Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e0d27d47ce | ||
|
|
78b270559c | ||
|
|
98a74e90a5 | ||
|
|
b5528fae87 | ||
|
|
4864d837f1 | ||
|
|
027c24ee27 | ||
|
|
df140ab218 | ||
|
|
df5af95cb3 | ||
|
|
6c310c93b7 | ||
|
|
e856e7af4d |
@@ -0,0 +1 @@
|
||||
[ 882ms] [ERROR] Failed to load resource: the server responded with a status of 401 () @ https://app2.hyeonworks.com/favicon.ico:0
|
||||
@@ -0,0 +1 @@
|
||||
[ 178ms] [ERROR] Failed to load resource: the server responded with a status of 401 () @ https://app2.hyeonworks.com/favicon.ico:0
|
||||
@@ -0,0 +1,2 @@
|
||||
[ 19340ms] [ERROR] Failed to load resource: the server responded with a status of 403 () @ https://app2.hyeonworks.com/oauth2/callback?state=rKipZCUv8W5a-xgYheJbjBsInoD5Il1AaF1RlM_RB2s%3A%2Fapi%2Fecho&session_state=Mw52KcQijFB9Bq4rN-C4SF5Y&iss=https%3A%2F%2Fauth.hyeonworks.com%2Frealms%2Fkeycloak-patterns&code=f9a4835a-2af3-b886-bd04-10b5347ee8d2.Mw52KcQijFB9Bq4rN-C4SF5Y.80431dbc-af81-4673-9790-ad06d1570b2e:0
|
||||
[ 20374ms] [ERROR] Failed to load resource: the server responded with a status of 401 () @ https://app2.hyeonworks.com/favicon.ico:0
|
||||
@@ -0,0 +1 @@
|
||||
[ 210ms] [ERROR] Failed to load resource: the server responded with a status of 401 () @ https://app2.hyeonworks.com/favicon.ico:0
|
||||
@@ -0,0 +1 @@
|
||||
[ 423ms] [ERROR] Failed to load resource: the server responded with a status of 401 () @ https://app2.hyeonworks.com/favicon.ico:0
|
||||
@@ -0,0 +1,8 @@
|
||||
[ 1127ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 2377ms] [WARNING] <meta name="apple-mobile-web-app-capable" content="yes"> is deprecated. Please include <meta name="mobile-web-app-capable" content="yes"> @ https://app2.hyeonworks.com/explore?schemaVersion=1&panes=%7B%22h4a%22%3A%7B%22datasource%22%3A%22PBFA97CFB590B2093%22%2C%22queries%22%3A%5B%7B%22refId%22%3A%22A%22%2C%22expr%22%3A%22vendor_cluster_size%22%2C%22range%22%3Atrue%2C%22instant%22%3Afalse%2C%22editorMode%22%3A%22code%22%2C%22legendFormat%22%3A%22cluster_size+%7B%7Bpod%7D%7D%22%2C%22datasource%22%3A%7B%22type%22%3A%22prometheus%22%2C%22uid%22%3A%22PBFA97CFB590B2093%22%7D%7D%2C%7B%22refId%22%3A%22B%22%2C%22expr%22%3A%22up%7Bjob%3D%5C%22keycloak%5C%22%7D%22%2C%22range%22%3Atrue%2C%22instant%22%3Afalse%2C%22editorMode%22%3A%22code%22%2C%22legendFormat%22%3A%22up+%7B%7Bpod%7D%7D%22%2C%22datasource%22%3A%7B%22type%22%3A%22prometheus%22%2C%22uid%22%3A%22PBFA97CFB590B2093%22%7D%7D%5D%2C%22range%22%3A%7B%22from%22%3A%22now-30m%22%2C%22to%22%3A%22now%22%7D%7D%7D&orgId=1:0
|
||||
[ 2472ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 3501ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 5119ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 8511ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 14956ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 28065ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
@@ -0,0 +1,10 @@
|
||||
[ 1362ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1874ms] [WARNING] <meta name="apple-mobile-web-app-capable" content="yes"> is deprecated. Please include <meta name="mobile-web-app-capable" content="yes"> @ https://app2.hyeonworks.com/explore?schemaVersion=1&orgId=1&panes=%7B%22a%22%3A%7B%22datasource%22%3A%22PBFA97CFB590B2093%22%2C%22queries%22%3A%5B%7B%22refId%22%3A%22A%22%2C%22expr%22%3A%22vendor_cluster_size%22%2C%22range%22%3Atrue%2C%22instant%22%3Afalse%2C%22editorMode%22%3A%22code%22%2C%22legendFormat%22%3A%22cluster_size%20%7B%7Bpod%7D%7D%22%2C%22datasource%22%3A%7B%22type%22%3A%22prometheus%22%2C%22uid%22%3A%22PBFA97CFB590B2093%22%7D%7D%2C%7B%22refId%22%3A%22B%22%2C%22expr%22%3A%22up%7Bjob%3D%5C%22keycloak%5C%22%7D%22%2C%22range%22%3Atrue%2C%22instant%22%3Afalse%2C%22editorMode%22%3A%22code%22%2C%22legendFormat%22%3A%22up%20%7B%7Bpod%7D%7D%22%2C%22datasource%22%3A%7B%22type%22%3A%22prometheus%22%2C%22uid%22%3A%22PBFA97CFB590B2093%22%7D%7D%5D%2C%22range%22%3A%7B%22from%22%3A%221788502680000%22%2C%22to%22%3A%221788503520000%22%7D%7D%7D:0
|
||||
[ 2907ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 3998ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 6253ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 9426ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 12495ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 24486ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 31338ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 46196ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
@@ -0,0 +1,106 @@
|
||||
[ 1319ms] [WARNING] <meta name="apple-mobile-web-app-capable" content="yes"> is deprecated. Please include <meta name="mobile-web-app-capable" content="yes"> @ https://app2.hyeonworks.com/explore?schemaVersion=1&orgId=1&panes=%7B%22a%22%3A%7B%22datasource%22%3A%22PBFA97CFB590B2093%22%2C%22queries%22%3A%5B%7B%22refId%22%3A%22A%22%2C%22expr%22%3A%22vendor_cluster_size%22%2C%22range%22%3Atrue%2C%22instant%22%3Afalse%2C%22editorMode%22%3A%22code%22%2C%22legendFormat%22%3A%22cluster_size%20%7B%7Bpod%7D%7D%22%2C%22datasource%22%3A%7B%22type%22%3A%22prometheus%22%2C%22uid%22%3A%22PBFA97CFB590B2093%22%7D%7D%2C%7B%22refId%22%3A%22B%22%2C%22expr%22%3A%22vendor_statistics_approximate_entries_unique%7Bcache%3D%5C%22sessions%5C%22%7D%22%2C%22range%22%3Atrue%2C%22instant%22%3Afalse%2C%22editorMode%22%3A%22code%22%2C%22legendFormat%22%3A%22sessions%20%5Cuce90%5Cuc2dc%20%7B%7Bpod%7D%7D%22%2C%22datasource%22%3A%7B%22type%22%3A%22prometheus%22%2C%22uid%22%3A%22PBFA97CFB590B2093%22%7D%7D%5D%2C%22range%22%3A%7B%22from%22%3A%221788497040000%22%2C%22to%22%3A%221788499080000%22%7D%7D%7D:0
|
||||
[ 5941ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 11107ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 14234ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 17005ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 23049ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 30565ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 44135ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 54992ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 63653ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 70658ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 90768ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 105475ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 114995ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 125443ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 137321ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 147252ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 167227ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 179100ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 187598ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 207362ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 213255ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 230544ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 248833ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 257549ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 262324ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 274443ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 294124ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 310689ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 312049ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 327025ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 339933ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 342391ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 362305ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 370693ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 378685ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 397930ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 414007ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 419130ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 420355ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 428557ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 442088ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 445041ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 446677ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 460087ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 462505ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 463673ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 482762ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 495123ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 513442ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 516414ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 536581ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 543441ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 563624ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 580510ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 588408ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 594209ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 604166ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 605295ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 621987ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 639705ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 653320ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 660911ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 678105ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 693662ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 703089ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 704712ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 719727ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 725514ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 730429ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 735135ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 736677ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 751626ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 767197ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 782052ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 797775ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 803343ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 822168ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 828683ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 845938ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 865903ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 883116ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 894375ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 898471ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 914886ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 933184ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 953353ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 963902ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 982846ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 998975ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1000721ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1003229ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1009879ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1016334ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1023805ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1043684ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1049467ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1059107ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1075856ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1076956ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1094159ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1102825ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1116077ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1134809ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1136553ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
[ 1141191ms] [ERROR] WebSocket connection to 'wss://app2.hyeonworks.com/api/live/ws' failed: Error during WebSocket handshake: Unexpected response code: 400 @ https://app2.hyeonworks.com/public/build/1518.a3f1f690c084a37f01c7.js:362
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f45e3]:
|
||||
- banner [ref=f45e4]:
|
||||
- generic [ref=f45e5]: keycloak-patterns
|
||||
- main [ref=f45e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f45e8]
|
||||
- generic [ref=f45e12]:
|
||||
- generic [ref=f45e13]:
|
||||
- generic [ref=f45e14]: Username or email
|
||||
- textbox "Username or email" [active] [ref=f45e17]
|
||||
- generic [ref=f45e18]:
|
||||
- generic [ref=f45e19]: Password
|
||||
- generic [ref=f45e21]:
|
||||
- textbox "Password" [ref=f45e24]
|
||||
- button "Show password" [ref=f45e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f45e27]:
|
||||
- button "Sign In" [ref=f45e30] [cursor=pointer]
|
||||
@@ -0,0 +1,7 @@
|
||||
- main [ref=f46e2]:
|
||||
- heading "AP3 · Backend-for-Frontend" [level=1] [ref=f46e3]
|
||||
- paragraph [ref=f46e4]: 브라우저에는 OAuth token이 전혀 전달되지 않습니다. HttpOnly session cookie로 BFF만 호출하고, BFF가 서버 보관 access token을 Resource Server 요청에 붙입니다.
