config secret before, not during, this window. A broken human
login and a broken client registration arriving together would be very hard to
tell apart.
4. **The actual signed issuer is verified as `https://auth.coulomb.social`.**
The admitted probe passed signature/audience/time/nonce verification on
2026-09-08 at 21:44:44 UTC, exited 0 and removed every temporary resource.
[Receipt](../evidence/2026-09-08-keycape-upstream-issuer-proof.json).
The configuration owner must still ensure `authelia.issuer` is pinned to
that exact value before this window. The probe left normal configuration
unchanged. Keep the existing-human-login regression in the rollout checks.
In-window order: