• Joined on 2025-03-24
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 18:49:35 +00:00
940e0cc613 communication: wire MAS secrets via init render
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 18:44:32 +00:00
45f62bc331 communication: fix MAS config permissions
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 18:41:29 +00:00
d9c003ce5a communication: fix MAS container entrypoint
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 18:38:05 +00:00
716059d9ac communication: add matrix-authentication-service
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 18:23:30 +00:00
6203faae3f communication: make pin job mutable
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 18:16:09 +00:00
d8d741bbd9 communication: remove plaintext secrets
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 16:49:56 +00:00
aca05266fc comms: avoid Synapse PVC rollout deadlock
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 16:43:36 +00:00
ee6bcec3c5 chat.ai: gate root with API key
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 16:25:55 +00:00
a815322f6e comms: move LiveKit media to UDP 443
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 15:17:04 +00:00
5ed650d19c communication: prune guest-helper and synapse-federation
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 15:15:23 +00:00
6759817518 communication: stage guest-helper for prune
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 15:12:00 +00:00
71c58ee081 communication: disable livekit room auto-create
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-31 15:00:28 +00:00
a6bd6b8cc8 communication: add Othrys stack via Flux
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 19:57:54 +00:00
c0a53e59b5 jitsi-launcher: add oauth2-proxy error middleware for redirects
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 19:54:46 +00:00
c9ebcfc869 jitsi-launcher: allow any authenticated user (no group gate)
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 19:40:49 +00:00
0e3d36a5ae jitsi-launcher: add health endpoint and readiness
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 19:35:56 +00:00
a8fdcc5931 jitsi-launcher: pull image from docker hub
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 19:34:06 +00:00
a55203a909 jitsi: add vault-backed jwt launcher
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 06:43:32 +00:00
77ecf3229e vault: use dedicated service account for k8s auth
bstein pushed to feature/sso-hardening at bstein/titan-iac 2025-12-25 06:37:07 +00:00
bb93f730d5 jitsi: fix secrets-store csi driver name