|
||||
- button "Keycloak 로그인" [ref=f46e5] [cursor=pointer]
|
||||
- button "token 경계 확인" [ref=f46e6] [cursor=pointer]
|
||||
- button "BFF 경유 API 호출" [ref=f46e7] [cursor=pointer]
|
||||
- button "CSRF token으로 상태 변경" [ref=f46e8] [cursor=pointer]
|
||||
@@ -0,0 +1 @@
|
||||
- generic [active] [ref=f47e1]: "{ \"headers\" : { \"host\" : [ \"app2.hyeonworks.com\" ], \"user-agent\" : [ \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" ], \"accept\" : [ \"text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7\" ], \"accept-encoding\" : [ \"gzip, deflate, br, zstd\" ], \"accept-language\" : [ \"en-US,en;q=0.9\" ], \"cookie\" : [ \"grafana_session=60c3e7ae41ffc00665f4a2c377def399; grafana_session_expiry=1788497124; _oauth2_proxy=djIuWDI5aGRYUm9NbDl3Y205NGVTMDJZakF5T0dFM01HWTJPV000WmpCa1lUazVOalpsWWpNMk9UY3laR1ptTWcuWmpUamNTbGxVSHV1RmJjQ2ZRd2lsUQ==|1788500797|17Hbo3RDtzOldnLZx2xOt3e34lHo_v0yqRNdqdKUx-g=\" ], \"priority\" : [ \"u=0, i\" ], \"sec-ch-ua\" : [ \"\\\"Chromium\\\";v=\\\"152\\\", \\\"Not?A_Brand\\\";v=\\\"24\\\", \\\"Google Chrome\\\";v=\\\"152\\\"\" ], \"sec-ch-ua-mobile\" : [ \"?0\" ], \"sec-ch-ua-platform\" : [ \"\\\"Linux\\\"\" ], \"sec-fetch-dest\" : [ \"document\" ], \"sec-fetch-mode\" : [ \"navigate\" ], \"sec-fetch-site\" : [ \"none\" ], \"sec-fetch-user\" : [ \"?1\" ], \"upgrade-insecure-requests\" : [ \"1\" ], \"x-forwarded-email\" : [ \"labuser@example.com\" ], \"x-forwarded-host\" : [ \"app2.hyeonworks.com\" ], \"x-forwarded-port\" : [ \"443\" ], \"x-forwarded-preferred-username\" : [ \"labuser\" ], \"x-forwarded-proto\" : [ \"https\" ], \"x-forwarded-server\" : [ \"traefik-5d6fcf895-wpfhr\" ], \"x-forwarded-user\" : [ \"27df5ea9-8703-4ec5-badd-d972c583e1ff\" ], \"x-real-ip\" : [ \"100.123.124.30\" ] }, \"remoteAddr\" : \"100.123.124.30\", \"localAddr\" : \"10.42.0.53\", \"scheme\" : \"https\", \"secure\" : true, \"serverName\" : \"app2.hyeonworks.com\", \"serverPort\" : 443, \"requestUrl\" : \"https://app2.hyeonworks.com/api/echo\" }"
|
||||
@@ -0,0 +1 @@
|
||||
- generic [active] [ref=f48e1]: "{\"pattern\":\"AP3-backend-for-frontend\",\"principal\":\"labuser\",\"accessTokenStoredOnServer\":true,\"refreshTokenStoredOnServer\":true,\"browserTokenCount\":0,\"csrfProtectionEnabled\":true}"
|
||||
@@ -0,0 +1 @@
|
||||
- generic [active] [ref=f49e1]: "{ \"headers\" : { \"host\" : [ \"app2.hyeonworks.com\" ], \"user-agent\" : [ \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" ], \"accept\" : [ \"text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7\" ], \"accept-encoding\" : [ \"gzip, deflate, br, zstd\" ], \"accept-language\" : [ \"en-US,en;q=0.9\" ], \"cookie\" : [ \"grafana_session=60c3e7ae41ffc00665f4a2c377def399; grafana_session_expiry=1788497124; _oauth2_proxy=djIuWDI5aGRYUm9NbDl3Y205NGVTMDJZakF5T0dFM01HWTJPV000WmpCa1lUazVOalpsWWpNMk9UY3laR1ptTWcuWmpUamNTbGxVSHV1RmJjQ2ZRd2lsUQ==|1788500797|17Hbo3RDtzOldnLZx2xOt3e34lHo_v0yqRNdqdKUx-g=\" ], \"priority\" : [ \"u=0, i\" ], \"sec-ch-ua\" : [ \"\\\"Chromium\\\";v=\\\"152\\\", \\\"Not?A_Brand\\\";v=\\\"24\\\", \\\"Google Chrome\\\";v=\\\"152\\\"\" ], \"sec-ch-ua-mobile\" : [ \"?0\" ], \"sec-ch-ua-platform\" : [ \"\\\"Linux\\\"\" ], \"sec-fetch-dest\" : [ \"document\" ], \"sec-fetch-mode\" : [ \"navigate\" ], \"sec-fetch-site\" : [ \"none\" ], \"sec-fetch-user\" : [ \"?1\" ], \"upgrade-insecure-requests\" : [ \"1\" ], \"x-forwarded-email\" : [ \"labuser@example.com\" ], \"x-forwarded-host\" : [ \"app2.hyeonworks.com\" ], \"x-forwarded-port\" : [ \"443\" ], \"x-forwarded-preferred-username\" : [ \"labuser\" ], \"x-forwarded-proto\" : [ \"https\" ], \"x-forwarded-server\" : [ \"traefik-5d6fcf895-wpfhr\" ], \"x-forwarded-user\" : [ \"27df5ea9-8703-4ec5-badd-d972c583e1ff\" ], \"x-real-ip\" : [ \"100.123.124.30\" ] }, \"remoteAddr\" : \"100.123.124.30\", \"localAddr\" : \"10.42.0.53\", \"scheme\" : \"https\", \"secure\" : true, \"serverName\" : \"app2.hyeonworks.com\", \"serverPort\" : 443, \"requestUrl\" : \"https://app2.hyeonworks.com/api/echo\" }"
|
||||
@@ -0,0 +1 @@
|
||||
- generic [active] [ref=f50e1]: "{\"pattern\":\"AP3-backend-for-frontend\",\"principal\":\"labuser\",\"accessTokenStoredOnServer\":true,\"refreshTokenStoredOnServer\":true,\"browserTokenCount\":0,\"csrfProtectionEnabled\":true}"
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f51e3]:
|
||||
- banner [ref=f51e4]:
|
||||
- generic [ref=f51e5]: keycloak-patterns
|
||||
- main [ref=f51e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f51e8]
|
||||
- generic [ref=f51e12]:
|
||||
- generic [ref=f51e13]:
|
||||
- generic [ref=f51e14]: Username or email
|
||||
- textbox "Username or email" [active] [ref=f51e17]
|
||||
- generic [ref=f51e18]:
|
||||
- generic [ref=f51e19]: Password
|
||||
- generic [ref=f51e21]:
|
||||
- textbox "Password" [ref=f51e24]
|
||||
- button "Show password" [ref=f51e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f51e27]:
|
||||
- button "Sign In" [ref=f51e30] [cursor=pointer]
|
||||
@@ -0,0 +1,7 @@
|
||||
- main [ref=f52e2]:
|
||||
- heading "AP3 · Backend-for-Frontend" [level=1] [ref=f52e3]
|
||||
- paragraph [ref=f52e4]: 브라우저에는 OAuth token이 전혀 전달되지 않습니다. HttpOnly session cookie로 BFF만 호출하고, BFF가 서버 보관 access token을 Resource Server 요청에 붙입니다.
|
||||
- button "Keycloak 로그인" [ref=f52e5] [cursor=pointer]
|
||||
- button "token 경계 확인" [ref=f52e6] [cursor=pointer]
|
||||
- button "BFF 경유 API 호출" [ref=f52e7] [cursor=pointer]
|
||||
- button "CSRF token으로 상태 변경" [ref=f52e8] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f53e3]:
|
||||
- banner [ref=f53e4]:
|
||||
- generic [ref=f53e5]: keycloak-patterns
|
||||
- main [ref=f53e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f53e8]
|
||||
- generic [ref=f53e12]:
|
||||
- generic [ref=f53e13]:
|
||||
- generic [ref=f53e14]: Username or email
|
||||
- textbox "Username or email" [ref=f53e17]
|
||||
- generic [ref=f53e18]:
|
||||
- generic [ref=f53e19]: Password
|
||||
- generic [ref=f53e21]:
|
||||
- textbox "Password" [ref=f53e24]
|
||||
- button "Show password" [ref=f53e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f53e27]:
|
||||
- button "Sign In" [ref=f53e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f53e3]:
|
||||
- banner [ref=f53e4]:
|
||||
- generic [ref=f53e5]: keycloak-patterns
|
||||
- main [ref=f53e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f53e8]
|
||||
- generic [ref=f53e12]:
|
||||
- generic [ref=f53e13]:
|
||||
- generic [ref=f53e14]: Username or email
|
||||
- textbox "Username or email" [ref=f53e17]: labuser
|
||||
- generic [ref=f53e18]:
|
||||
- generic [ref=f53e19]: Password
|
||||
- generic [ref=f53e21]:
|
||||
- textbox "Password" [active] [ref=f53e24]: labpass
|
||||
- button "Show password" [ref=f53e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f53e27]:
|
||||
- button "Sign In" [ref=f53e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f53e3]:
|
||||
- banner [ref=f53e4]:
|
||||
- generic [ref=f53e5]: keycloak-patterns
|
||||
- main [ref=f53e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f53e8]
|
||||
- generic [ref=f53e12]:
|
||||
- generic [ref=f53e13]:
|
||||
- generic [ref=f53e14]: Username or email
|
||||
- textbox "Username or email" [ref=f53e17]: labuser
|
||||
- generic [ref=f53e18]:
|
||||
- generic [ref=f53e19]: Password
|
||||
- generic [ref=f53e21]:
|
||||
- textbox "Password" [active] [ref=f53e24]: labpass
|
||||
- button "Show password" [ref=f53e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f53e27]:
|
||||
- button "Sign In" [ref=f53e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f53e3]:
|
||||
- banner [ref=f53e4]:
|
||||
- generic [ref=f53e5]: keycloak-patterns
|
||||
- main [ref=f53e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f53e8]
|
||||
- generic [ref=f53e12]:
|
||||
- generic [ref=f53e13]:
|
||||
- generic [ref=f53e14]: Username or email
|
||||
- textbox "Username or email" [ref=f53e17]: labuser
|
||||
- generic [ref=f53e18]:
|
||||
- generic [ref=f53e19]: Password
|
||||
- generic [ref=f53e21]:
|
||||
- textbox "Password" [active] [ref=f53e24]: labpass
|
||||
