docs(runbook): control-panel bitborg-web OAuth2 client bootstrap (#47) #98

Sammanfogat
supernaut sammanfogade 1 incheckning från feat/47-control-panel-kanidm-client in i main 2026-07-18 15:48:03 +00:00
Ägare

Closes #47.

Finding: the code plumbing already exists

The web role already injects the control-panel OIDC config end-to-end, gated on web_auth_enabled (= both vault_web_oidc_client_secret and vault_web_session_secret set):

  • bitborg-web.container.j2: OIDC_ISSUER/CLIENT_ID/REDIRECT_URI/ADMIN_GROUP env + OIDC_CLIENT_SECRET/SESSION_SECRET podman secrets.
  • group_vars: web_oidc_client_id, web_oidc_issuer, web_oidc_admin_group.

So #47's only real gap was the Kanidm bitborg-web OAuth2 client — which, like the Forgejo and Grafana clients, is created out-of-band (the provision state's systems.oauth2 is intentionally empty).

Change

Runbook subsection mirroring the Forgejo bootstrap: create the bitborg-web client (redirect /auth/callback, PKCE on, forgejo_users scope map, groups claim → forgejo_admins = panel admin), vault the client secret + an openssl rand session key, apply --tags web, verify, rotate. Notes the panel stays 404 until both secrets exist, so applying on prod before bootstrap is safe.

Pairs with bitborg-web#36 (JWKS verify + security review — done on branch feat/36-oidc-security-review).

Verification

  • markdownlint clean. No code change (plumbing pre-existed and was re-read to confirm).

Apply-day

Operator runs the Kanidm bootstrap (needs idm_admin), vaults the two secrets, site.yml --tags web. Verify /account login end-to-end.

Closes #47. ## Finding: the code plumbing already exists The web role already injects the control-panel OIDC config end-to-end, gated on `web_auth_enabled` (= both `vault_web_oidc_client_secret` and `vault_web_session_secret` set): - `bitborg-web.container.j2`: `OIDC_ISSUER/CLIENT_ID/REDIRECT_URI/ADMIN_GROUP` env + `OIDC_CLIENT_SECRET`/`SESSION_SECRET` podman secrets. - group_vars: `web_oidc_client_id`, `web_oidc_issuer`, `web_oidc_admin_group`. So #47's only real gap was the **Kanidm `bitborg-web` OAuth2 client** — which, like the Forgejo and Grafana clients, is created out-of-band (the provision state's `systems.oauth2` is intentionally empty). ## Change Runbook subsection mirroring the Forgejo bootstrap: create the `bitborg-web` client (redirect `/auth/callback`, PKCE on, `forgejo_users` scope map, `groups` claim → `forgejo_admins` = panel admin), vault the client secret + an `openssl rand` session key, `apply --tags web`, verify, rotate. Notes the panel stays 404 until both secrets exist, so applying on prod before bootstrap is safe. Pairs with bitborg-web#36 (JWKS verify + security review — done on branch `feat/36-oidc-security-review`). ## Verification - markdownlint clean. No code change (plumbing pre-existed and was re-read to confirm). ## Apply-day Operator runs the Kanidm bootstrap (needs `idm_admin`), vaults the two secrets, `site.yml --tags web`. Verify `/account` login end-to-end.
supernaut tvångsskickade feat/47-control-panel-kanidm-client från 805ba84ac6
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m36s
till 263f331a88
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m39s
2026-07-18 14:58:38 +00:00
Jämför
supernaut tvångsskickade feat/47-control-panel-kanidm-client från 263f331a88
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m39s
till 508237c7ee
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m42s
2026-07-18 15:23:44 +00:00
Jämför
supernaut sammanfogade incheckning 6b1d83e7ce till main 2026-07-18 15:48:03 +00:00
supernaut tog bort grenen feat/47-control-panel-kanidm-client 2026-07-18 15:48:03 +00:00
supernaut ändrade titeln från docs(runbook): control-panel gitborg-web OAuth2 client bootstrap (#47) till docs(runbook): control-panel bitborg-web OAuth2 client bootstrap (#47) 2026-08-03 09:58:44 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!98
Ingen beskrivning angiven.