hermes: restore legacy chat/triage hosts alongside the renamed ones
PR #34 renamed the public chat/triage hosts in place rather than adding the new names, so chat.hermes.bstein.dev and triage.hermes.bstein.dev were dropped from the certificate SANs, the hermes-sites Ingress rules and the CoreDNS overrides at once. Both legacy hosts now answer 404 with Traefik's default self-signed certificate, and the renamed hosts cannot complete a login because the Keycloak clients still carry the old redirect URIs, so chat and triage are unreachable on every hostname. Make the rename additive, which is the rollback path the post-merge runbook asks for when the OIDC step fails: - put the legacy names back on hermes-sites-tls and on the Ingress, pointing at the same oauth2-proxy backends - restore both CoreDNS host overrides for in-cluster resolution - teach ensure_proxy_client to register an optional legacy origin, so hermes-chat-proxy and hermes-triage-proxy accept the old and new redirect URIs, web origins and post-logout origins at the same time while rootUrl stays on the canonical new host - bump the immutable ensure Job so Flux reruns the script Serving both names is deliberate: oauth2-proxy cookies are host-bound, so redirecting the legacy hosts would silently drop live sessions. Retiring them stays a separate, explicit change. Supersedes #36, which only bumped the Job and would have left the legacy hosts dark. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e3de466ad1
commit
f4f51323f6
@ -19,6 +19,7 @@ data:
|
||||
192.168.22.9 cd.bstein.dev
|
||||
192.168.22.9 chat.ai.bstein.dev
|
||||
192.168.22.9 chat.bstein.dev
|
||||
192.168.22.9 chat.hermes.bstein.dev
|
||||
192.168.22.9 ci.bstein.dev
|
||||
192.168.22.9 cloud.bstein.dev
|
||||
192.168.22.9 health.bstein.dev
|
||||
@ -46,6 +47,7 @@ data:
|
||||
192.168.22.9 wolf.bstein.dev
|
||||
192.168.22.9 tasks.bstein.dev
|
||||
192.168.22.9 triage.bstein.dev
|
||||
192.168.22.9 triage.hermes.bstein.dev
|
||||
192.168.22.9 vault.bstein.dev
|
||||
fallthrough
|
||||
}
|
||||
|
||||
@ -13,3 +13,7 @@ spec:
|
||||
- agent.hermes.bstein.dev
|
||||
- chat.bstein.dev
|
||||
- triage.bstein.dev
|
||||
# Legacy hosts stay on the certificate until they are retired on purpose;
|
||||
# the rename in #34 must not break links or sessions already in flight.
|
||||
- chat.hermes.bstein.dev
|
||||
- triage.hermes.bstein.dev
|
||||
|
||||
@ -90,6 +90,8 @@ spec:
|
||||
- agent.hermes.bstein.dev
|
||||
- chat.bstein.dev
|
||||
- triage.bstein.dev
|
||||
- chat.hermes.bstein.dev
|
||||
- triage.hermes.bstein.dev
|
||||
secretName: hermes-sites-tls
|
||||
rules:
|
||||
- host: chat.bstein.dev
|
||||
@ -112,3 +114,26 @@ spec:
|
||||
name: oauth2-proxy-hermes-triage
|
||||
port:
|
||||
name: http
|
||||
# Legacy hosts serve the same backends so the rename is additive. They are
|
||||
# kept until an explicit retirement change, not redirected: oauth2-proxy
|
||||
# cookies are host-bound, so a redirect would silently drop the session.
|
||||
- host: chat.hermes.bstein.dev
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: oauth2-proxy-hermes-chat
|
||||
port:
|
||||
name: http
|
||||
- host: triage.hermes.bstein.dev
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: oauth2-proxy-hermes-triage
|
||||
port:
|
||||
name: http
|
||||
|
||||
@ -3,7 +3,7 @@
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: hermes-access-oidc-client-ensure-10
|
||||
name: hermes-access-oidc-client-ensure-11
|
||||
namespace: sso
|
||||
spec:
|
||||
backoffLimit: 3
|
||||
|
||||
@ -84,10 +84,24 @@ ensure_proxy_client() {
|
||||
client_id="$1"
|
||||
public_url="$2"
|
||||
vault_path="$3"
|
||||
# Optional legacy host kept registered alongside the canonical one during a
|
||||
# hostname rename. Keycloak matches redirect_uri exactly, so dropping the old
|
||||
# entry turns every in-flight login into "Invalid parameter: redirect_uri".
|
||||
legacy_url="${4:-}"
|
||||
if [ -n "${legacy_url}" ]; then
|
||||
origins="$(jq -nc --arg a "${public_url}" --arg b "${legacy_url}" '[$a,$b]')"
|
||||
else
|
||||
origins="$(jq -nc --arg a "${public_url}" '[$a]')"
|
||||
fi
|
||||
redirect_uris="$(printf '%s' "${origins}" | jq -c 'map(. + "/oauth2/callback")')"
|
||||
# Keycloak takes post-logout origins as one "##"-delimited string.
|
||||
post_logout="$(printf '%s' "${origins}" | jq -r 'join("##")')"
|
||||
payload="$(jq -nc \
|
||||
--arg client_id "${client_id}" \
|
||||
--arg redirect_uri "${public_url}/oauth2/callback" \
|
||||
--argjson redirect_uris "${redirect_uris}" \
|
||||
--argjson web_origins "${origins}" \
|
||||
--arg web_origin "${public_url}" \
|
||||
--arg post_logout "${post_logout}" \
|
||||
'{
|
||||
clientId:$client_id,
|
||||
name:$client_id,
|
||||
@ -98,13 +112,13 @@ ensure_proxy_client() {
|
||||
implicitFlowEnabled:false,
|
||||
directAccessGrantsEnabled:false,
|
||||
serviceAccountsEnabled:false,
|
||||
redirectUris:[$redirect_uri],
|
||||
webOrigins:[$web_origin],
|
||||
redirectUris:$redirect_uris,
|
||||
webOrigins:$web_origins,
|
||||
rootUrl:$web_origin,
|
||||
baseUrl:"/",
|
||||
attributes:{
|
||||
"pkce.code.challenge.method":"S256",
|
||||
"post.logout.redirect.uris":$web_origin,
|
||||
"post.logout.redirect.uris":$post_logout,
|
||||
"access.token.lifespan":"1200"
|
||||
}
|
||||
}')"
|
||||
@ -327,8 +341,10 @@ ensure_telegram_config() {
|
||||
}
|
||||
|
||||
ensure_hermes_owner
|
||||
ensure_proxy_client "hermes-chat-proxy" "https://chat.bstein.dev" "hermes/chat-oidc"
|
||||
ensure_proxy_client "hermes-chat-proxy" "https://chat.bstein.dev" "hermes/chat-oidc" \
|
||||
"https://chat.hermes.bstein.dev"
|
||||
ensure_proxy_client "hermes-agent-proxy" "https://agent.hermes.bstein.dev" "hermes/agent-oidc"
|
||||
ensure_proxy_client "hermes-triage-proxy" "https://triage.bstein.dev" "hermes/triage-oidc"
|
||||
ensure_proxy_client "hermes-triage-proxy" "https://triage.bstein.dev" "hermes/triage-oidc" \
|
||||
"https://triage.hermes.bstein.dev"
|
||||
ensure_service_account_client "hermes-automation" "hermes/developer-keycloak"
|
||||
ensure_telegram_config
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user