docs(keycloak-session-store): remake all 28 diagrams through the techviz pipeline

The originating repository's SVGs were drawn by hand and every one of them
put a title, a subtitle and an explanation band inside the canvas. This
repository forbids both, so they could not be carried over — the whole set
was rebuilt through the skill's pipeline instead.

Each diagram went through prepare, references, prompt, a VizSpec 1.1 citing
document line ranges, lint, and render. All 28 pass lint and produce the
same eight formats the existing keycloak project has. Sentences moved out of
the canvas into <desc> and the paragraph beside each figure; the drawings
carry names only.

Two lint rules did real work rather than formatting work:

  edge-through-node                  caught arrows crossing an unrelated
                                     node and implying an adjacency that
                                     does not exist — four diagrams had to
                                     be restructured, not just relaid out
  evidence-outside-prepared-context  caught a diagram citing another
                                     section; its anchor moved from B-0 to
                                     B-1 so all three sections it draws on
                                     are inside the prepared context

lab-topology also had to change profile: its context offers a different
candidate set, and query-fanout with shard roles is what the section
actually shows — one entry point spreading to two Keycloak nodes.

The document now carries all 28 inline, one per claim that needed one, and
the section recording what was still missing is updated: the diagram gap is
closed, Studio records remain.

verify-pipeline.py passes. audit-records.py reports no issues.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-09-05 11:03:10 +09:00
co-authored by Claude Opus 5
parent b2963105a8
commit 75bed382c8
286 changed files with 65385 additions and 710 deletions
@@ -0,0 +1,120 @@
{
"version": "1.1",
"id": "d3-secret-exposure",
"title": "base64 는 암호화가 아니다",
"question": "Secret 에 넣으면 값이 가려지는가",
"type": "architecture",
"direction": "TB",
"audience": [
"쿠버네티스에 비밀을 두는 엔지니어"
],
"summary": "etcd 에 평문으로 있고 파드 안에서는 환경 변수로 그대로 읽힌다.",
"alt": "Secret 의 값이 base64 디코드와 파드 환경 변수 두 경로로 모두 평문에 닿는 구성.",
"long_description": "kubectl get secret -o yaml 이 보여주는 base64 는 인코딩이지 암호화가 아니다. etcd 에 평문으로 있다. 그리고 파드 안에서 env 를 grep 하면 그대로 나온다. 값을 Secret 에 넣었다는 것과 값이 가려졌다는 것은 다른 사건이다.",
"source_context": {
"document": "docs/keycloak-session-store/final/document.md",
"document_sha256": "1d44cba1905544d92f1d26ae36a8deb64a3db3914d6b488fd30d6ae7f8cfbabe",
"anchor": {
"kind": "heading",
"value": "D-3 · 비밀",
"line": 504
}
},
"composition": {
"profile": "component-flow",
"diagram_only": true,
"reference_ids": [
"payment-event-flow"
],
"rationale": "값이 평문으로 드러나는 경로가 몇 개인가가 지배적 질문이다. 노출 경로이므로 component-flow 를 골랐다."
},
"groups": [],
"nodes": [
{
"id": "secret",
"label": "k8s Secret",
"kind": "datastore",
"role": "source",
"emphasis": "warning",
"description": "base64 로 담긴다.",
"details": [
"인코딩이지 암호화가 아니다"
],
"evidence": [
{
"start_line": 495,
"end_line": 501
}
],
"assumption": false
},
{
"id": "etcd",
"label": "etcd",
"kind": "datastore",
"role": "target",
"emphasis": "warning",
"description": "평문으로 있다.",
"details": [],
"evidence": [
{
"start_line": 495,
"end_line": 501
}
],
"assumption": false
},
{
"id": "pod",
"label": "파드 환경 변수",
"kind": "component",
"role": "target",
"emphasis": "warning",
"description": "env 로 그대로 읽힌다.",
"details": [
"env | grep -i secret"
],
"evidence": [
{
"start_line": 495,
"end_line": 501
}
],
"assumption": false
}
],
"edges": [
{
"id": "s-e",
"from": "secret",
"to": "etcd",
"label": "여기 저장된다",
"kind": "write",
"evidence": [
{
"start_line": 495,
"end_line": 501
}
],
"assumption": false
},
{
"id": "s-p",
"from": "secret",
"to": "pod",
"label": "주입된다",
"kind": "write",
"evidence": [
{
"start_line": 495,
"end_line": 501
}
],
"assumption": false
}
],
"legend": [],
"metadata": {
"rationale": "인코딩과 암호화를 갈랐다. 두 경로 모두 끝이 평문이다."
}
}