- button "Show password" [ref=f53e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f53e27]:
|
||||
- button "Sign In" [ref=f53e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f54e3]:
|
||||
- banner [ref=f54e4]:
|
||||
- generic [ref=f54e5]: keycloak-patterns
|
||||
- main [ref=f54e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f54e8]
|
||||
- generic [ref=f54e12]:
|
||||
- generic [ref=f54e13]:
|
||||
- generic [ref=f54e14]: Username or email
|
||||
- textbox "Username or email" [ref=f54e17]
|
||||
- generic [ref=f54e18]:
|
||||
- generic [ref=f54e19]: Password
|
||||
- generic [ref=f54e21]:
|
||||
- textbox "Password" [ref=f54e24]
|
||||
- button "Show password" [ref=f54e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f54e27]:
|
||||
- button "Sign In" [ref=f54e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f54e3]:
|
||||
- banner [ref=f54e4]:
|
||||
- generic [ref=f54e5]: keycloak-patterns
|
||||
- main [ref=f54e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f54e8]
|
||||
- generic [ref=f54e12]:
|
||||
- generic [ref=f54e13]:
|
||||
- generic [ref=f54e14]: Username or email
|
||||
- textbox "Username or email" [ref=f54e17]: labuser
|
||||
- generic [ref=f54e18]:
|
||||
- generic [ref=f54e19]: Password
|
||||
- generic [ref=f54e21]:
|
||||
- textbox "Password" [active] [ref=f54e24]: labpass
|
||||
- button "Show password" [ref=f54e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f54e27]:
|
||||
- button "Sign In" [ref=f54e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f55e3]:
|
||||
- banner [ref=f55e4]:
|
||||
- generic [ref=f55e5]: keycloak-patterns
|
||||
- main [ref=f55e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f55e8]
|
||||
- generic [ref=f55e12]:
|
||||
- generic [ref=f55e13]:
|
||||
- generic [ref=f55e14]: Username or email
|
||||
- textbox "Username or email" [ref=f55e17]
|
||||
- generic [ref=f55e18]:
|
||||
- generic [ref=f55e19]: Password
|
||||
- generic [ref=f55e21]:
|
||||
- textbox "Password" [ref=f55e24]
|
||||
- button "Show password" [ref=f55e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f55e27]:
|
||||
- button "Sign In" [ref=f55e30] [cursor=pointer]
|
||||
@@ -0,0 +1,16 @@
|
||||
- generic [ref=f55e3]:
|
||||
- banner [ref=f55e4]:
|
||||
- generic [ref=f55e5]: keycloak-patterns
|
||||
- main [ref=f55e6]:
|
||||
- heading "Sign in to your account" [level=1] [ref=f55e8]
|
||||
- generic [ref=f55e12]:
|
||||
- generic [ref=f55e13]:
|
||||
- generic [ref=f55e14]: Username or email
|
||||
- textbox "Username or email" [ref=f55e17]: labuser
|
||||
- generic [ref=f55e18]:
|
||||
- generic [ref=f55e19]: Password
|
||||
- generic [ref=f55e21]:
|
||||
- textbox "Password" [ref=f55e24]: labpass
|
||||
- button "Show password" [ref=f55e26] [cursor=pointer]:
|
||||
- generic [aria-hidden] [ref=f55e27]:
|
||||
- button "Sign In" [ref=f55e30] [cursor=pointer]
|
||||
@@ -0,0 +1,17 @@
|
||||
- generic [ref=f56e1]:
|
||||
- generic [ref=f56e3]:
|
||||
- generic [ref=f56e4]: "403"
|
||||
- heading "Forbidden" [level=1] [ref=f56e6]
|
||||
- generic [ref=f56e8]:
|
||||
- paragraph [ref=f56e9]: More Info
|
||||
- generic [ref=f56e10] [cursor=pointer]:
|
||||
- separator [ref=f56e12]
|
||||
- generic [ref=f56e13]:
|
||||
- button "Go back" [ref=f56e16] [cursor=pointer]
|
||||
- button "Sign in" [ref=f56e19] [cursor=pointer]
|
||||
- contentinfo [ref=f56e20]:
|
||||
- paragraph [ref=f56e22]:
|
||||
- text: Secured with
|
||||
- link "OAuth2 Proxy" [ref=f56e23] [cursor=pointer]:
|
||||
- /url: https://github.com/oauth2-proxy/oauth2-proxy#oauth2_proxy
|
||||
- text: version v7.7.1
|
||||
@@ -0,0 +1 @@
|
||||
- generic [ref=f57e1]: "{ \"headers\" : { \"host\" : [ \"app2.hyeonworks.com\" ], \"user-agent\" : [ \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" ], \"accept\" : [ \"text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7\" ], \"accept-encoding\" : [ \"gzip, deflate, br, zstd\" ], \"accept-language\" : [ \"en-US,en;q=0.9\" ], \"cookie\" : [ \"grafana_session=60c3e7ae41ffc00665f4a2c377def399; grafana_session_expiry=1788497124; _oauth2_proxy=djIuWDI5aGRYUm9NbDl3Y205NGVTMDNZMkZrTUdZM01tRmlZekkwWldFell6a3lOREJpTW1KaE5UZGpOVEJoWWcuZVVmckp5VHRqY1VsXzdiV1hiX3hwdw==|1788503135|yDSo7VdgRSlvoVfj9raHPClKTlQiWDg7FauLfoUayw4=\" ], \"priority\" : [ \"u=0, i\" ], \"sec-ch-ua\" : [ \"\\\"Chromium\\\";v=\\\"152\\\", \\\"Not?A_Brand\\\";v=\\\"24\\\", \\\"Google Chrome\\\";v=\\\"152\\\"\" ], \"sec-ch-ua-mobile\" : [ \"?0\" ], \"sec-ch-ua-platform\" : [ \"\\\"Linux\\\"\" ], \"sec-fetch-dest\" : [ \"document\" ], \"sec-fetch-mode\" : [ \"navigate\" ], \"sec-fetch-site\" : [ \"none\" ], \"sec-fetch-user\" : [ \"?1\" ], \"upgrade-insecure-requests\" : [ \"1\" ], \"x-forwarded-email\" : [ \"labuser@example.com\" ], \"x-forwarded-host\" : [ \"app2.hyeonworks.com\" ], \"x-forwarded-port\" : [ \"443\" ], \"x-forwarded-preferred-username\" : [ \"labuser\" ], \"x-forwarded-proto\" : [ \"https\" ], \"x-forwarded-server\" : [ \"traefik-5d6fcf895-wpfhr\" ], \"x-forwarded-user\" : [ \"27df5ea9-8703-4ec5-badd-d972c583e1ff\" ], \"x-real-ip\" : [ \"100.123.124.30\" ] }, \"remoteAddr\" : \"100.123.124.30\", \"localAddr\" : \"10.42.0.53\", \"scheme\" : \"https\", \"secure\" : true, \"serverName\" : \"app2.hyeonworks.com\", \"serverPort\" : 443, \"requestUrl\" : \"https://app2.hyeonworks.com/api/echo\" }"
|
||||
@@ -0,0 +1 @@
|
||||
- generic [ref=f58e1]: "{ \"headers\" : { \"host\" : [ \"app2.hyeonworks.com\" ], \"user-agent\" : [ \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" ], \"accept\" : [ \"text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7\" ], \"accept-encoding\" : [ \"gzip, deflate, br, zstd\" ], \"accept-language\" : [ \"en-US,en;q=0.9\" ], \"cookie\" : [ \"grafana_session=60c3e7ae41ffc00665f4a2c377def399; grafana_session_expiry=1788497124; _oauth2_proxy=djIuWDI5aGRYUm9NbDl3Y205NGVTMHpabUV5TVdKaVpEa3lOemRrTlRFMU9USTBaV00wWWpGaE16bGhNak0zT1EuN2tTa3dnWUdISDkwMGFSSTVOSUFFUQ==|1788503202|snWKU5IRfRLoD9-bXEodGjEgfHeAw8PQaoHnecpFH90=\" ], \"priority\" : [ \"u=0, i\" ], \"sec-ch-ua\" : [ \"\\\"Chromium\\\";v=\\\"152\\\", \\\"Not?A_Brand\\\";v=\\\"24\\\", \\\"Google Chrome\\\";v=\\\"152\\\"\" ], \"sec-ch-ua-mobile\" : [ \"?0\" ], \"sec-ch-ua-platform\" : [ \"\\\"Linux\\\"\" ], \"sec-fetch-dest\" : [ \"document\" ], \"sec-fetch-mode\" : [ \"navigate\" ], \"sec-fetch-site\" : [ \"none\" ], \"sec-fetch-user\" : [ \"?1\" ], \"upgrade-insecure-requests\" : [ \"1\" ], \"x-forwarded-email\" : [ \"changed-labuser@example.com\" ], \"x-forwarded-host\" : [ \"app2.hyeonworks.com\" ], \"x-forwarded-port\" : [ \"443\" ], \"x-forwarded-preferred-username\" : [ \"labuser\" ], \"x-forwarded-proto\" : [ \"https\" ], \"x-forwarded-server\" : [ \"traefik-5d6fcf895-wpfhr\" ], \"x-forwarded-user\" : [ \"27df5ea9-8703-4ec5-badd-d972c583e1ff\" ], \"x-real-ip\" : [ \"100.123.124.30\" ] }, \"remoteAddr\" : \"100.123.124.30\", \"localAddr\" : \"10.42.1.132\", \"scheme\" : \"https\", \"secure\" : true, \"serverName\" : \"app2.hyeonworks.com\", \"serverPort\" : 443, \"requestUrl\" : \"https://app2.hyeonworks.com/api/echo\" }"
|
||||
@@ -0,0 +1,175 @@
|
||||
- generic [ref=f59e1]:
|
||||
- generic [ref=f59e4]:
|
||||
- link "Skip to main content" [ref=f59e5] [cursor=pointer]:
|
||||
- /url: "#pageContent"
|
||||
- banner [ref=f59e7]:
|
||||
- generic [ref=f59e8]:
|
||||
- link [ref=f59e10] [cursor=pointer]:
|
||||
- /url: /
|
||||
- img "Grafana" [ref=f59e11]
|
||||
- generic [ref=f59e14]:
|
||||
- button "Search or jump to..." [ref=f59e18] [cursor=pointer]
|
||||
- generic [ref=f59e19]: ctrl+k
|
||||
- generic [ref=f59e23]:
|
||||
- button "New" [ref=f59e24] [cursor=pointer]
|
||||
- button "Help" [ref=f59e30] [cursor=pointer]
|
||||
- button "News" [ref=f59e33] [cursor=pointer]
|
||||
- button "Profile" [ref=f59e36] [cursor=pointer]:
|
||||
- img "User avatar" [ref=f59e37]
|
||||
- generic [ref=f59e38]:
|
||||
- button "Open menu" [ref=f59e40] [cursor=pointer]
|
||||
- navigation "Breadcrumbs" [ref=f59e43]:
|
||||
- list [ref=f59e44]:
|
||||
- listitem [ref=f59e45]:
|
||||
- link "Home" [ref=f59e46] [cursor=pointer]:
