Compare commits
merge into: eho/register-referentie:feat/demo-otp-autofill
eho/register-referentie:main
eho/register-referentie:fix/keycloak-proxy-headers
eho/register-referentie:feat/demo-otp-autofill
eho/register-referentie:fix/182-celery-concurrency
eho/register-referentie:feat/public-host-caddy
eho/register-referentie:ci/175-deploy-on-merge
eho/register-referentie:feat/177-public-tls-edge
eho/register-referentie:ci/168-helm-chart-ci-gate
eho/register-referentie:docs/169-mkdocs-nav
eho/register-referentie:feat/25-helm-kubernetes-caddy
eho/register-referentie:fix/161-e2e-bounded-and-diagnosable
eho/register-referentie:feat/162-werkbak-live-refresh
eho/register-referentie:feat/132-medewerker-mfa
eho/register-referentie:fix/156-tempo-ingester-healthcheck
eho/register-referentie:feat/153-projection-sourced-from-objecten
eho/register-referentie:feat/152-objecten-publishes-to-nrc
eho/register-referentie:feat/149-acl-writes-registerrecord
eho/register-referentie:feat/141-registerrecord-objecttype
eho/register-referentie:perf/verify-stack-uwsgi-oz-nrc
eho/register-referentie:fix/144-verify-stack-uwsgi
eho/register-referentie:feat/140-objecten-up
eho/register-referentie:feat/139-objecttypen-up
eho/register-referentie:feat/131-default-fill-crud
eho/register-referentie:chore/136-ci-job-summaries
eho/register-referentie:fix/134-verify-stack-scheduling
eho/register-referentie:feat/130-beheer-catalogi
eho/register-referentie:feat/124-metrics-dashboards
eho/register-referentie:ci/127-parallel-jobs
eho/register-referentie:feat/123-distributed-traces
eho/register-referentie:feat/111-self-service-resume
eho/register-referentie:feat/113-acl-zaaktype-by-identificatie
eho/register-referentie:fix/110-compose-local-flow
eho/register-referentie:fix/115-e2e-single-worker
eho/register-referentie:docs/111-backlog-s26
eho/register-referentie:feat/106-close-zaak-on-timeout
eho/register-referentie:feat/103-diploma-upload-documenten
eho/register-referentie:feat/102-document-wait-timeout
eho/register-referentie:feat/14-dmn-diploma-eligibility
eho/register-referentie:feat/15-beoordeling-escalation
eho/register-referentie:fix/portal-nginx-resolver
eho/register-referentie:fix/local-eventsubscriber-acl
eho/register-referentie:feat/12-withdrawal-portal
eho/register-referentie:fix/91-local-compose-parity
eho/register-referentie:feat/12-withdrawal-bff
eho/register-referentie:feat/12-withdrawal-workflow
eho/register-referentie:feat/12-withdrawal
eho/register-referentie:feat/13-behandel-portal
eho/register-referentie:feat/13-behandel-decide
eho/register-referentie:feat/13-behandel-bff-auth-werkbak
eho/register-referentie:feat/13-workflow-user-tasks
eho/register-referentie:feat/13-behandel-decision-model
eho/register-referentie:chore/release-2026.07.0
eho/register-referentie:feat/78-reference-correlation
eho/register-referentie:feat/75-approval-flow
eho/register-referentie:feat/10-openbaar-portal
eho/register-referentie:chore/73-ci-speedups
eho/register-referentie:feat/68-e2e
eho/register-referentie:feat/67-self-service-form
eho/register-referentie:feat/66-api-client
eho/register-referentie:feat/65-nx-workspace
eho/register-referentie:feat/8-bff
eho/register-referentie:feat/6-domain-service
eho/register-referentie:feat/7-event-subscriber-projection
eho/register-referentie:feat/56-nrc-notification-wiring
eho/register-referentie:test/46-acl-openzaak-integration
eho/register-referentie:feat/47-acl-mutation-baseline
eho/register-referentie:ci/30-gitea-actions-ci
eho/register-referentie:feat/5-acl-open-zaak
eho/register-referentie:feat/4-flowable
eho/register-referentie:feat/3-keycloak
eho/register-referentie:feat/2-opennotificaties
eho/register-referentie:feat/2-catalogus-seed
eho/register-referentie:feat/10-openzaak-compose
eho/register-referentie:feat/32-docs-scaffold
eho/register-referentie:feat/31-contributor-workflow
eho/register-referentie:feat/30-gitea-actions-ci
eho/register-referentie:feat/29-bff-docker-compose
eho/register-referentie:chore/remove-bootstrap-scripts
eho/register-referentie:feat/28-bff-health
eho/register-referentie:docs/split-s00
..
