Files
document-haness/docs/keycloak-session-store/source/docs/evidence/d3-secret-management
DongHyeonkaandClaude Opus 5 b2963105a8 docs(keycloak-session-store): import the session-storage lab as a new project
The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.

Follows the import procedure in README.md.

  source/     the originating repository verbatim — 78 documents, 28 SVGs,
              8 manifests, plus .source-revision recording the commit
  final/      the SSOT
    document.md   729 lines written from the 29 experiment documents, not
                  concatenated: what was predicted, what was measured, and
                  where the measurement itself was wrong
    evidence/raw    125 outputs, flattened to <experiment>__<file> because
                    the originals collided (01-baseline.txt appeared three
                    times) and the audit only globs the top level
    evidence/meta   one per raw file; command and exitCode are null and the
                    README says why rather than inventing them
    evidence/browser  22 captures
    assets/       three diagrams through techviz
    .techviz/     their VizSpecs

A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.

Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.

verify-pipeline.py passes. audit-records.py reports no issues.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-04 22:51:59 +09:00
..

D-3 — 비밀 관리 증거

2026-09-04 17:1517:25 KST 해설: docs/experiment-d3-secret-management.md

파일 무엇을 보여주는가
01-base64-not-encryption.txt 실험대의 모든 비밀이 명령 네 줄로 평문 출력. describe14 bytes 만 보여줘 착각을 준다
02-at-rest.txt Encryption Status: Disabled · state.db 안에 비밀번호 평문 2회 일치 · 파드 안에서는 KEYCLOAK_CLIENT_SECRET=bff-lab-secret 환경변수 · default SA 는 읽을 수 없음

핵심 세 줄

  1. base64 는 감추려는 것이 아니라 YAML 에 바이트를 담기 위한 것이다. describe 가 값을 가려 안전하다는 착각을 준다.
  2. 저장소 암호화가 꺼져 있고 노드 디스크에 평문이 있다. 노드 디스크 하나가 전 클러스터의 비밀이다.
  3. 네 경로 중 RBAC 만 제 역할을 한다. 그것이 실질적 방어선이며, 관리자에게는 아무 방어가 없다.