|
||||
- /url: /
|
||||
- listitem [ref=f59e50]:
|
||||
- link "Explore" [ref=f59e51] [cursor=pointer]:
|
||||
- /url: /explore
|
||||
- listitem [ref=f59e55]:
|
||||
- generic "Prometheus" [ref=f59e56]
|
||||
- generic [ref=f59e57]:
|
||||
- generic [ref=f59e60]:
|
||||
- button "Copy shortened URL" [ref=f59e61] [cursor=pointer]
|
||||
- button "Open copy link options" [ref=f59e64] [cursor=pointer]
|
||||
- button "Toggle top search bar" [ref=f59e68] [cursor=pointer]
|
||||
- main [ref=f59e74]:
|
||||
- generic [ref=f59e76]:
|
||||
- heading "Explore" [level=1] [ref=f59e77]
|
||||
- generic [ref=f59e82]:
|
||||
- navigation "Explore toolbar" [ref=f59e84]:
|
||||
- navigation "Search links" [ref=f59e86]:
|
||||
- generic [ref=f59e87]:
|
||||
- button "Content outline" [expanded] [ref=f59e89] [cursor=pointer]:
|
||||
- generic [ref=f59e92]: Outline
|
||||
- generic [ref=f59e97] [cursor=pointer]:
|
||||
- img "Prometheus logo" [ref=f59e99]
|
||||
- textbox "Select a data source" [ref=f59e100]:
|
||||
- /placeholder: Prometheus
|
||||
- generic [ref=f59e104]:
|
||||
- button "Split the pane" [ref=f59e106] [cursor=pointer]:
|
||||
- generic [ref=f59e109]: Split
|
||||
- button "Add" [ref=f59e111] [cursor=pointer]
|
||||
- generic [ref=f59e116]:
|
||||
- 'button "Time range selected: Last 30 minutes" [ref=f59e117] [cursor=pointer]'
|
||||
- button "Zoom out time range" [ref=f59e122] [cursor=pointer]
|
||||
- generic [ref=f59e126]:
|
||||
- button "Cancel" [ref=f59e127] [cursor=pointer]
|
||||
- button "Auto refresh turned off. Choose refresh time interval" [ref=f59e129] [cursor=pointer]
|
||||
- generic [ref=f59e133]:
|
||||
- generic [ref=f59e137]:
|
||||
- button "Collapse outline" [expanded] [ref=f59e139] [cursor=pointer]:
|
||||
- img "arrow-from-right" [ref=f59e140]
|
||||
- generic [ref=f59e142]:
|
||||
- button "Content outline item collapse button" [ref=f59e143] [cursor=pointer]:
|
||||
- img "angle-right" [ref=f59e144]
|
||||
- button "Queries" [ref=f59e146] [cursor=pointer]:
|
||||
- img "arrow" [ref=f59e147]
|
||||
- generic [ref=f59e154]:
|
||||
- generic [ref=f59e156]:
|
||||
- generic [ref=f59e157]:
|
||||
- generic "Query editor row" [ref=f59e159]:
|
||||
- generic [ref=f59e160]:
|
||||
- generic [ref=f59e162]:
|
||||
- generic [ref=f59e163]:
|
||||
- button "Collapse query row" [expanded] [ref=f59e164] [cursor=pointer]
|
||||
- generic [ref=f59e167]:
|
||||
- button "Query editor row title A" [ref=f59e168] [cursor=pointer]:
|
||||
- generic [ref=f59e169]: A
|
||||
- emphasis [ref=f59e170]: (Prometheus)
|
||||
- generic [ref=f59e171]:
|
||||
- button "Show data source help" [ref=f59e173] [cursor=pointer]
|
||||
- button "Duplicate query" [ref=f59e177] [cursor=pointer]
|
||||
- button "Hide response" [ref=f59e181] [cursor=pointer]
|
||||
- button "Remove query" [ref=f59e185] [cursor=pointer]
|
||||
- button "Drag and drop to reorder" [ref=f59e188]:
|
||||
- img "Drag and drop to reorder" [ref=f59e189]
|
||||
- generic [ref=f59e192]:
|
||||
- generic [ref=f59e193]:
|
||||
- button "Kick start your query" [ref=f59e194] [cursor=pointer]
|
||||
- generic [ref=f59e197]:
|
||||
- generic [ref=f59e198] [cursor=pointer]: Explain
|
||||
- generic [ref=f59e199]:
|
||||
- checkbox "Explain Toggle switch" [ref=f59e200]
|
||||
- generic "Toggle switch" [ref=f59e201] [cursor=pointer]
|
||||
- radiogroup [ref=f59e206]:
|
||||
- generic [ref=f59e207]:
|
||||
- radio "Builder" [ref=f59e208] [cursor=pointer]
|
||||
- generic [ref=f59e209] [cursor=pointer]: Builder
|
||||
- generic [ref=f59e210]:
|
||||
- radio "Code" [checked] [ref=f59e211] [cursor=pointer]
|
||||
- generic [ref=f59e212] [cursor=pointer]: Code
|
||||
- generic [ref=f59e214]:
|
||||
- generic [ref=f59e216]:
|
||||
- button "Loading metrics..." [disabled] [ref=f59e217] [cursor=pointer]
|
||||
- code [ref=f59e224]:
|
||||
- generic [ref=f59e225]:
|
||||
- generic [ref=f59e230]: vendor_cluster_size
|
||||
- textbox "Editor content;Press Alt+F1 for Accessibility Options." [ref=f59e235]: vendor_cluster_size
|
||||
- 'button "Options Legend: cluster_size {{pod}} Format: Time series Step: auto Type: Range Exemplars: false" [ref=f59e241] [cursor=pointer]':
|
||||
- generic [ref=f59e245]:
|
||||
- heading "Options" [level=6] [ref=f59e246]
|
||||
- generic [ref=f59e247]:
|
||||
- generic [ref=f59e248]: "Legend: cluster_size {{pod}}"
|
||||
- generic [ref=f59e249]: "Format: Time series"
|
||||
- generic [ref=f59e250]: "Step: auto"
|
||||
- generic [ref=f59e251]: "Type: Range"
|
||||
- generic [ref=f59e252]: "Exemplars: false"
|
||||
- generic "Query editor row" [ref=f59e254]:
|
||||
- generic [ref=f59e255]:
|
||||
- generic [ref=f59e257]:
|
||||
- generic [ref=f59e258]:
|
||||
- button "Collapse query row" [expanded] [ref=f59e259] [cursor=pointer]
|
||||
- generic [ref=f59e262]:
|
||||
- button "Query editor row title B" [ref=f59e263] [cursor=pointer]:
|
||||
- generic [ref=f59e264]: B
|
||||
- emphasis [ref=f59e265]: (Prometheus)
|
||||
- generic [ref=f59e266]:
|
||||
- button "Show data source help" [ref=f59e268] [cursor=pointer]
|
||||
- button "Duplicate query" [ref=f59e272] [cursor=pointer]
|
||||
- button "Hide response" [ref=f59e276] [cursor=pointer]
|
||||
- button "Remove query" [ref=f59e280] [cursor=pointer]
|
||||
- button "Drag and drop to reorder" [ref=f59e283]:
|
||||
- img "Drag and drop to reorder" [ref=f59e284]
|
||||
- generic [ref=f59e287]:
|
||||
- generic [ref=f59e288]:
|
||||
- button "Kick start your query" [ref=f59e289] [cursor=pointer]
|
||||
- generic [ref=f59e292]:
|
||||
- generic [ref=f59e293] [cursor=pointer]: Explain
|
||||
- generic [ref=f59e294]:
|
||||
- checkbox "Explain Toggle switch" [ref=f59e295]
|
||||
- generic "Toggle switch" [ref=f59e296] [cursor=pointer]
|
||||
- radiogroup [ref=f59e301]:
|
||||
- generic [ref=f59e302]:
|
||||
- radio "Builder" [ref=f59e303] [cursor=pointer]
|
||||
- generic [ref=f59e304] [cursor=pointer]: Builder
|
||||
- generic [ref=f59e305]:
|
||||
- radio "Code" [checked] [ref=f59e306] [cursor=pointer]
|
||||
- generic [ref=f59e307] [cursor=pointer]: Code
|
||||
- generic [ref=f59e309]:
|
||||
- generic [ref=f59e311]:
|
||||
- button "Loading metrics..." [disabled] [ref=f59e312] [cursor=pointer]
|
||||
- code [ref=f59e319]:
|
||||
- generic [ref=f59e320]:
|
||||
- generic [ref=f59e325]: "up{job=\"keycloak\"}"
|
||||
- textbox "Editor content;Press Alt+F1 for Accessibility Options." [ref=f59e330]: "up{job=\"keycloak\"}"
|
||||
- 'button "Options Legend: up {{pod}} Format: Time series Step: auto Type: Range Exemplars: false" [ref=f59e336] [cursor=pointer]':
|
||||
- generic [ref=f59e340]:
|
||||
- heading "Options" [level=6] [ref=f59e341]
|
||||
- generic [ref=f59e342]:
|
||||
- generic [ref=f59e343]: "Legend: up {{pod}}"
|
||||
- generic [ref=f59e344]: "Format: Time series"
|
||||
- generic [ref=f59e345]: "Step: auto"
|
||||
- generic [ref=f59e346]: "Type: Range"
|
||||
- generic [ref=f59e347]: "Exemplars: false"
|
||||
- generic [ref=f59e348]:
|
||||
- button "Add query" [ref=f59e349] [cursor=pointer]
|
||||
- button "Query history" [ref=f59e353] [cursor=pointer]
|
||||
- button "Query inspector" [ref=f59e357] [cursor=pointer]
|
||||
- generic:
|
||||
- main
|
||||
- generic [ref=f59e364]:
|
||||
- alert
|
||||
- alert
|
||||
- complementary
|
||||
- complementary
|
||||
@@ -0,0 +1,56 @@
|
||||
- generic [ref=f62e4]:
|
||||
- link "Skip to main content" [ref=f62e5] [cursor=pointer]:
|
||||
- /url: "#pageContent"
|
||||
- banner [ref=f62e7]:
|
||||
- generic [ref=f62e8]:
|
||||
- link [ref=f62e10] [cursor=pointer]:
|
||||
- /url: /
|
||||
- img "Grafana" [ref=f62e11]
|
||||
- generic [ref=f62e14]:
|
||||
- button "Search or jump to..." [ref=f62e18] [cursor=pointer]
|
||||
- generic [ref=f62e19]: ctrl+k
|
||||
- generic [ref=f62e23]:
|
||||
- button "New" [ref=f62e24] [cursor=pointer]
|
||||
- button "Help" [ref=f62e30] [cursor=pointer]
|
||||
- button "News" [ref=f62e33] [cursor=pointer]
|
||||
- button "Profile" [ref=f62e36] [cursor=pointer]:
|
||||
- img "User avatar" [ref=f62e37]
