DongHyeonka and Claude Opus 5
f1e8c35805
docs: plan all remaining experiments with architecture, injection points and predictions
...
Twenty experiments across four layers, each with a topology diagram marking where the fault goes in, the metrics to watch, a falsifiable prediction written before the run, and a pass/fail rule.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 10:50:23 +09:00
DongHyeonka and Claude Opus 5
1de6108157
docs: add the prerequisite knowledge this lab assumes
...
Builds up from HTTP statelessness to why session storage location determines the operational response, so the measurements have context to land in.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 10:24:21 +09:00
DongHyeonka and Claude Opus 5
22d873eb4f
docs: capture the SQL the other node actually runs, and correct the replication claim
...
PostgreSQL statement logging shows keycloak-1 reading and updating the session created on keycloak-0. The same transaction reveals optimistic locking via VERSION, SKIP LOCKED, and synchronous_commit turned off. Fixes the earlier concept note that credited Infinispan with cross-node propagation.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 10:14:45 +09:00
DongHyeonka and Claude Opus 5
e5ebaeb623
docs: prove sessions are shared by PostgreSQL, not Infinispan replication
...
Experiment 0 with three probes: cross-node refresh/logout, cache counter deltas around a single login, and cache entry ownership. Each node caches only what it handled; cache totals sum exactly to the database count.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 09:58:10 +09:00
DongHyeonka and Claude Opus 5
006da7d490
docs: record observability setup and add concept layers 10-13
...
Adds Kubernetes resources (StatefulSet, PVC, Secret, RBAC, placement), Keycloak clustering internals (Infinispan, JGroups), Prometheus concepts and virtualization operations.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 09:21:45 +09:00
DongHyeonka and Claude Opus 5
d5cc2b55a9
fix: grant nodes/proxy so kubelet metrics can be scraped
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 09:14:51 +09:00
DongHyeonka and Claude Opus 5
0bb0e0ac49
feat: add Prometheus, node-exporter and Grafana for fault-injection observability
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-04 09:13:41 +09:00
DongHyeonka and Claude Opus 5
33878e8880
docs: record multi-node cluster setup, rationale and formation evidence
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 17:26:45 +09:00
DongHyeonka and Claude Opus 5
6dce35ec83
feat: deploy Keycloak multi-node cluster with PostgreSQL
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 17:17:25 +09:00
DongHyeonka and Claude Opus 5
001efd624a
docs: correct the memory analysis to distinguish host and guest headroom
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 17:02:11 +09:00
DongHyeonka and Claude Opus 5
d6f8b9f8b3
docs: restructure roadmap into A/B/operations layers and add five operational items
...
Adds backup rehearsal, version upgrade, observability, secret management and certificate renewal. Corrects the experiment order so the refresh-token contention test runs after the shared store exists.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:56:13 +09:00
DongHyeonka and Claude Opus 5
df4d3b4345
docs: map published open questions to lab coverage and fix experiment order
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:44:12 +09:00
DongHyeonka and Claude Opus 5
61ba5db259
docs: add lab operations guide with tooling, commands and drills
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:39:45 +09:00
DongHyeonka and Claude Opus 5
bc784fcd6e
docs: surface the spoofing bypass finding in the roadmap
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:24:52 +09:00
DongHyeonka and Claude Opus 5
ddcb1c08e6
docs: record the session store lab roadmap and progress
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:20:38 +09:00
DongHyeonka and Claude Opus 5
e1ba9c5626
docs: record proxy-bypass closure with before and after evidence
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:17:24 +09:00
DongHyeonka and Claude Opus 5
3af52bb66a
feat: narrow Traefik trusted range and restrict echo ingress to Traefik
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 16:15:28 +09:00
DongHyeonka and Claude Opus 5
98874b0c6c
docs: retake staged evidence screenshots with indented output
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 15:52:47 +09:00
DongHyeonka and Claude Opus 5
b708c8d503
feat: indent echo responses for readable evidence
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 15:48:57 +09:00
DongHyeonka and Claude Opus 5
7737787937
docs: record the staged fix and post-fix evidence
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 15:33:40 +09:00
DongHyeonka and Claude Opus 5
1c1b86e849
feat: let the app interpret forwarded headers
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 15:30:31 +09:00
DongHyeonka and Claude Opus 5
2294c52095
feat: make Traefik trust forwarded headers from the host nginx
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 15:29:18 +09:00
DongHyeonka and Claude Opus 5
69d4502757
docs: collect evidence for the two-hop header contract failure
...
