feat(signup): participant tier + zero quota + cap secret plumbing (#84, #85) #86

Sammanfogat
supernaut sammanfogade 4 incheckningar från open-registration in i main 2026-07-17 21:25:34 +00:00
Ägare

Infra half of the Open registration epic (bitborg-docs#27, ADR 0029 in the docs PR). Closes #84, closes #85.

  • kanidm: new tier_participant group — the signup default; tier_basic untouched.
  • web role: web_kanidm_tier_group: tier_participant, web_signups_open: "true" (the kill switch becomes real in the bitborg-web PR), CAP_SECRET podman secret (vault_web_cap_secret — mint with openssl rand -base64 32 and vault BEFORE applying).
  • reconciler: ensures zero-quota group participant (single size:all=0 rule, deliberately NO base rule — Forgejo merges overlapping rules most-permissively); precedence ent_lfs_large → ent_lfs → tier_participant → lfs-basic.
  • forgejo: [quota.default] TOTAL -1 → 0 — closes the JIT-login window where a brand-new account had unlimited quota.
  • runbook: kill-switch procedure + participant quota notes.

Apply-day checklist (after merge, via infra-apply)

  • Vault vault_web_cap_secret (the web container fails signup closed without it)
  • Verify every existing account incl. service accounts is in an explicit quota group (GET /api/v1/admin/quota/groups) BEFORE the forgejo tag apply lands quota.default 0
  • Apply kanidm → reconciler → forgejo → web; run the reconciler once and confirm the participant group exists with size:all=0 and no base rule
  • Deploy the bitborg-web PR image before or with this (the app must know the captcha + kill switch)
Infra half of the Open registration epic (bitborg-docs#27, ADR 0029 in the docs PR). Closes #84, closes #85. - **kanidm:** new `tier_participant` group — the signup default; `tier_basic` untouched. - **web role:** `web_kanidm_tier_group: tier_participant`, `web_signups_open: "true"` (the kill switch becomes real in the bitborg-web PR), `CAP_SECRET` podman secret (`vault_web_cap_secret` — mint with `openssl rand -base64 32` and vault BEFORE applying). - **reconciler:** ensures zero-quota group `participant` (single `size:all=0` rule, deliberately NO `base` rule — Forgejo merges overlapping rules most-permissively); precedence `ent_lfs_large → ent_lfs → tier_participant → lfs-basic`. - **forgejo:** `[quota.default] TOTAL -1 → 0` — closes the JIT-login window where a brand-new account had unlimited quota. - **runbook:** kill-switch procedure + participant quota notes. ## Apply-day checklist (after merge, via infra-apply) - [ ] Vault `vault_web_cap_secret` (the web container fails signup closed without it) - [ ] Verify every existing account incl. service accounts is in an explicit quota group (`GET /api/v1/admin/quota/groups`) BEFORE the forgejo tag apply lands quota.default 0 - [ ] Apply kanidm → reconciler → forgejo → web; run the reconciler once and confirm the `participant` group exists with size:all=0 and no base rule - [ ] Deploy the bitborg-web PR image before or with this (the app must know the captcha + kill switch)
supernaut tvångsskickade open-registration från 8da150d5f9
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m29s
till 0d4e0a6d7a
Väntande kontroller
ci / ci (pull_request) Has started running
2026-07-17 20:49:10 +00:00
Jämför
supernaut lade till 1 incheckning 2026-07-17 20:50:41 +00:00
feat(signup): vault cap captcha secret (#84)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m32s
ad97ba60d1
supernaut lade till 1 incheckning 2026-07-17 21:12:17 +00:00
fix(forgejo): revert quota.default to -1 — v16 applies it to ALL users (#85)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m40s
b49280ba39
supernaut sammanfogade incheckning cffe382d73 till main 2026-07-17 21:25:34 +00:00
supernaut tog bort grenen open-registration 2026-07-17 21:25:35 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!86
Ingen beskrivning angiven.