|
||||
- generic [ref=f62e38]:
|
||||
- button "Open menu" [ref=f62e40] [cursor=pointer]
|
||||
- navigation "Breadcrumbs" [ref=f62e43]:
|
||||
- list [ref=f62e44]:
|
||||
- listitem [ref=f62e45]:
|
||||
- link "Home" [ref=f62e46] [cursor=pointer]:
|
||||
- /url: /
|
||||
- listitem [ref=f62e50]:
|
||||
- link "Explore" [ref=f62e51] [cursor=pointer]:
|
||||
- /url: /explore
|
||||
- listitem [ref=f62e55]:
|
||||
- generic "Prometheus" [ref=f62e56]
|
||||
- generic [ref=f62e57]:
|
||||
- button "Show more items" [ref=f62e60] [cursor=pointer]
|
||||
- button "Toggle top search bar" [ref=f62e64] [cursor=pointer]
|
||||
- main [ref=f62e70]:
|
||||
- generic [ref=f62e72]:
|
||||
- heading "Explore" [level=1] [ref=f62e73]
|
||||
- generic [ref=f62e78]:
|
||||
- navigation "Explore toolbar" [ref=f62e80]:
|
||||
- navigation "Search links" [ref=f62e82]:
|
||||
- generic [ref=f62e83]:
|
||||
- button "Content outline" [expanded] [ref=f62e85] [cursor=pointer]:
|
||||
- generic [ref=f62e88]: Outline
|
||||
- generic [ref=f62e93] [cursor=pointer]:
|
||||
- img "Prometheus logo" [ref=f62e95]
|
||||
- textbox "Select a data source" [ref=f62e96]:
|
||||
- /placeholder: Prometheus
|
||||
- button "Show more items" [ref=f62e102] [cursor=pointer]
|
||||
- generic [ref=f62e106]:
|
||||
- button "Collapse outline" [expanded] [ref=f62e112] [cursor=pointer]:
|
||||
- img "arrow-from-right" [ref=f62e113]
|
||||
- generic [ref=f62e119]:
|
||||
- generic [ref=f62e122]:
|
||||
- button "Add query" [ref=f62e123] [cursor=pointer]
|
||||
- button "Query history" [ref=f62e127] [cursor=pointer]
|
||||
- button "Query inspector" [ref=f62e131] [cursor=pointer]
|
||||
- generic:
|
||||
- main
|
||||
@@ -0,0 +1,29 @@
|
||||
- generic [ref=f65e4]:
|
||||
- link "Skip to main content" [ref=f65e5] [cursor=pointer]:
|
||||
- /url: "#pageContent"
|
||||
- banner [ref=f65e7]:
|
||||
- generic [ref=f65e8]:
|
||||
- link [ref=f65e10] [cursor=pointer]:
|
||||
- /url: /
|
||||
- img "Grafana" [ref=f65e11]
|
||||
- generic [ref=f65e14]:
|
||||
- button "Search or jump to..." [ref=f65e18] [cursor=pointer]
|
||||
- generic [ref=f65e19]: ctrl+k
|
||||
- generic [ref=f65e23]:
|
||||
- button "New" [ref=f65e24] [cursor=pointer]
|
||||
- button "Help" [ref=f65e30] [cursor=pointer]
|
||||
- button "News" [ref=f65e33] [cursor=pointer]
|
||||
- button "Profile" [ref=f65e36] [cursor=pointer]:
|
||||
- img "User avatar" [ref=f65e37]
|
||||
- generic [ref=f65e38]:
|
||||
- button "Open menu" [ref=f65e40] [cursor=pointer]
|
||||
- navigation "Breadcrumbs" [ref=f65e43]:
|
||||
- list [ref=f65e44]:
|
||||
- listitem [ref=f65e45]:
|
||||
- link "Home" [ref=f65e46] [cursor=pointer]:
|
||||
- /url: /
|
||||
- listitem [ref=f65e50]:
|
||||
- generic "Explore" [ref=f65e51]
|
||||
- button "Toggle top search bar" [ref=f65e53] [cursor=pointer]
|
||||
- main [ref=f65e59]:
|
||||
- heading "Explore" [level=1] [ref=f65e62]
|
||||
@@ -0,0 +1,12 @@
|
||||
# 다이어그램 규약
|
||||
|
||||
| 표현 | 뜻 |
|
||||
|---|---|
|
||||
| 실선 상자 | 살아 있는 구성 요소 |
|
||||
| 붉은 점선 상자 | 이 실험에서 죽이거나 막은 것 |
|
||||
| ✂ 붉은 X | 주입 지점 |
|
||||
| 실선 화살표 | 정상 경로 |
|
||||
| 붉은 점선 화살표 | 실험에서 깨진 경로 |
|
||||
| 회색 글씨 | 측정값 |
|
||||
|
||||
SVG 는 GitHub 에서 그대로 렌더링되며 외부 폰트를 쓰지 않는다.
|
||||
@@ -0,0 +1,26 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 300" width="700" height="300" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">A-2 · PostgreSQL 정지 — 살아남는 노드가 없다</text>
|
||||
<rect class="box" x="30" y="46" width="180" height="52"/><text class="t" x="120" y="68" text-anchor="middle">keycloak-1</text><text class="s" x="120" y="86" text-anchor="middle">캐시: 세션 N개</text>
|
||||
<rect class="box" x="480" y="46" width="180" height="52"/><text class="t" x="570" y="68" text-anchor="middle">keycloak-0</text><text class="s" x="570" y="86" text-anchor="middle">캐시: 세션 M개</text>
|
||||
<path class="ln" d="M210,72 L480,72"/><text class="s" x="345" y="66" text-anchor="middle">7800 · 살아 있다</text>
|
||||
<path class="bad" d="M120,100 L300,150"/><path class="bad" d="M570,100 L400,150"/>
|
||||
<rect class="dead" x="270" y="156" width="160" height="52"/>
|
||||
<text class="r" x="350" y="178" text-anchor="middle">postgres ✗</text><text class="s" x="350" y="196" text-anchor="middle">replicas=0</text>
|
||||
<rect class="dead" x="30" y="228" width="290" height="52"/>
|
||||
<text class="r" x="175" y="250" text-anchor="middle">양쪽 모두 NotReady</text><text class="s" x="175" y="268" text-anchor="middle">ready 주소 = [] · 외부 503</text>
|
||||
<rect class="box" x="370" y="228" width="290" height="52"/>
|
||||
<text class="t" x="515" y="250" text-anchor="middle">up{job="keycloak"} = 1</text><text class="s" x="515" y="268" text-anchor="middle">프로세스는 살아 있다 — up 은 못 잡는다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.4 KiB |
@@ -0,0 +1,36 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 720 330" width="720" height="330" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
</style>
|
||||
<defs><marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker></defs>
|
||||
<text class="h" x="16" y="24">A-7 · 같은 주입, 같은 관측, 정반대 결과</text>
|
||||
|
||||
<text class="h" x="180" y="52" text-anchor="middle">persistent (KC 26 기본)</text>
|
||||
<rect class="box" x="30" y="62" width="300" height="54"/>
|
||||
<text class="t" x="180" y="84" text-anchor="middle">keycloak ×2 — 로컬 캐시</text>
|
||||
<path class="ln" d="M180,116 L180,140"/>
|
||||
<rect class="ok" x="70" y="142" width="220" height="40"/>
|
||||
<text class="g" x="180" y="167" text-anchor="middle">PostgreSQL — 진실의 원천</text>
|
||||
|
||||
<text class="h" x="540" y="52" text-anchor="middle">volatile (KC 24 이전 방식)</text>
|
||||
<rect class="box" x="390" y="62" width="300" height="54"/>
|
||||
<text class="t" x="540" y="84" text-anchor="middle">keycloak ×2 — 캐시가 곧 진실</text>
|
||||
<path class="ln" d="M470,116 L470,140"/><path class="ln" d="M610,140 L610,116"/>
|
||||
<rect class="ok" x="430" y="142" width="220" height="40"/>
|
||||
<text class="g" x="540" y="167" text-anchor="middle">클러스터 복제 (7800)</text>
|
||||
|
||||
<rect class="box" x="30" y="202" width="660" height="112"/>
|
||||
<text class="t" x="360" y="224" text-anchor="middle">뒤집힌 세 결과</text>
|
||||
<text class="s" x="200" y="248" text-anchor="middle">A-1 7800 차단 후 교차 refresh</text>
|
||||
<text class="g" x="430" y="248" text-anchor="middle">200</text><text class="r" x="560" y="248" text-anchor="middle">400 Session not active</text>
|
||||
<text class="s" x="200" y="272" text-anchor="middle">A-8 롤링 재시작 후 refresh</text>
|
||||
<text class="g" x="430" y="272" text-anchor="middle">200</text><text class="r" x="560" y="272" text-anchor="middle">400 Session not active</text>
|
||||
<text class="s" x="200" y="296" text-anchor="middle">A-2 DB 정지 중 새 로그인</text>
|
||||
<text class="r" x="430" y="296" text-anchor="middle">500</text><text class="g" x="560" y="296" text-anchor="middle">200</text>
|
||||
<text class="s" x="430" y="230" text-anchor="middle">persistent</text><text class="s" x="560" y="230" text-anchor="middle">volatile</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.8 KiB |
@@ -0,0 +1,33 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 330" width="700" height="330" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">B-1 · Redis 는 세션만 옮기고 토큰은 두고 간다</text>
|
||||
<rect class="box" x="30" y="46" width="140" height="46"/><text class="t" x="100" y="66" text-anchor="middle">bff-0</text><text class="s" x="100" y="82" text-anchor="middle">kc-lab-1</text>
|
||||
<rect class="box" x="30" y="104" width="140" height="46"/><text class="t" x="100" y="124" text-anchor="middle">bff-1</text><text class="s" x="100" y="140" text-anchor="middle">kc-lab-2</text>
|
||||
<rect class="ok" x="330" y="46" width="330" height="60"/>
|
||||
<text class="t" x="495" y="68" text-anchor="middle">Redis — Application Session</text>
|
||||
<text class="s" x="495" y="86" text-anchor="middle">sessionRepository → RedisSessionRepository ✔ 옮겨졌다</text>
|
||||
<text class="s" x="495" y="100" text-anchor="middle">필드: SPRING_SECURITY_CONTEXT · TTL 1772초</text>
|
||||