Control experiment isolates two independent causes: the nginx 443 block still emits X-Forwarded-Proto http, and Traefik rewrites forwarded headers regardless.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 15:04:38 +09:00
DongHyeonka and Claude Opus 5
ae1f391598
docs: expand two-hop header contract with switch locations and per-pattern impact
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 14:57:08 +09:00
DongHyeonka and Claude Opus 5
844d6f1d33
docs: measure and diagnose the two-hop proxy header contract
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 14:35:27 +09:00
DongHyeonka and Claude Opus 5
a831792c5c
docs: map deploy/ assets and record why unapplied configs are kept
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 14:18:08 +09:00
DongHyeonka and Claude Opus 5
bcfdeb93ee
docs: explain every setting used in the echo manifest
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 14:11:18 +09:00
DongHyeonka and Claude Opus 5
deae8966b8
docs: record why Docker must not be installed on the lab host
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 13:53:36 +09:00
DongHyeonka and Claude Opus 5
6c90468c5a
feat: report pod address from echo endpoint
...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
2026-09-03 13:44:29 +09:00
DongHyeonka
51bb055d61
feat: 2홉 구성 진행
2026-09-03 11:46:56 +09:00
DongHyeonka
c22b217fbd
chore: 메타데이터 gitignore
2026-09-02 14:44:06 +09:00
donghyeon-ka
c07593c471
merge: four-pattern tradeoff matrix
2026-07-25 16:31:44 +09:00
donghyeon-ka
d01a60964a
docs: compare four authentication patterns
2026-07-25 16:31:44 +09:00
donghyeon-ka
5d7544256a
merge: public domain tunnel profile
2026-07-25 16:31:13 +09:00
donghyeon-ka
eacc0e86c9
feat: add validated named tunnel profile
2026-07-25 16:31:13 +09:00
donghyeon-ka
ac912cb354
merge: HTTPS termination profiles
2026-07-25 16:30:25 +09:00
donghyeon-ka
e4cee2a06d
feat: add validated HTTPS termination profiles
2026-07-25 16:30:25 +09:00
donghyeon-ka
006b405ad5
merge: reverse proxy header contract
2026-07-25 16:29:32 +09:00
donghyeon-ka
8539d1bf5b
feat: define trusted reverse proxy header contract
2026-07-25 16:29:32 +09:00
donghyeon-ka
3473875d9a
merge: Google redirect URI policy
2026-07-25 16:28:53 +09:00
donghyeon-ka
f077e5038e
docs: define exact Google redirect URI policy
2026-07-25 16:28:53 +09:00
donghyeon-ka
e4eb7e54f7
merge: federated subject identity contract
2026-07-25 16:28:00 +09:00
donghyeon-ka
bdde0feb86
test: verify broker identity uses subject not email
2026-07-25 16:28:00 +09:00
donghyeon-ka
3da8e609ae
merge: broker claim-to-role mapping
2026-07-25 16:26:59 +09:00
donghyeon-ka
ed064473dc
feat: map broker claims to realm roles
2026-07-25 16:26:59 +09:00
donghyeon-ka
a84f7d50a1
merge: Google claim attribute mapping
2026-07-25 16:24:24 +09:00
donghyeon-ka
98b07b4fdf
feat: map upstream Google identity claims
2026-07-25 16:24:24 +09:00
donghyeon-ka
98566a713d
merge: hardened First Broker Login flow
2026-07-25 16:17:54 +09:00
donghyeon-ka
aeb783e592
test: reproduce and block unsafe broker auto-link
2026-07-25 16:17:54 +09:00
donghyeon-ka
3bbbaf5230
merge: Google broker configuration profiles
2026-07-25 15:30:47 +09:00