fix(kanidm): decouple the tile icon from branding, rename the dev tile #287

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/285-286-kanidm-tile-followups in i main 2026-07-31 19:13:25 +00:00
Ägare

Closes #285, closes #286. Both follow-ups from the sign-up journey epic's final review.

#285 — a cosmetic switch could abort identity provisioning

The tile icon added in #284 was mounted straight out of the branding overlay directory, whose contents are staged only when: kanidm_custom_branding — while image_file was declared unconditionally.

Set that flag false, which is a reasonable move when debugging a Kanidm upgrade to rule out our CSS and asset overrides, and:

  1. the icon is never staged, so the host path does not exist;
  2. rootless podman creates the missing bind-mount source as a directory;
  3. kanidm-provision fails reading it and the error propagates;
  4. the entire kanidm converge aborts — entitlement groups, the forgejo claim maps, all four OAuth2 clients, and the account-policy gate with them.

Production was never at risk (the default is true and nothing overrides it), but a theming switch taking out identity provisioning, several steps removed from the symptom, is a bad trap to leave armed.

Fixed by separating the concerns rather than gating them together. hpkg/img is Kanidm's UI theming and genuinely optional. A tile icon is functional client metadata that bitborg-web's sign-up email instructs users to click ("choose Bitborg to finish setting up"), so it is load-bearing for onboarding and must survive theming being switched off. It now stages to its own ungated directory, kanidm_oauth2_icon_dir.

The alternative — gating image_file on the same flag — would have kept the coupling and just made the failure quieter.

#286 — the fourth tile kept the old convention

bitborg-web-dev still read bitborg portal (dev) after the other three were renamed: lowercase brand against the style guide, and "portal", the internal name the bitborg-web rename removed. Now Bitborg (local development).

Admin-only (scope-mapped to forgejo_admins) and cosmetic. Worth fixing anyway because the premise of #284 was that these tiles are user-facing copy rather than configuration strings — leaving one un-reviewed beside three reviewed ones just leaves the next reader guessing which convention is intended.

Verification

--syntax-check clean; ansible-lint roles/kanidm/ passes on the production profile.

Dry-run --check --diff --tags kanidm: changed=3

  • Create the OAuth2 tile icon directory and Stage the OAuth2 tile icon — first run only, idempotent after
  • Render the kanidm provisioning state — whose only diff is the dev display name:
-        "displayName": "bitborg portal (dev)",
+        "displayName": "Bitborg (local development)",

imageFile is untouched because the in-container path (/icons/logo-square.svg) is unchanged — only the host side of the mount moved. Origins, scope maps and all seven forgejo claim maps are untouched. Both gates pass in the dry-run.

Post-apply check

kanidm system oauth2 list — confirm the dev tile reads Bitborg (local development) and that forgejo still shows its icon and seven claim maps.

Optionally, the thing this PR is actually about: run a converge with -e kanidm_custom_branding=false and confirm it now completes instead of aborting.