<rect class="dead" x="330" y="122" width="330" height="60"/>
|
||||
<text class="r" x="495" y="144" text-anchor="middle">프로세스 메모리 — OAuth2AuthorizedClient</text>
|
||||
<text class="s" x="495" y="162" text-anchor="middle">InMemoryOAuth2AuthorizedClientService ✗ 그대로</text>
|
||||
<text class="s" x="495" y="176" text-anchor="middle">access token · refresh token 이 여기 있다</text>
|
||||
<path class="ln" d="M170,69 L330,69"/><path class="ln" d="M170,127 L330,80"/>
|
||||
<path class="bad" d="M170,140 L330,150"/>
|
||||
<rect class="box" x="30" y="210" width="630" height="90"/>
|
||||
<text class="t" x="345" y="234" text-anchor="middle">그 결과 사용자에게 보이는 것</text>
|
||||
<text class="s" x="345" y="256" text-anchor="middle">principal: labuser ← 로그인은 되어 있다</text>
|
||||
<text class="s" x="345" y="272" text-anchor="middle">accessTokenStoredOnServer: false ← 토큰이 없다</text>
|
||||
<text class="r" x="345" y="292" text-anchor="middle">완전히 로그아웃되는 편이 차라리 낫다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.8 KiB |
@@ -0,0 +1,29 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 300" width="700" height="300" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">B-3 · 동시 refresh — 경쟁이 아니라 세션 파괴</text>
|
||||
<rect class="box" x="30" y="46" width="150" height="40"/><text class="t" x="105" y="71" text-anchor="middle">같은 refresh token ×5</text>
|
||||
<path class="ln" d="M180,66 L280,66"/>
|
||||
<rect class="box" x="280" y="42" width="180" height="48"/><text class="t" x="370" y="62" text-anchor="middle">Keycloak</text>
|
||||
<text class="s" x="370" y="80" text-anchor="middle">rotation ON · maxReuse=0</text>
|
||||
<path class="ln" d="M460,58 L560,58"/><rect class="box" x="560" y="42" width="110" height="24"/><text class="s" x="615" y="58" text-anchor="middle">1× HTTP 200</text>
|
||||
<path class="bad" d="M460,78 L560,78"/><rect class="dead" x="560" y="66" width="110" height="24"/><text class="s" x="615" y="82" text-anchor="middle">4× HTTP 400</text>
|
||||
<rect class="dead" x="120" y="120" width="460" height="70"/>
|
||||
<text class="r" x="350" y="144" text-anchor="middle">재사용 탐지가 client session 을 제거한다</text>
|
||||
<text class="s" x="350" y="164" text-anchor="middle">user_session 은 남고 client_session = 0 (정상 세션은 1)</text>
|
||||
<text class="s" x="350" y="180" text-anchor="middle">그래서 오류가 "Session doesn't have required client"</text>
|
||||
<rect class="dead" x="120" y="210" width="460" height="60"/>
|
||||
<text class="r" x="350" y="234" text-anchor="middle">★ 이긴 요청의 새 토큰도 곧바로 400</text>
|
||||
<text class="s" x="350" y="254" text-anchor="middle">재시도로 회복 불가 → Q2 의 판정은 lock</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.5 KiB |
@@ -0,0 +1,37 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 290" width="700" height="290" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">B-4 · edge 가 설정하지 않은 헤더는 그대로 통과한다</text>
|
||||
<rect class="box" x="30" y="46" width="130" height="60"/><text class="t" x="95" y="68" text-anchor="middle">공격자</text>
|
||||
<text class="s" x="95" y="86" text-anchor="middle">X-Auth-Request-</text><text class="s" x="95" y="100" text-anchor="middle">Roles: admin</text>
|
||||
<path class="ln" d="M160,76 L250,76"/>
|
||||
<rect class="box" x="250" y="40" width="180" height="72"/><text class="t" x="340" y="62" text-anchor="middle">nginx</text>
|
||||
<text class="s" x="340" y="82" text-anchor="middle">proxy_set_header 한 것만 덮어쓴다</text>
|
||||
<text class="r" x="340" y="100" text-anchor="middle">X-Auth-Request-* 는 설정이 없다</text>
|
||||
<path class="bad" d="M430,76 L520,76"/>
|
||||
<rect class="dead" x="520" y="46" width="150" height="60"/>
|
||||
<text class="r" x="595" y="68" text-anchor="middle">upstream</text>
|
||||
<text class="s" x="595" y="86" text-anchor="middle">['viewer','admin']</text><text class="s" x="595" y="100" text-anchor="middle">둘 다 도착 · 검증 없음</text>
|
||||
<rect class="box" x="30" y="134" width="310" height="66"/>
|
||||
<text class="t" x="185" y="156" text-anchor="middle">구분자 문제</text>
|
||||
<text class="s" x="185" y="176" text-anchor="middle">"admin,editor" 와 "role-with,comma" 가</text>
|
||||
<text class="s" x="185" y="192" text-anchor="middle">도착 시점에 구별되지 않는다</text>
|
||||
<rect class="box" x="360" y="134" width="310" height="66"/>
|
||||
<text class="t" x="515" y="156" text-anchor="middle">크기는 절벽이다</text>
|
||||
<text class="s" x="515" y="176" text-anchor="middle">4KB 통과 · 8KB → Tomcat 400</text>
|
||||
<text class="s" x="515" y="192" text-anchor="middle">16KB → 연결 끊김 (nginx)</text>
|
||||
<rect class="dead" x="30" y="222" width="640" height="50"/>
|
||||
<text class="r" x="350" y="244" text-anchor="middle">헤더가 인가 근거가 되면 위조 가능성이 곧 권한 상승이다</text>
|
||||
<text class="s" x="350" y="262" text-anchor="middle">Q4 의 5문항 중 2·4번 해당 → Q4 자신의 기준으로 BFF 구조</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 3.1 KiB |
@@ -0,0 +1,35 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 300" width="700" height="300" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">B-5 · 파드가 Ready 인 채로 계속 실패한다</text>
|
||||
<rect class="box" x="30" y="46" width="180" height="76"/>
|
||||
<text class="t" x="120" y="68" text-anchor="middle">bff ×2</text>
|
||||
<text class="g" x="120" y="90" text-anchor="middle">Ready = true</text>
|
||||
<text class="s" x="120" y="110" text-anchor="middle">Service 에 그대로 남는다</text>
|
||||
<path class="bad" d="M210,84 L330,84"/>
|
||||
<rect class="dead" x="330" y="58" width="160" height="52"/>
|
||||
<text class="r" x="410" y="80" text-anchor="middle">redis ✗</text><text class="s" x="410" y="98" text-anchor="middle">replicas=0</text>
|
||||
<rect class="box" x="30" y="146" width="310" height="110"/>
|
||||
<text class="t" x="185" y="168" text-anchor="middle">health group 이 갈랐다</text>
|
||||
<text class="r" x="185" y="192" text-anchor="middle">/actuator/health → 503</text>
|
||||
<text class="g" x="185" y="214" text-anchor="middle">/actuator/health/readiness → 200 UP</text>
|
||||
<text class="s" x="185" y="238" text-anchor="middle">redis 지표가 readiness 그룹에 없다</text>
|
||||
<rect class="box" x="360" y="146" width="310" height="110"/>
|
||||
<text class="t" x="515" y="168" text-anchor="middle">A-2 와 정반대</text>
|
||||
<text class="s" x="515" y="192" text-anchor="middle">A-2 Keycloak: DB 검사가 readiness 에</text>
|
||||
<text class="s" x="515" y="208" text-anchor="middle">→ NotReady → 503 (명확)</text>
|
||||
<text class="s" x="515" y="230" text-anchor="middle">B-5 BFF: 없음 → Ready 유지</text>
|
||||
<text class="r" x="515" y="248" text-anchor="middle">→ HTTP 000 (멈춤)</text>
|
||||
<text class="s" x="16" y="284">영속화: 볼륨 없이 AOF 만 켜면 appendonlydir 은 생기지만 파드 삭제로 전부 사라진다 — 볼륨이 먼저다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.8 KiB |
@@ -0,0 +1,34 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 260" width="700" height="260" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">B-6 · 회전은 안전하고 옛 키를 버리는 순간이 위험하다</text>
|
||||
<rect class="ok" x="30" y="46" width="190" height="76"/>
|
||||
<text class="t" x="125" y="68" text-anchor="middle">t0 — 키 A 만</text>
|
||||
<text class="s" x="125" y="88" text-anchor="middle">발급 A · 검증 A</text>
|
||||
<text class="s" x="125" y="108" text-anchor="middle">JWKS RS256 1개</text>
|
||||
<path class="ln" d="M220,84 L255,84"/>
|
||||
<rect class="ok" x="255" y="46" width="190" height="76"/>
|
||||
<text class="t" x="350" y="68" text-anchor="middle">t1 — B 추가 (priority 200)</text>
|
||||
<text class="g" x="350" y="88" text-anchor="middle">발급 B · 검증 A+B</text>
|
||||
<text class="s" x="350" y="108" text-anchor="middle">옛 토큰 200 · 새 토큰 200</text>
|
||||
<path class="bad" d="M445,84 L480,84"/>
|
||||
<rect class="dead" x="480" y="46" width="190" height="76"/>
|
||||
<text class="t" x="575" y="68" text-anchor="middle">t2 — A 제거</text>
|
||||
<text class="r" x="575" y="88" text-anchor="middle">옛 토큰 즉시 401</text>
|
||||
<text class="s" x="575" y="108" text-anchor="middle">캐시가 유예를 주지 않는다</text>
|
||||
<rect class="box" x="30" y="146" width="640" height="60"/>
|
||||
<text class="t" x="350" y="168" text-anchor="middle">겹침 구간(t1~t2)의 최소 길이 = 옛 키로 서명된 것 중 가장 오래 사는 것의 수명</text>
