Skip to content

Harden Keycloak and ops OIDC session flow - #9

Merged
Abiorh001 merged 1 commit into
mainfrom
harden-keycloak-ops-auth
May 29, 2026
Merged

Abiorh001 merged 1 commit into
mainfrom
harden-keycloak-ops-auth

Conversation

@Abiorh001

Copy link
Copy Markdown
Contributor

Summary

  • run bundled Keycloak in production server mode with Postgres storage and strict hostname/proxy settings
  • align Compose Postgres DSNs with the shared password secret and add the Keycloak schema init step
  • clear stale ops OIDC/session cookies on auth callback errors and mark auth redirects no-store
  • add regression coverage for Keycloak Compose wiring, hosted redirects, and OIDC auth-error cleanup

Validation

  • npm test (apps/ops-console)
  • uv run pytest tests/test_hosted_deployment_compose.py -q
  • docker compose -f docker-compose.yml -f infra/compose/docker-compose.e2e-ports.yml config --quiet

Deployment note

Already deployed and smoke-tested on the EC2 alpha stack after the issue was reproduced.

@Abiorh001
Abiorh001 merged commit ef81cd9 into main May 29, 2026
2 checks passed
@Abiorh001
Abiorh001 deleted the harden-keycloak-ops-auth branch May 29, 2026 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant