The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.
Follows the import procedure in README.md.
source/ the originating repository verbatim — 78 documents, 28 SVGs,
8 manifests, plus .source-revision recording the commit
final/ the SSOT
document.md 729 lines written from the 29 experiment documents, not
concatenated: what was predicted, what was measured, and
where the measurement itself was wrong
evidence/raw 125 outputs, flattened to <experiment>__<file> because
the originals collided (01-baseline.txt appeared three
times) and the audit only globs the top level
evidence/meta one per raw file; command and exitCode are null and the
README says why rather than inventing them
evidence/browser 22 captures
assets/ three diagrams through techviz
.techviz/ their VizSpecs
A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.
Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.
verify-pipeline.py passes. audit-records.py reports no issues.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
41 lines
1.7 KiB
Plaintext
41 lines
1.7 KiB
Plaintext
Sub-scope 09 (mongo) - execution probe: what the profile's TLS and timeout policy reaches
|
|
revision=a24ece9cf797f7ea647e33bf846b115208ed1ba5
|
|
generatedAt=2026-08-30T00:24:04+00:00
|
|
|
|
One temporary probe class was added, run, and removed:
|
|
src/test/.../security/Ss09TlsProbe.java (@Tag mongodb-contract, hermetic)
|
|
No production source was modified.
|
|
|
|
PROBE profile.tlsRequired=true -> validator ACCEPTED
|
|
PROBE settings Boot builds from the README's URI (spring.data.mongodb.uri, line 37):
|
|
sslEnabled=false
|
|
connectTimeoutMs=10000
|
|
serverSelectionTimeoutMs=30000
|
|
poolMaxSize=100
|
|
serverApi=null
|
|
uuidRepresentation=UNSPECIFIED
|
|
PROBE settings MongoClientSettingsFactory would build: sslEnabled=true
|
|
|
|
Reading: MongoSecurityProfileValidator accepts a production profile that declares TLS
|
|
required, and nothing applies that declaration to the driver, because
|
|
MongoClientSettingsFactory has no caller anywhere in the repository (8.1b, 8.1e).
|
|
The connect timeout, server-selection timeout, pool bounds, Stable API declaration and
|
|
pinned UUID representation the profile states are equally unapplied; the values above are
|
|
the driver's own defaults.
|
|
|
|
Contrast (8.1c): the identical defect on the observability half - a settings-builder
|
|
method with no caller - was fixed by registering a MongoClientSettingsBuilderCustomizer
|
|
in MongoDriverObservabilityAutoConfiguration. The same mechanism is available here and is
|
|
not used.
|
|
|
|
Note (8.1b): MongoTlsLaneTest proves the SERVER enforces TLS. It builds its own settings
|
|
with applyToSslSettings(ssl -> ssl.enabled(true)) by hand (line 137), so it does not
|
|
exercise the path from a profile's tlsRequired flag to a TLS connection.
|
|
$ git status --short | wc -l
|
|
0
|
|
exit=0
|
|
|
|
$ git status --short
|
|
exit=0
|
|
|