|
||||
<text class="s" x="350" y="190" text-anchor="middle">access token 60초 · refresh token 1800초 → 최소 30분</text>
|
||||
<text class="s" x="16" y="234">모르는 kid 를 만나면 JWKS 를 다시 받으므로 제거가 즉시 반영된다. 유예는 옛 키를 남겨두는 기간으로 만든다.</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.7 KiB |
@@ -0,0 +1,31 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 300" width="700" height="300" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">C-1 · SSO 의 구조와 IdP 로그아웃의 한계</text>
|
||||
<rect class="box" x="220" y="42" width="260" height="52"/>
|
||||
<text class="t" x="350" y="64" text-anchor="middle">Keycloak user session ×1</text>
|
||||
<text class="s" x="350" y="82" text-anchor="middle">oqOjHekin4JU-BZjgQLjUByW</text>
|
||||
<path class="ln" d="M300,96 L180,130"/><path class="ln" d="M400,96 L520,130"/>
|
||||
<rect class="box" x="60" y="134" width="240" height="52"/>
|
||||
<text class="t" x="180" y="156" text-anchor="middle">client session — bff-confidential</text>
|
||||
<text class="s" x="180" y="174" text-anchor="middle">app1 · Redis 세션 + PostgreSQL 토큰</text>
|
||||
<rect class="box" x="400" y="134" width="240" height="52"/>
|
||||
<text class="t" x="520" y="156" text-anchor="middle">client session — oauth2-proxy</text>
|
||||
<text class="s" x="520" y="174" text-anchor="middle">app2 · 쿠키 티켓 + Redis 세션</text>
|
||||
<rect class="dead" x="220" y="206" width="260" height="40"/>
|
||||
<text class="r" x="350" y="231" text-anchor="middle">IdP 세션 삭제 ✗</text>
|
||||
<path class="bad" d="M300,246 L200,262"/><path class="bad" d="M400,246 L500,262"/>
|
||||
<rect class="ok" x="60" y="256" width="240" height="34"/><text class="g" x="180" y="278" text-anchor="middle">app1 그대로 동작</text>
|
||||
<rect class="ok" x="400" y="256" width="240" height="34"/><text class="g" x="520" y="278" text-anchor="middle">app2 그대로 동작</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.4 KiB |
@@ -0,0 +1,30 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 270" width="700" height="270" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">D-1 · 빈 데이터베이스가 200 을 냈다</text>
|
||||
<rect class="box" x="30" y="46" width="180" height="46"/><text class="t" x="120" y="66" text-anchor="middle">pg_dump</text><text class="s" x="120" y="82" text-anchor="middle">395KB · 101 테이블 · 세션 포함</text>
|
||||
<path class="ln" d="M210,69 L270,69"/>
|
||||
<rect class="dead" x="270" y="42" width="180" height="54"/>
|
||||
<text class="r" x="360" y="64" text-anchor="middle">DROP SCHEMA CASCADE</text><text class="s" x="360" y="84" text-anchor="middle">남은 테이블 0</text>
|
||||
<path class="ln" d="M450,69 L510,69"/>
|
||||
<rect class="ok" x="510" y="42" width="160" height="54"/>
|
||||
<text class="g" x="590" y="64" text-anchor="middle">복구 1초</text><text class="s" x="590" y="84" text-anchor="middle">오류 0건 · 재시작 0회</text>
|
||||
<rect class="box" x="30" y="118" width="640" height="76"/>
|
||||
<text class="t" x="350" y="140" text-anchor="middle">테이블이 0개일 때 무엇이 깨졌는가 — 전부가 아니다</text>
|
||||
<text class="g" x="350" y="162" text-anchor="middle">/protocol/openid-connect/certs → 200 (realm 키가 캐시에 있다)</text>
|
||||
<text class="r" x="350" y="182" text-anchor="middle">/.well-known → 500 토큰 발급 → 400</text>
|
||||
<rect class="dead" x="30" y="210" width="640" height="46"/>
|
||||
<text class="r" x="350" y="232" text-anchor="middle">헬스체크는 "DB 가 살아 있다"만 보고 "데이터가 있다"는 안 본다</text>
|
||||
<text class="s" x="350" y="250" text-anchor="middle">RPO = 백업 주기 + A-3 의 synchronous_commit 손실 · 덤프는 같은 호스트 /tmp 에 있었다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.6 KiB |
@@ -0,0 +1,31 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 280" width="700" height="280" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">D-3 · 네 경로 중 RBAC 만 실제로 감춘다</text>
|
||||
<rect class="dead" x="30" y="46" width="310" height="60"/>
|
||||
<text class="r" x="185" y="68" text-anchor="middle">kubectl get -o jsonpath | base64 -d</text>
|
||||
<text class="s" x="185" y="88" text-anchor="middle">POSTGRES_PASSWORD = lab-postgres-change-me</text>
|
||||
<rect class="dead" x="360" y="46" width="310" height="60"/>
|
||||
<text class="r" x="515" y="68" text-anchor="middle">저장소 (at rest)</text>
|
||||
<text class="s" x="515" y="88" text-anchor="middle">Encryption Disabled · state.db 에 평문</text>
|
||||
<rect class="dead" x="30" y="120" width="310" height="60"/>
|
||||
<text class="r" x="185" y="142" text-anchor="middle">파드 안</text>
|
||||
<text class="s" x="185" y="162" text-anchor="middle">KEYCLOAK_CLIENT_SECRET=... 환경변수</text>
|
||||
<rect class="ok" x="360" y="120" width="310" height="60"/>
|
||||
<text class="g" x="515" y="142" text-anchor="middle">RBAC</text>
|
||||
<text class="s" x="515" y="162" text-anchor="middle">default SA 는 get secrets 불가</text>
|
||||
<rect class="box" x="30" y="200" width="640" height="60"/>
|
||||
<text class="t" x="350" y="222" text-anchor="middle">describe 는 "14 bytes" 만 보여줘 감춰졌다는 착각을 준다</text>
|
||||
<text class="s" x="350" y="244" text-anchor="middle">base64 는 감추기 위한 것이 아니라 YAML 에 임의 바이트를 담기 위한 인코딩이다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.4 KiB |
@@ -0,0 +1,30 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 700 250" width="700" height="250" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.r{font-size:12px;fill:#cf222e;font-weight:600}.g{font-size:12px;fill:#1a7f37;font-weight:600}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.dead{fill:#fff5f5;stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;rx:6}
|
||||
.ok{fill:#f6fdf6;stroke:#1a7f37;stroke-width:1.6;rx:6}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
.bad{stroke:#cf222e;stroke-width:1.6;stroke-dasharray:5 3;fill:none;marker-end:url(#b)}
|
||||
</style>
|
||||
<defs>
|
||||
<marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker>
|
||||
<marker id="b" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#cf222e"/></marker>
|
||||
</defs>
|
||||
<text class="h" x="16" y="24">D-4 · 인증서 체인과 SAN 제약</text>
|
||||
<rect class="ok" x="30" y="46" width="300" height="104"/>
|
||||
<text class="t" x="180" y="68" text-anchor="middle">체인 4단계 · Verify return code: 0</text>
|
||||
<text class="s" x="180" y="90" text-anchor="middle">0 CN=auth.hyeonworks.com</text>
|
||||
<text class="s" x="180" y="106" text-anchor="middle">1 Let's Encrypt YE2</text>
|
||||
<text class="s" x="180" y="122" text-anchor="middle">2 ISRG Root YE</text>
|
||||
<text class="s" x="180" y="138" text-anchor="middle">3 ISRG Root X2</text>
|
||||
<rect class="box" x="360" y="46" width="310" height="104"/>
|
||||
<text class="t" x="515" y="68" text-anchor="middle">SAN 3개 · 와일드카드 아님</text>
|
||||
<text class="s" x="515" y="90" text-anchor="middle">auth · app1 · app2</text>
|
||||
<text class="r" x="515" y="114" text-anchor="middle">네 번째 이름이 없다</text>
|
||||
<text class="s" x="515" y="134" text-anchor="middle">B-7 에서 Grafana 의 app2 를 빌려야 했다</text>
|
||||
<rect class="box" x="30" y="168" width="640" height="60"/>
|
||||
<text class="t" x="350" y="190" text-anchor="middle">단계가 1개면 cert.pem, 2개 이상이면 fullchain.pem 이다</text>
|
||||
<text class="s" x="350" y="212" text-anchor="middle">브라우저는 중간 인증서를 캐시하므로 cert.pem 실수는 캐시 없는 클라이언트에서만 드러난다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 2.4 KiB |
@@ -0,0 +1,57 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 760 470" width="760" height="470" font-family="system-ui,-apple-system,Segoe UI,Roboto,sans-serif">
|
||||
<style>
|
||||
.t{font-size:13px;fill:#1f2328}.s{font-size:11px;fill:#59636e}.h{font-size:14px;font-weight:600;fill:#1f2328}
|
||||
.box{fill:#fff;stroke:#8c959f;stroke-width:1.4;rx:6}
|
||||
.host{fill:#f6f8fa;stroke:#59636e;stroke-width:1.6;rx:8}
|
||||
.node{fill:#fff;stroke:#0969da;stroke-width:1.6;rx:8}
|
||||
.ln{stroke:#59636e;stroke-width:1.4;fill:none;marker-end:url(#a)}
|
||||
</style>
|
||||
<defs><marker id="a" markerWidth="9" markerHeight="9" refX="8" refY="4.5" orient="auto"><path d="M0,0 L9,4.5 L0,9 z" fill="#59636e"/></marker></defs>
|
||||
|
||||
<rect class="box" x="290" y="12" width="180" height="38"/>
|
||||
