Files
document-haness/docs/keycloak-session-store/source/docs/keycloak-branch-manifest.tsv
T
DongHyeonkaandClaude Opus 5 b2963105a8 docs(keycloak-session-store): import the session-storage lab as a new project
The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.

Follows the import procedure in README.md.

  source/     the originating repository verbatim — 78 documents, 28 SVGs,
              8 manifests, plus .source-revision recording the commit
  final/      the SSOT
    document.md   729 lines written from the 29 experiment documents, not
                  concatenated: what was predicted, what was measured, and
                  where the measurement itself was wrong
    evidence/raw    125 outputs, flattened to <experiment>__<file> because
                    the originals collided (01-baseline.txt appeared three
                    times) and the audit only globs the top level
    evidence/meta   one per raw file; command and exitCode are null and the
                    README says why rather than inventing them
    evidence/browser  22 captures
    assets/       three diagrams through techviz
    .techviz/     their VizSpecs

A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.

Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.

verify-pipeline.py passes. audit-records.py reports no issues.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-04 22:51:59 +09:00

2.7 KiB

1branchtargetdelivery
2feature/keycloak-account-linking-spa-uxap1documented-and-contract-tested
3feature/keycloak-account-linking-sub-vs-emailcommondocumented-and-contract-tested
4feature/keycloak-bff-csrf-samesite-defenseap3locally-verified
5feature/keycloak-bff-oauth2login-sessionap3locally-verified
6feature/keycloak-bff-vs-spa-directap3documented
7feature/keycloak-docker-compose-stackcommonlocally-verified
8feature/keycloak-edge-forwardauth-google-federationap4documented-and-config-tested
9feature/keycloak-edge-forwardauth-no-googleap4documented-and-config-tested
10feature/keycloak-federation-spa-zero-changeap1contract-tested
11feature/keycloak-first-broker-login-flowcommonlocally-verified-with-mock-idp
12feature/keycloak-four-pattern-tradeoff-matrixcommondocumented-and-evidence-linked
13feature/keycloak-google-claim-attribute-mappingcommonlocally-verified-with-mock-idp
14feature/keycloak-google-redirect-uri-policycommonconfig-tested
15feature/keycloak-header-spoofing-defenseap4locally-verified
16feature/keycloak-https-termination-caddy-nginxcommonconfig-tested
17feature/keycloak-idp-brokering-google-clientcommonlocally-verified-with-mock-idp
18feature/keycloak-idp-mappers-claim-to-rolecommonlocally-verified-with-mock-idp
19feature/keycloak-internal-spa-direct-google-federationap1documented-and-contract-tested
20feature/keycloak-internal-spa-direct-no-googleap1documented-and-contract-tested
21feature/keycloak-iss-claim-hostname-mismatchap1locally-verified
22feature/keycloak-nginx-auth-request-integrationap4locally-verified
23feature/keycloak-oauth2-proxy-oidc-flowap4locally-verified
24feature/keycloak-patternscommongovernance
25feature/keycloak-pkce-flow-stagesap1contract-tested
26feature/keycloak-public-domain-tunnelingcommonconfig-tested
27feature/keycloak-realm-client-exportcommonlocally-verified
28feature/keycloak-refresh-rotation-and-logoutap1locally-verified
29feature/keycloak-refresh-token-rotationap1contract-tested
30feature/keycloak-reverse-proxy-headerscommonconfig-tested
31feature/keycloak-single-ec2-google-federationap1documented-and-config-tested
32feature/keycloak-single-ec2-no-googleap1documented-and-contract-tested
33feature/keycloak-spa-token-storage-tradeoffap1locally-verified
34feature/keycloak-spring-rs-audience-validatorap1locally-verified
35feature/keycloak-spring-rs-role-mappingap1locally-verified
36feature/keycloak-three-leg-trust-chainap1documented-and-contract-tested
37feature/keycloak-token-mediating-access-handoffap2locally-verified
38feature/keycloak-token-mediating-confidential-clientap2locally-verified
39feature/keycloak-traefik-forwardauth-alternativeap4config-tested
40feature/keycloak-vanilla-js-spa-pkceap1locally-verified