Closes #285, closes #286. Both follow-ups from the sign-up journey epic's final review. ## #285 — a cosmetic switch could abort identity provisioning The tile icon added in #284 was mounted straight out of the branding overlay directory, whose contents are staged only `when: kanidm_custom_branding` — while `image_file` was declared unconditionally. Set that flag false, which is a reasonable move when debugging a Kanidm upgrade to rule out our CSS and asset overrides, and: 1. the icon is never staged, so the host path does not exist; 2. rootless podman creates the missing bind-mount source as a **directory**; 3. `kanidm-provision` fails reading it and the error propagates; 4. the **entire kanidm converge aborts** — entitlement groups, the forgejo claim maps, all four OAuth2 clients, and the account-policy gate with them. Production was never at risk (the default is `true` and nothing overrides it), but a theming switch taking out identity provisioning, several steps removed from the symptom, is a bad trap to leave armed. **Fixed by separating the concerns rather than gating them together.** `hpkg/img` is Kanidm's UI theming and genuinely optional. A tile icon is functional client metadata that bitborg-web's sign-up email instructs users to click ("choose **Bitborg** to finish setting up"), so it is load-bearing for onboarding and must survive theming being switched off. It now stages to its own ungated directory, `kanidm_oauth2_icon_dir`. The alternative — gating `image_file` on the same flag — would have kept the coupling and just made the failure quieter. ## #286 — the fourth tile kept the old convention `bitborg-web-dev` still read `bitborg portal (dev)` after the other three were renamed: lowercase brand against the style guide, and "portal", the internal name the `bitborg-web` rename removed. Now **`Bitborg (local development)`**. Admin-only (scope-mapped to `forgejo_admins`) and cosmetic. Worth fixing anyway because the premise of #284 was that these tiles are user-facing copy rather than configuration strings — leaving one un-reviewed beside three reviewed ones just leaves the next reader guessing which convention is intended. ## Verification `--syntax-check` clean; `ansible-lint roles/kanidm/` passes on the production profile. Dry-run `--check --diff --tags kanidm`: **changed=3** - `Create the OAuth2 tile icon directory` and `Stage the OAuth2 tile icon` — first run only, idempotent after - `Render the kanidm provisioning state` — whose **only** diff is the dev display name: ``` - "displayName": "bitborg portal (dev)", + "displayName": "Bitborg (local development)", ``` `imageFile` is untouched because the in-container path (`/icons/logo-square.svg`) is unchanged — only the host side of the mount moved. Origins, scope maps and all seven `forgejo` claim maps are untouched. Both gates pass in the dry-run. ## Post-apply check `kanidm system oauth2 list` — confirm the dev tile reads `Bitborg (local development)` and that `forgejo` still shows its icon and seven claim maps. Optionally, the thing this PR is actually about: run a converge with `-e kanidm_custom_branding=false` and confirm it now completes instead of aborting.
supernaut lade till 1 incheckning 2026-07-31 18:50:18 +00:00
fix(kanidm): decouple the tile icon from branding, rename the dev tile
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m31s
4be6b7e9ce
Closes #285, closes #286.

#285: the tile icon was mounted straight out of the branding overlay directory,
whose contents are staged only when kanidm_custom_branding is true, while
image_file was declared unconditionally. Setting that flag false — a reasonable
step when debugging a Kanidm upgrade, to rule out our CSS and asset overrides —
left the mount source missing, so rootless podman created it as a DIRECTORY,
kanidm-provision failed reading it, and the whole kanidm converge aborted:
entitlement groups, the forgejo claim maps, every OAuth2 client and the
account-policy gate with them. A cosmetic switch took out identity provisioning,
several steps removed from the symptom.

Fixed by separating the two concerns rather than gating them together. hpkg/img is
Kanidm's UI theming and genuinely optional; a tile icon is functional client
metadata that gitborg-web's sign-up email instructs users to click, so it is
load-bearing for onboarding and must survive theming being switched off. It now
stages to its own ungated directory, kanidm_oauth2_icon_dir.

#286: the dev client still read "gitborg portal (dev)" after the other three were
renamed — lowercase brand against the style guide, and "portal", the internal name
the gitborg-web rename removed. Now "Gitborg (local development)". Admin-only and
cosmetic, but these tiles are user-facing copy rather than configuration strings,
and one un-reviewed exception beside three reviewed ones just leaves the next
reader guessing which convention is intended.

Dry-run: changed=3 — the new icon directory and stage (first run only; idempotent
after), plus the state render whose ONLY diff is the dev display name. imageFile is
untouched because the in-container path is unchanged; origins, scope maps and all
seven forgejo claim maps are untouched.
supernaut sammanfogade incheckning be8e87b788 till main 2026-07-31 19:13:25 +00:00
supernaut tog bort grenen fix/285-286-kanidm-tile-followups 2026-07-31 19:13:25 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!287
Ingen beskrivning angiven.