The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.
Follows the import procedure in README.md.
source/ the originating repository verbatim — 78 documents, 28 SVGs,
8 manifests, plus .source-revision recording the commit
final/ the SSOT
document.md 729 lines written from the 29 experiment documents, not
concatenated: what was predicted, what was measured, and
where the measurement itself was wrong
evidence/raw 125 outputs, flattened to <experiment>__<file> because
the originals collided (01-baseline.txt appeared three
times) and the audit only globs the top level
evidence/meta one per raw file; command and exitCode are null and the
README says why rather than inventing them
evidence/browser 22 captures
assets/ three diagrams through techviz
.techviz/ their VizSpecs
A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.
Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.
verify-pipeline.py passes. audit-records.py reports no issues.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
43 lines
1.4 KiB
Bash
Executable File
43 lines
1.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Build the API image on this workstation and import it into each lab node's
|
|
# containerd.
|
|
#
|
|
# k3s does not run Docker and the lab has no registry, so images are shipped as
|
|
# a stream: docker save -> ssh through the lab host -> k3s ctr images import.
|
|
# Every node needs its own copy because the scheduler may place the pod anywhere.
|
|
#
|
|
# ./deploy/lab/scripts/build-and-import.sh
|
|
# IMAGE=keycloak-pattern-api:lab NODES="kc-lab-1" ./deploy/lab/scripts/build-and-import.sh
|
|
set -euo pipefail
|
|
|
|
IMAGE="${IMAGE:-keycloak-pattern-api:lab}"
|
|
NODES="${NODES:-kc-lab-1 kc-lab-2}"
|
|
LAB_HOST="${LAB_HOST:-test-server}"
|
|
CONTEXT="${CONTEXT:-backend}"
|
|
|
|
repo_root="$(git rev-parse --show-toplevel)"
|
|
cd "$repo_root"
|
|
|
|
echo "==> building ${IMAGE} from ${CONTEXT}/"
|
|
docker build -t "$IMAGE" "$CONTEXT"
|
|
|
|
for node in $NODES; do
|
|
echo "==> importing into ${node}"
|
|
# Nested ssh: the workstation cannot reach the guests directly because they
|
|
# sit behind the lab host's libvirt NAT. The lab host's ~/.ssh/config holds
|
|
# the kc-lab-* aliases.
|
|
docker save "$IMAGE" \
|
|
| ssh "$LAB_HOST" "ssh ${node} 'sudo k3s ctr images import -'"
|
|
done
|
|
|
|
echo "==> verifying"
|
|
for node in $NODES; do
|
|
printf ' %-10s ' "$node"
|
|
ssh "$LAB_HOST" "ssh ${node} 'sudo k3s ctr images ls -q'" \
|
|
| grep -c "$IMAGE" \
|
|
| xargs -I{} echo "{} match(es)"
|
|
done
|
|
|
|
echo
|
|
echo "next: kubectl rollout restart -n header-lab deployment/echo"
|