Incident 2026-07-17..30: sign-up broken for 13 days — Kanidm entry-manager delegation never followed ADR 0029/0036 #271
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#271
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Incident record, filed retroactively. The outage is resolved and every remediation has shipped;
this issue exists so the incident has a searchable record rather than living only in commit
messages. Filed closed.
Impact
Sign-up was broken in production from 2026-07-17 to 2026-07-30 — 13 days. Every new-user
registration failed. No alert fired; the outage surfaced only because someone tried to register and
said so.
Root cause
The portal adds each new sign-up to Kanidm tier groups. Member-write on those groups is delegated to
idm_bitborg_ent_managersviaentry-managed-by. That delegation was a manualkanidm group set-entry-managerstep — kanidm-provision (pinned) had no ACP support — and it wasrestated in three places that had to agree.
ADR 0029 moved sign-up from
tier_basictotier_participant; ADR 0036 addedtier_trial. Thedelegation followed neither, so the portal was denied member-write on precisely the groups it
writes:
tier_basicent_renovatetier_participanttier_trialforgejo_usersforgejo_userswas a second, independent instance of the same gap — found by the drill writtenduring remediation, not by the original investigation.
Why it went unnoticed for 13 days
site.ymlrun proved nothing about it.permission/config mismatch rather than logic, and there is no Kanidm in the local harness.
generic upstream fault.
Remediation (all shipped)
kanidm_portal_managed_groups) consumed by state, gate and drillscripts/signup-drill.sh+ runbook section "Sign-up is broken (group add -> 404)"entryManagedBy)The manual
set-entry-managerstep no longer exists — #268 removed the class of failure rather thanjust this instance of it.
Verification
Delegations restored in production and confirmed;
pnpm signup:drillpassing; apply-time healthgates green; sign-up verified working end-to-end in production on 2026-07-30.
Follow-up
None outstanding. Retained as evidence for the ISMS incident-management control — see
gitborg/gitborg-docs#30.