PR #34 renamed the public chat/triage hosts in hermes_access_oidc_ensure.sh (chat.bstein.dev, triage.bstein.dev) but the last applied hermes-access-oidc-client-ensure Job predates that change, so Keycloak still has the old redirect_uri/webOrigins/rootUrl registered for hermes-chat-proxy and hermes-triage-proxy. Live check confirms Keycloak returns HTTP 400 Invalid parameter: redirect_uri for both new hosts. Bump the Job name to force Flux to recreate the (immutable) Job and rerun the ensure script, matching this repo's established retry convention for this Job (ensure-7..ensure-10). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%