fix(kanidm): decouple the tile icon from branding, rename the dev tile #287
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!287
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/285-286-kanidm-tile-followups"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #285, closes #286. Both follow-ups from the sign-up journey epic's final review.
#285 — a cosmetic switch could abort identity provisioning
The tile icon added in #284 was mounted straight out of the branding overlay directory, whose contents are staged only
when: kanidm_custom_branding— whileimage_filewas declared unconditionally.Set that flag false, which is a reasonable move when debugging a Kanidm upgrade to rule out our CSS and asset overrides, and:
kanidm-provisionfails reading it and the error propagates;Production was never at risk (the default is
trueand nothing overrides it), but a theming switch taking out identity provisioning, several steps removed from the symptom, is a bad trap to leave armed.Fixed by separating the concerns rather than gating them together.
hpkg/imgis Kanidm's UI theming and genuinely optional. A tile icon is functional client metadata that bitborg-web's sign-up email instructs users to click ("choose Bitborg to finish setting up"), so it is load-bearing for onboarding and must survive theming being switched off. It now stages to its own ungated directory,kanidm_oauth2_icon_dir.The alternative — gating
image_fileon the same flag — would have kept the coupling and just made the failure quieter.#286 — the fourth tile kept the old convention
bitborg-web-devstill readbitborg portal (dev)after the other three were renamed: lowercase brand against the style guide, and "portal", the internal name thebitborg-webrename removed. NowBitborg (local development).Admin-only (scope-mapped to
forgejo_admins) and cosmetic. Worth fixing anyway because the premise of #284 was that these tiles are user-facing copy rather than configuration strings — leaving one un-reviewed beside three reviewed ones just leaves the next reader guessing which convention is intended.Verification
--syntax-checkclean;ansible-lint roles/kanidm/passes on the production profile.Dry-run
--check --diff --tags kanidm: changed=3Create the OAuth2 tile icon directoryandStage the OAuth2 tile icon— first run only, idempotent afterRender the kanidm provisioning state— whose only diff is the dev display name:imageFileis untouched because the in-container path (/icons/logo-square.svg) is unchanged — only the host side of the mount moved. Origins, scope maps and all sevenforgejoclaim maps are untouched. Both gates pass in the dry-run.Post-apply check
kanidm system oauth2 list— confirm the dev tile readsBitborg (local development)and thatforgejostill shows its icon and seven claim maps.Optionally, the thing this PR is actually about: run a converge with
-e kanidm_custom_branding=falseand confirm it now completes instead of aborting.