The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.
Follows the import procedure in README.md.
source/ the originating repository verbatim — 78 documents, 28 SVGs,
8 manifests, plus .source-revision recording the commit
final/ the SSOT
document.md 729 lines written from the 29 experiment documents, not
concatenated: what was predicted, what was measured, and
where the measurement itself was wrong
evidence/raw 125 outputs, flattened to <experiment>__<file> because
the originals collided (01-baseline.txt appeared three
times) and the audit only globs the top level
evidence/meta one per raw file; command and exitCode are null and the
README says why rather than inventing them
evidence/browser 22 captures
assets/ three diagrams through techviz
.techviz/ their VizSpecs
A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.
Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.
verify-pipeline.py passes. audit-records.py reports no issues.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
48 lines
1.9 KiB
Bash
Executable File
48 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Rebuild a guest's cloud-init seed image and publish it into the libvirt pool.
|
|
# Run on the lab host.
|
|
#
|
|
# ./rebuild-seed.sh 1
|
|
#
|
|
# The same content lives in three places: the source YAML, the ISO, and the
|
|
# uploaded pool volume. Editing the YAML alone changes nothing, which is why
|
|
# this is a script and not a set of remembered commands.
|
|
#
|
|
# A rebuilt seed only takes effect on a freshly created VM. cloud-init runs its
|
|
# per-instance modules once per instance-id, so an existing guest ignores it.
|
|
set -euo pipefail
|
|
|
|
N="${1:?usage: rebuild-seed.sh <1|2>}"
|
|
CLOUD_DIR="${CLOUD_DIR:-$HOME/workspace/cloud}"
|
|
POOL="${POOL:-default}"
|
|
export LIBVIRT_DEFAULT_URI="${LIBVIRT_DEFAULT_URI:-qemu:///system}"
|
|
|
|
cd "$CLOUD_DIR"
|
|
src="kc-lab-${N}.yaml"
|
|
iso="seed-kc-lab-${N}.iso"
|
|
meta="meta-kc-lab-${N}"
|
|
|
|
[ -f "$src" ] || { echo "missing $CLOUD_DIR/$src" >&2; exit 1; }
|
|
|
|
# A fresh instance-id makes cloud-init treat the guest as new and re-run the
|
|
# per-instance modules.
|
|
printf 'instance-id: kc-lab-%s-%s\nlocal-hostname: kc-lab-%s\n' \
|
|
"$N" "$(date +%s)" "$N" > "$meta"
|
|
|
|
# NoCloud looks for a volume labelled cidata holding files named exactly
|
|
# user-data and meta-data. -graft-points renames them inside the image so no
|
|
# staging directory is needed.
|
|
xorrisofs -quiet -output "$iso" -volid CIDATA -joliet -rock -graft-points \
|
|
"/user-data=${src}" "/meta-data=${meta}"
|
|
|
|
size="$(stat -c%s "$iso")"
|
|
virsh vol-delete --pool "$POOL" "$iso" >/dev/null 2>&1 || true
|
|
virsh vol-create-as "$POOL" "$iso" "$size" --format raw >/dev/null
|
|
virsh vol-upload --pool "$POOL" "$iso" "$iso"
|
|
|
|
echo "$iso published to pool '$POOL' ($size bytes)"
|
|
echo "attach it as a virtio disk, not a SATA cdrom:"
|
|
echo " --disk vol=${POOL}/${iso},device=disk,bus=virtio,readonly=on"
|
|
echo "Debian genericcloud images carry no AHCI driver, so a SATA cdrom is invisible"
|
|
echo "to the guest and cloud-init fails with no error anywhere."
|