Files
document-haness/docs/keycloak-session-store/final/.techviz/b5-b6-storage-and-keys/spec.json
T
DongHyeonkaandClaude Opus 5 75bed382c8 docs(keycloak-session-store): remake all 28 diagrams through the techviz pipeline
The originating repository's SVGs were drawn by hand and every one of them
put a title, a subtitle and an explanation band inside the canvas. This
repository forbids both, so they could not be carried over — the whole set
was rebuilt through the skill's pipeline instead.

Each diagram went through prepare, references, prompt, a VizSpec 1.1 citing
document line ranges, lint, and render. All 28 pass lint and produce the
same eight formats the existing keycloak project has. Sentences moved out of
the canvas into <desc> and the paragraph beside each figure; the drawings
carry names only.

Two lint rules did real work rather than formatting work:

  edge-through-node                  caught arrows crossing an unrelated
                                     node and implying an adjacency that
                                     does not exist — four diagrams had to
                                     be restructured, not just relaid out
  evidence-outside-prepared-context  caught a diagram citing another
                                     section; its anchor moved from B-0 to
                                     B-1 so all three sections it draws on
                                     are inside the prepared context

lab-topology also had to change profile: its context offers a different
candidate set, and query-fanout with shard roles is what the section
actually shows — one entry point spreading to two Keycloak nodes.

The document now carries all 28 inline, one per claim that needed one, and
the section recording what was still missing is updated: the diagram gap is
closed, Studio records remain.

verify-pipeline.py passes. audit-records.py reports no issues.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 11:03:10 +09:00

152 lines
4.3 KiB
JSON

{
"version": "1.1",
"id": "b5-b6-storage-and-keys",
"title": "볼륨 없는 영속화와 유예 없는 회전",
"question": "설정만으로 영속화와 무중단 키 교체가 되는가",
"type": "architecture",
"direction": "TB",
"audience": [
"저장소와 키 회전을 운영하는 엔지니어"
],
"summary": "볼륨이 없으면 appendonly 설정은 장식이고, JWKS 캐시는 모르는 kid 를 만나면 곧바로 다시 가져온다.",
"alt": "Redis 의 데이터 디렉터리가 컨테이너 파일시스템일 때 영속화 설정이 무의미해지는 구성과, 새 kid 를 만난 검증기가 JWKS 를 재조회하는 구성.",
"long_description": "redis-cli config set appendonly yes 를 켜도 아무것도 달라지지 않았다. /data 가 컨테이너 파일시스템이라 컨테이너와 함께 죽기 때문이다. appendonlydir 이 만들어졌다가 그대로 버려진다. 볼륨 없는 영속화 설정은 장식이다. realm 키를 회전했을 때는 JWKS 캐시의 유예 구간을 기대했는데 없었다. NimbusJwtDecoder 는 모르는 kid 를 만나면 JWKS 를 다시 가져온다.",
"source_context": {
"document": "docs/keycloak-session-store/final/document.md",
"document_sha256": "1d44cba1905544d92f1d26ae36a8deb64a3db3914d6b488fd30d6ae7f8cfbabe",
"anchor": {
"kind": "heading",
"value": "B-5 · B-6 — 저장소 상실과 키 회전",
"line": 415
}
},
"composition": {
"profile": "component-flow",
"diagram_only": true,
"reference_ids": [
"payment-event-flow"
],
"rationale": "설정이 실제 저장 매체에 닿는가가 지배적 질문이다. 경로의 끝이 어디인가이므로 component-flow 를 골랐다."
},
"groups": [],
"nodes": [
{
"id": "config",
"label": "appendonly yes",
"kind": "process",
"role": "source",
"emphasis": "warning",
"description": "설정은 적용된다.",
"details": [
"redis-cli config set"
],
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
},
{
"id": "datadir",
"label": "/data",
"kind": "datastore",
"role": "control",
"emphasis": "warning",
"description": "컨테이너 파일시스템이다.",
"details": [
"appendonlydir 이 만들어졌다 버려진다"
],
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
},
{
"id": "container",
"label": "컨테이너",
"kind": "component",
"role": "target",
"emphasis": "warning",
"description": "죽으면 /data 도 같이 사라진다.",
"details": [
"볼륨이 없으면 여기까지다"
],
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
},
{
"id": "volume",
"label": "PersistentVolume",
"kind": "datastore",
"role": "target",
"emphasis": "primary",
"description": "여기 있어야 설정이 뜻을 갖는다.",
"details": [],
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
}
],
"edges": [
{
"id": "c-d",
"from": "config",
"to": "datadir",
"label": "AOF 파일을 쓴다",
"kind": "write",
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
},
{
"id": "d-c",
"from": "datadir",
"to": "container",
"label": "컨테이너와 함께 죽는다",
"kind": "blocked",
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
},
{
"id": "d-v",
"from": "datadir",
"to": "volume",
"label": "볼륨을 붙여야 남는다",
"kind": "write",
"evidence": [
{
"start_line": 406,
"end_line": 412
}
],
"assumption": false
}
],
"legend": [],
"metadata": {
"rationale": "설정과 매체를 분리해 그렸다. 설정만 보면 두 경우 모두 되어 있는 것으로 읽힌다."
}
}