atlas-iac/services/hermes/agent-certificate.yaml
Hermes Agent 94106bf252 refactor(hermes): rename the owner agent host to worker.bstein.dev
Introduce worker.bstein.dev as the canonical hostname for the owner-only
Hermes coordinator, previously agent.hermes.bstein.dev.

The rename is additive, matching the shape #38 restored for chat and triage.
CoreDNS, both agent Ingresses and the hermes-sites certificate now serve BOTH
names, so merging this cannot take away the endpoint the operator uses to
reach the coordinator. Retiring agent.hermes.bstein.dev is a separate,
separately scheduled change. No redirect middleware is added.

What switches to the new host:
- HERMES_DASHBOARD_PUBLIC_URL and the oauth2-proxy --redirect-url
- the Keycloak agent proxy rootUrl
- operator docs, skills, the ZAP baseline target and the triage monitor default

What stays dual-homed until retirement:
- CoreDNS hosts entry, both agent Ingress rules, certificate SANs
- API_SERVER_CORS_ORIGINS (now a comma-separated pair)
- the Keycloak redirect URIs, web origins and post-logout origins, so a
  rollback only needs the oauth2-proxy --redirect-url reverted and does not
  require re-running the ensure job

The agent client passes its legacy origin through the optional fourth argument
#38 added to ensure_proxy_client, so no second mechanism is introduced. The
immutable ensure Job goes -11 -> -12 because #38 already consumed -11 and that
run has completed; without a further bump this change would never be applied.
Login on the new host fails until the -12 Job completes.

Because the session and CSRF cookies use the __Host- prefix they are bound to
one origin, so a fresh login must start on worker.bstein.dev and existing
sessions do not carry over -- re-login is required after rollout.

#38's public-host continuity test now covers the agent proxy's dual origins
rather than asserting the agent surface was untouched by the rename.

Knowledge catalogs and diagrams regenerated with `make knowledge`.
2026-08-21 10:29:46 +00:00

23 lines
715 B
YAML

# services/hermes/agent-certificate.yaml
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: hermes-sites-tls
namespace: hermes
spec:
secretName: hermes-sites-tls
issuerRef:
kind: ClusterIssuer
name: letsencrypt
dnsNames:
- agent.hermes.bstein.dev
- chat.bstein.dev
- triage.bstein.dev
# Legacy hosts stay on the certificate until they are retired on purpose;
# the rename in #34 must not break links or sessions already in flight.
- chat.hermes.bstein.dev
- triage.hermes.bstein.dev
# worker.bstein.dev is the canonical owner-agent host; the legacy
# agent.hermes.bstein.dev SAN above stays until it is retired on purpose.
- worker.bstein.dev