kanidm: the tile icon mount is unconditional but its source is branding-gated, so disabling branding aborts the converge #285
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#285
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The icon mount added for the dashboard brand mark (#284) is unconditional, but the file it mounts is staged only when branding is enabled. With
kanidm_custom_branding: falsethe whole kanidm converge aborts.The coupling
roles/kanidm/tasks/main.ymlmounts the icon into the provisioning container unconditionally:But that path is only populated by
Stage Kanidm branding graphics + fonts, which is gated:And
image_file: "/icons/logo-square.svg"is declared unconditionally on theforgejoclient indefaults/main.yml.Failure scenario
Set
kanidm_custom_branding: false— a plausible step when debugging a Kanidm upgrade, to rule out our CSS and asset overrides. Then:kanidm-provisionreadsimage_file, fails on the read, and the error propagates.So a debugging aid turns into a broken identity converge, and the cause (a missing icon) is several steps removed from the symptom.
Production is unaffected today: the default is
trueand nothing overrides it. This is a latent trap, not a live fault.Fix options
image_fileon the same flag — the client declaration only carries the key when branding is on. Keeps the two facts together, but puts Jinja conditionals into the client list.Option 2 is probably right: the tile icon is load-bearing for the sign-up journey (the email tells users to choose that tile), so it should not disappear when someone turns off cosmetic theming.
Done when
kanidm_custom_branding: falseproduces a successful kanidm converge, with or without the tile icon.