pull from: eho/register-referentie:main
eho/register-referentie:fix/keycloak-proxy-headers
eho/register-referentie:main
eho/register-referentie:feat/demo-otp-autofill
eho/register-referentie:fix/182-celery-concurrency
eho/register-referentie:feat/public-host-caddy
eho/register-referentie:ci/175-deploy-on-merge
eho/register-referentie:feat/177-public-tls-edge
eho/register-referentie:ci/168-helm-chart-ci-gate
eho/register-referentie:docs/169-mkdocs-nav
eho/register-referentie:feat/25-helm-kubernetes-caddy
eho/register-referentie:fix/161-e2e-bounded-and-diagnosable
eho/register-referentie:feat/162-werkbak-live-refresh
eho/register-referentie:feat/132-medewerker-mfa
eho/register-referentie:fix/156-tempo-ingester-healthcheck
eho/register-referentie:feat/153-projection-sourced-from-objecten
eho/register-referentie:feat/152-objecten-publishes-to-nrc
eho/register-referentie:feat/149-acl-writes-registerrecord
eho/register-referentie:feat/141-registerrecord-objecttype
eho/register-referentie:perf/verify-stack-uwsgi-oz-nrc
eho/register-referentie:fix/144-verify-stack-uwsgi
eho/register-referentie:feat/140-objecten-up
eho/register-referentie:feat/139-objecttypen-up
eho/register-referentie:feat/131-default-fill-crud
eho/register-referentie:chore/136-ci-job-summaries
eho/register-referentie:fix/134-verify-stack-scheduling
eho/register-referentie:feat/130-beheer-catalogi
eho/register-referentie:feat/124-metrics-dashboards
eho/register-referentie:ci/127-parallel-jobs
eho/register-referentie:feat/123-distributed-traces
eho/register-referentie:feat/111-self-service-resume
eho/register-referentie:feat/113-acl-zaaktype-by-identificatie
eho/register-referentie:fix/110-compose-local-flow
eho/register-referentie:fix/115-e2e-single-worker
eho/register-referentie:docs/111-backlog-s26
eho/register-referentie:feat/106-close-zaak-on-timeout
eho/register-referentie:feat/103-diploma-upload-documenten
eho/register-referentie:feat/102-document-wait-timeout
eho/register-referentie:feat/14-dmn-diploma-eligibility
eho/register-referentie:feat/15-beoordeling-escalation
eho/register-referentie:fix/portal-nginx-resolver
eho/register-referentie:fix/local-eventsubscriber-acl
eho/register-referentie:feat/12-withdrawal-portal
eho/register-referentie:fix/91-local-compose-parity
eho/register-referentie:feat/12-withdrawal-bff
eho/register-referentie:feat/12-withdrawal-workflow
eho/register-referentie:feat/12-withdrawal
eho/register-referentie:feat/13-behandel-portal
eho/register-referentie:feat/13-behandel-decide
eho/register-referentie:feat/13-behandel-bff-auth-werkbak
eho/register-referentie:feat/13-workflow-user-tasks
eho/register-referentie:feat/13-behandel-decision-model
eho/register-referentie:chore/release-2026.07.0
eho/register-referentie:feat/78-reference-correlation
eho/register-referentie:feat/75-approval-flow
eho/register-referentie:feat/10-openbaar-portal
eho/register-referentie:chore/73-ci-speedups
eho/register-referentie:feat/68-e2e
eho/register-referentie:feat/67-self-service-form
eho/register-referentie:feat/66-api-client
eho/register-referentie:feat/65-nx-workspace
eho/register-referentie:feat/8-bff
eho/register-referentie:feat/6-domain-service
eho/register-referentie:feat/7-event-subscriber-projection
eho/register-referentie:feat/56-nrc-notification-wiring
eho/register-referentie:test/46-acl-openzaak-integration
eho/register-referentie:feat/47-acl-mutation-baseline
eho/register-referentie:ci/30-gitea-actions-ci
eho/register-referentie:feat/5-acl-open-zaak
eho/register-referentie:feat/4-flowable
eho/register-referentie:feat/3-keycloak
eho/register-referentie:feat/2-opennotificaties
eho/register-referentie:feat/2-catalogus-seed
eho/register-referentie:feat/10-openzaak-compose
eho/register-referentie:feat/32-docs-scaffold
eho/register-referentie:feat/31-contributor-workflow
eho/register-referentie:feat/30-gitea-actions-ci
eho/register-referentie:feat/29-bff-docker-compose
eho/register-referentie:chore/remove-bootstrap-scripts
eho/register-referentie:feat/28-bff-health
eho/register-referentie:docs/split-s00
1
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
0074a1bff3 |
feat(k8s): optionally auto-fill the medewerker OTP step for the public demo (refs #177) (#181)
