docs(keycloak-session-store): remake all 28 diagrams through the techviz pipeline

The originating repository's SVGs were drawn by hand and every one of them
put a title, a subtitle and an explanation band inside the canvas. This
repository forbids both, so they could not be carried over — the whole set
was rebuilt through the skill's pipeline instead.

Each diagram went through prepare, references, prompt, a VizSpec 1.1 citing
document line ranges, lint, and render. All 28 pass lint and produce the
same eight formats the existing keycloak project has. Sentences moved out of
the canvas into <desc> and the paragraph beside each figure; the drawings
carry names only.

Two lint rules did real work rather than formatting work:

  edge-through-node                  caught arrows crossing an unrelated
                                     node and implying an adjacency that
                                     does not exist — four diagrams had to
                                     be restructured, not just relaid out
  evidence-outside-prepared-context  caught a diagram citing another
                                     section; its anchor moved from B-0 to
                                     B-1 so all three sections it draws on
                                     are inside the prepared context

lab-topology also had to change profile: its context offers a different
candidate set, and query-fanout with shard roles is what the section
actually shows — one entry point spreading to two Keycloak nodes.

The document now carries all 28 inline, one per claim that needed one, and
the section recording what was still missing is updated: the diagram gap is
closed, Studio records remain.

verify-pipeline.py passes. audit-records.py reports no issues.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-09-05 11:03:10 +09:00
co-authored by Claude Opus 5
parent b2963105a8
commit 75bed382c8
286 changed files with 65385 additions and 710 deletions
@@ -0,0 +1,150 @@
{
"version": "1.1",
"id": "b3-rotation-contention",
"title": "회전 경쟁에서 이긴 요청도 진다",
"question": "같은 refresh token 으로 동시에 여러 요청이 오면 어떻게 되는가",
"type": "architecture",
"direction": "TB",
"audience": [
"Refresh Token Rotation 을 켜려는 백엔드 엔지니어"
],
"summary": "하나가 성공하고 나머지가 실패하는 것이 아니다. 경쟁이 감지되면 client session 이 지워져 이긴 요청의 새 토큰조차 쓸 수 없다.",
"alt": "동시에 도착한 refresh 요청들이 경쟁을 일으키고, 그 결과 client session 자체가 지워지는 구성.",
"long_description": "revokeRefreshToken 을 켜고 refreshTokenMaxReuse 를 0 으로 둔 상태에서 같은 refresh token 으로 동시에 5건을 보냈다. 순차로 돌리면 재현되지 않으며 백그라운드로 띄우고 wait 해야 경합이 생긴다. 이긴 요청이 받은 새 토큰조차 쓸 수 없었다. Keycloak 이 경쟁을 감지하면 client session 을 지우기 때문이다.",
"source_context": {
"document": "docs/keycloak-session-store/final/document.md",
"document_sha256": "1d44cba1905544d92f1d26ae36a8deb64a3db3914d6b488fd30d6ae7f8cfbabe",
"anchor": {
"kind": "heading",
"value": "B-3 · Refresh Token Rotation 경쟁 (Q2)",
"line": 391
}
},
"composition": {
"profile": "component-flow",
"diagram_only": true,
"reference_ids": [
"payment-event-flow"
],
"rationale": "경쟁의 결과가 개별 요청이 아니라 세션 전체에 미치는 것이 지배적 질문이다. 영향 경로이므로 component-flow 를 골랐다."
},
"groups": [],
"nodes": [
{
"id": "concurrent",
"label": "동시 refresh 5건",
"kind": "actor",
"role": "source",
"emphasis": "primary",
"description": "같은 refresh token 을 쓴다.",
"details": [
"& 와 wait 이 없으면 재현되지 않는다"
],
"evidence": [
{
"start_line": 369,
"end_line": 375
}
],
"assumption": false
},
{
"id": "rotation",
"label": "회전 검사",
"kind": "process",
"role": "control",
"emphasis": "warning",
"description": "이미 쓴 토큰인지 본다.",
"details": [
"revokeRefreshToken=true · refreshTokenMaxReuse=0"
],
"evidence": [
{
"start_line": 369,
"end_line": 377
}
],
"assumption": false
},
{
"id": "client-session",
"label": "client session",
"kind": "component",
"role": "target",
"emphasis": "warning",
"description": "경쟁이 감지되면 지워진다.",
"details": [],
"evidence": [
{
"start_line": 378,
"end_line": 384
}
],
"assumption": false
},
{
"id": "new-token",
"label": "이긴 요청의 새 토큰",
"kind": "component",
"role": "target",
"emphasis": "warning",
"description": "세션이 지워져 쓸 수 없다.",
"details": [],
"evidence": [
{
"start_line": 378,
"end_line": 384
}
],
"assumption": false
}
],
"edges": [
{
"id": "c-r",
"from": "concurrent",
"to": "rotation",
"label": "동시 도착",
"kind": "request",
"evidence": [
{
"start_line": 369,
"end_line": 377
}
],
"assumption": false
},
{
"id": "r-cs",
"from": "rotation",
"to": "client-session",
"label": "경쟁 감지 시 삭제",
"kind": "blocked",
"evidence": [
{
"start_line": 378,
"end_line": 384
}
],
"assumption": false
},
{
"id": "cs-nt",
"from": "client-session",
"to": "new-token",
"label": "세션이 없으니 못 쓴다",
"kind": "blocked",
"evidence": [
{
"start_line": 378,
"end_line": 384
}
],
"assumption": false
}
],
"legend": [],
"metadata": {
"rationale": "실패가 진 요청에만 오지 않는다는 것을 그렸다. 재시도 설계가 여기서 갈린다."
}
}