CI / k8s (push) Successful in 8s
CI / build (push) Successful in 1m38s
CI / lint (push) Successful in 1m55s
CI / mutation (push) Canceled after 0s
CI / verify-stack (push) Canceled after 0s
CI / frontend (push) Canceled after 12s
CI / unit (push) Canceled after 18s
Deploy to Talos / deploy (push) Successful in 2m30s
## What & why For the public demo on `big-behandel` / `big-beheer`, visitors should see MFA being enforced without needing an authenticator app. This adds an opt-in Keycloak theme that fills in and submits the medewerker OTP code itself. - **Theme as real files in `infra/keycloak/themes/big-demo/`**, next to the realms: - `login/theme.properties`: `keycloak.v2` plus `scripts=js/otp-autofill.js`. I checked the 26.1 source: `keycloak.v2` loads theme `scripts` and sets none of its own. - `login/resources/js/otp-autofill.js`: on the OTP page, computes the code (RFC 6238, Keycloak's default policy) from the fixture secret `BIGMEDEWERKEROTPSEED` and submits it. - `account`, `admin`, `email`: plain children of Keycloak 26's defaults. Without them the account console returns 500 (see notes). - **Seeded like every other file input:** `infra/helm/seed-configmaps.sh` creates the `rr-kc-theme` ConfigMap, and the chart mounts it as a directory. The podspec gains `items` so flat ConfigMap keys map to theme paths. Keycloak runs `start-dev` (no theme cache), so edits show up about a minute after a reseed. - **Switch:** `demo.otpAutofill` only decides whether `KC_SPI_THEME_DEFAULT=big-demo` is set. `big.env` now skips env values that render empty, and no existing env var is empty. **Off, the render is identical to main except for that one missing variable,** so Keycloak keeps its stock theme. The realm JSONs are untouched, so compose and the e2e tests still require a code. - **Single-use codes:** a second login in the same 30 s window spends the next counter, as `nextUnusedCounter` does in the e2e. Past that it only fills in the field and doesn't submit, so a rejected code can't loop. - **Deploy workflow:** repo variable `OTP_AUTOFILL=true` → `--set demo.otpAutofill=true`. Flipping it changes the pod's env, so Keycloak restarts. Refs #177 ## Definition of Done - [x] Linked Gitea issue (above). - [ ] Failing test committed before the implementation. *(Not done; checks below.)* - [x] Conventional Commits referencing the issue (`refs #NN`). - [ ] CI green - [x] `docker compose up` unaffected (chart only). - [x] Docs updated (Talos runbook, "Publishing through the labs Caddy"). - [ ] ADR. The fixture-secret trade-off is ADR-0031's; this only automates typing it in. ## Notes for reviewers - **Tested on the live cluster.** I patched the running Keycloak with the rendered theme (autofill on) and ran real headless Chromium logins against the public hosts: - `merel-behandelaar` on big-behandel: only username and password typed. The OTP page loaded the script, submitted by itself, and the user landed in the Werkbak. - `jan-burger` on big-mijn still logs in (regression check). - `/realms/medewerker/account/` returns 200. - **Account console 500, found live and fixed in the second commit.** `KC_SPI_THEME_DEFAULT` applies to every theme type, and Keycloak does *not* fall back for a type the theme lacks (`NullPointerException ... "theme" is null`). `big-demo` now declares login, account, admin and email, each a plain child of Keycloak 26's default. It's one ConfigMap mounted as a directory; the podspec gains `items` for that. - **Keycloak restarts cause about 5 minutes of BFF 401s.** This is not caused by this PR, but you'll see it whenever Keycloak restarts. Dev-mode Keycloak makes new signing keys on each boot, and the BFF refreshes its cached keys at most every 5 minutes. Seen live: 401 right after the restart, 204 about 4½ minutes later. Flipping `OTP_AUTOFILL` restarts Keycloak, so expect this briefly. - `make k8s-lint` and `make k8s-drift` pass. The rendered script's code matches `infra/keycloak/check_realms.py otp`. - **Security:** with it on, the public behandel and beheer portals are protected only by the committed password `test123`. That's intentional for synthetic demo data. Never enable it anywhere real. 🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #181 |