<text class="t" x="380" y="30" text-anchor="middle">개발 노트북</text>
|
||||
<text class="s" x="380" y="44" text-anchor="middle">브라우저 · kubectl · Playwright</text>
|
||||
<path class="ln" d="M380,52 L380,80"/>
|
||||
<text class="s" x="392" y="70">https · tailnet 100.x · split DNS</text>
|
||||
|
||||
<rect class="host" x="40" y="84" width="680" height="66"/>
|
||||
<text class="h" x="56" y="106">test-server</text>
|
||||
<text class="s" x="56" y="122">Arch Linux · 12GB · WiFi only · sudo 는 비밀번호 필요</text>
|
||||
<rect class="box" x="430" y="94" width="270" height="46"/>
|
||||
<text class="t" x="565" y="112" text-anchor="middle">nginx :443 — TLS 종료</text>
|
||||
<text class="s" x="565" y="128" text-anchor="middle">auth / app1 / app2 (SAN 3개, 와일드카드 아님)</text>
|
||||
|
||||
<path class="ln" d="M240,152 L200,186"/><path class="ln" d="M520,152 L560,186"/>
|
||||
<text class="s" x="330" y="172" text-anchor="middle">http · libvirt NAT (virbr0)</text>
|
||||
|
||||
<rect class="node" x="40" y="190" width="320" height="250"/>
|
||||
<text class="h" x="56" y="212">kc-lab-1 · 5120MB</text>
|
||||
<text class="s" x="56" y="228">k3s server · 10.42.0.0/24</text>
|
||||
<rect class="box" x="56" y="238" width="130" height="26"/><text class="t" x="121" y="255" text-anchor="middle">traefik ×1</text>
|
||||
<rect class="box" x="196" y="238" width="148" height="26"/><text class="t" x="270" y="255" text-anchor="middle">coredns</text>
|
||||
<rect class="box" x="56" y="272" width="130" height="26"/><text class="t" x="121" y="289" text-anchor="middle">keycloak-1</text>
|
||||
<rect class="box" x="196" y="272" width="148" height="26"/><text class="t" x="270" y="289" text-anchor="middle">bff (1/2)</text>
|
||||
<rect class="box" x="56" y="306" width="288" height="26"/><text class="t" x="200" y="323" text-anchor="middle">oauth2-proxy (1/2)</text>
|
||||
<rect class="box" x="56" y="340" width="288" height="46"/>
|
||||
<text class="t" x="200" y="358" text-anchor="middle">prometheus (PVC) · grafana</text>
|
||||
<text class="s" x="200" y="374" text-anchor="middle">관측 스택은 여기 고정 — 죽이지 않는다</text>
|
||||
|
||||
<rect class="node" x="400" y="190" width="320" height="250"/>
|
||||
<text class="h" x="416" y="212">kc-lab-2 · 4096MB</text>
|
||||
<text class="s" x="416" y="228">k3s agent · 10.42.1.0/24</text>
|
||||
<rect class="box" x="416" y="238" width="288" height="26"/><text class="t" x="560" y="255" text-anchor="middle">keycloak-0</text>
|
||||
<rect class="box" x="416" y="272" width="140" height="26"/><text class="t" x="486" y="289" text-anchor="middle">bff (2/2)</text>
|
||||
<rect class="box" x="566" y="272" width="138" height="26"/><text class="t" x="635" y="289" text-anchor="middle">oauth2-proxy</text>
|
||||
<rect class="box" x="416" y="306" width="140" height="46"/>
|
||||
<text class="t" x="486" y="324" text-anchor="middle">postgres</text><text class="s" x="486" y="340" text-anchor="middle">PVC (노드 고정)</text>
|
||||
<rect class="box" x="566" y="306" width="138" height="46"/>
|
||||
<text class="t" x="635" y="324" text-anchor="middle">redis</text><text class="s" x="635" y="340" text-anchor="middle">PVC + AOF</text>
|
||||
<text class="s" x="560" y="374" text-anchor="middle">장애 주입은 여기</text>
|
||||
|
||||
<path d="M360,290 L400,290" stroke="#0969da" stroke-width="1.6" fill="none" marker-end="url(#a)"/>
|
||||
<path d="M400,300 L360,300" stroke="#0969da" stroke-width="1.6" fill="none" marker-end="url(#a)"/>
|
||||
<text class="s" x="380" y="284" text-anchor="middle">7800</text>
|
||||
<text class="s" x="380" y="318" text-anchor="middle">JGroups</text>
|
||||
|
||||
<text class="s" x="40" y="460">A-0 에서 확인: 세션은 이 7800 이 아니라 postgres 를 통해 공유된다</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 4.3 KiB |
@@ -0,0 +1,9 @@
|
||||
=== A-3 이 가정만 하고 재지 않은 값 ===
|
||||
name | setting | unit | source
|
||||
------------------------+---------+------+---------
|
||||
commit_delay | 0 | | default
|
||||
synchronous_commit | on | | default
|
||||
wal_writer_delay | 200 | ms | default
|
||||
wal_writer_flush_after | 128 | 8kB | default
|
||||
(4 rows)
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
# 주의 — 이 파일은 원 실험 시점에 0바이트로 저장됐다.
|
||||
# 리다이렉션이 stdout 만 받았는데 출력이 stderr 로 갔거나 tee 앞 파이프가
|
||||
# 비어 있었던 것으로 보인다. README 는 그 사이 파일 내용을 서술하고 있었는데,
|
||||
# 그것은 화면에서 본 것을 적은 것이지 이 파일에서 온 것이 아니었다.
|
||||
#
|
||||
# 아래는 사후에 다시 수집한 것이며, 원 시점의 DROP 규칙(0 패킷)은 이미
|
||||
# 제거되어 재현되지 않는다. 구조적 사실(kube-router 가 자기 체인을 FORWARD
|
||||
# 최상단에 유지한다)만 확인할 수 있다.
|
||||
# 원 실험의 결정적 증거는 04-correct-direction.txt 의 패킷 카운터 19/21 이다.
|
||||
|
||||
=== A-5 재수집 — filter 테이블 규칙이 CNI 체인에 밀리는 것 ===
|
||||
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
|
||||
num pkts bytes target prot opt in out source destination
|
||||
1 1690 3386K KUBE-ROUTER-FORWARD 0 -- * * 0.0.0.0/0 0.0.0.0/0 /* kube-router netpol - TEMCG2JMHZYE7H7T */
|
||||
2 7 612 KUBE-PROXY-FIREWALL 0 -- * * 0.0.0.0/0 0.0.0.0/0 ctstate NEW /* kubernetes load balancer firewall */
|
||||
3 40 13196 KUBE-FORWARD 0 -- * * 0.0.0.0/0 0.0.0.0/0 /* kubernetes forwarding rules */
|
||||
|
||||
(원 실험 시점의 규칙은 이미 제거됐다. 아래는 kube-router 가 자기 체인을
|
||||
FORWARD 최상단에 유지한다는 구조적 사실만 보여준다 — 그것이 실패 원인이었다.)
|
||||
|
||||
@@ -16,3 +16,10 @@
|
||||
1. **세션은 옮겨졌고 토큰은 안 옮겨졌다.** 빈 81개가 늘었는데 authorized client 관련은 하나도 안 바뀌었다.
|
||||
2. **refresh token 은 Redis 에 평문으로 있는 게 아니라 아예 없다.** 암호화를 고민하기 전에 이걸 알아야 한다.
|
||||
3. **"로그인은 되어 있는데 아무것도 못 하는" 상태가 만들어진다** — 완전 로그아웃보다 나쁘다.
|
||||
|
||||
## 스크린샷 주의
|
||||
|
||||
`b1-login-works-two-replicas.png` 과 `b1-token-boundary-after-redis.png` 는
|
||||
**동일 파일**이며 `b2-before-relogin.png` 와도 같다 (md5 `6de826a7…`).
|
||||
세 시점 모두 `accessTokenStoredOnServer: false` 인 같은 화면이었다.
|
||||
**시점 구별은 터미널 출력과 Redis/DB 조회가 한다.**
|
||||
|
||||
@@ -19,3 +19,14 @@
|
||||
2. **refresh token 은 평문이다.** DB 읽기 권한이면 작동하는 토큰을 얻는다.
|
||||
3. **같은 사용자의 두 번째 로그인이 첫 번째를 덮어쓴다.** 기본키에 session id 가 없어 구조적으로 그렇다.
|
||||
4. **로그아웃은 셋 중 하나만 지운다.** 평문 토큰과 Keycloak SSO 세션이 남는다.
|
||||
|
||||
## 스크린샷 주의
|
||||
|
||||
`b2-tokens-shared-across-instances.png` 는 **B-0 의
|
||||
`b0-bff-token-boundary.png` 와 동일 파일**이다 (md5 `9ed00537…`).
|
||||
두 시점 모두 `accessTokenStoredOnServer: true` 인 같은 화면이라 바이트가 같다.
|
||||
|
||||
**그래서 이 png 는 "JDBC 전환으로 토큰이 공유된다" 를 단독으로 증명하지
|
||||
못한다.** 그 증명은 `01-jdbc-store-deploy.txt`(테이블 생성)과
|
||||
`03-plaintext-tokens.txt`(행에 토큰이 들어 있음)가 한다.
|
||||
`b2-before-relogin.png` 는 B-1 의 캡처와 동일 파일이다.
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
=== 깨끗한 상태로 초기화 ===
|
||||
DELETE 1
|
||||
|
||||
=== 기준선 ===
|
||||
Keycloak 온라인 세션: 4
|
||||
Redis 키: 0
|
||||
|
||||
=== 두 앱의 구조 ===
|
||||
app1.hyeonworks.com → BFF (서버 세션: Redis + PostgreSQL)
|
||||
app2.hyeonworks.com → oauth2-proxy (쿠키 티켓 + Redis)
|
||||
둘 다 realm keycloak-patterns 를 쓴다
|
||||
@@ -0,0 +1,9 @@
|
||||
=== app1 로그인 직후 Keycloak 세션 ===
|
||||
user_session_id | client_sessions
|
||||
--------------------------+-----------------
|
||||
oqOjHekin4JU-BZjgQLjUByW | 1
|
||||
(1 row)
|
||||
|
||||
Redis 키: 1
|
||||
bff:session:sessions:6e0d9af4-2c8f-47d2-bf83-8b1e9670c679
|
||||
PostgreSQL authorized client: 1 행
|
||||
@@ -0,0 +1,20 @@
|
||||
=== app2 방문 후 — 로그인 화면 없이 통과했는가 ===
|
||||
user_session_id | client_sessions
|
||||
--------------------------+-----------------
|
||||
oqOjHekin4JU-BZjgQLjUByW | 2
|
||||
(1 row)
|
||||
|
||||
|
||||
=== 어느 클라이언트가 붙었는가 ===
|
||||
client_id | name
|
||||
--------------------------------------+------------------
|
||||
9055fa46-6abb-4d6d-a339-8a9183bbf26d | bff-confidential
|
||||
80431dbc-af81-4673-9790-ad06d1570b2e | oauth2-proxy
|
||||
(2 rows)
|
||||
|
||||
|
||||
=== 저장소 상태 ===
|
||||
Redis 키:
|
||||
_oauth2_proxy-6b028a70f69c8f0da9966eb36972dff2
|
||||
bff:session:sessions:6e0d9af4-2c8f-47d2-bf83-8b1e9670c679
|
||||
PostgreSQL authorized client: 1 행
|
||||
@@ -0,0 +1,25 @@
|
||||
=== ★ Keycloak 의 SSO 세션 하나를 죽인다 ===
|
||||
남은 Keycloak 세션: 1
|
||||
|
||||
=== 두 앱의 애플리케이션 세션은 그대로인가 ===
|
||||
_oauth2_proxy-6b028a70f69c8f0da9966eb36972dff2
|
||||
bff:session:sessions:6e0d9af4-2c8f-47d2-bf83-8b1e9670c679
|
||||
PostgreSQL authorized client: 1 행
|
||||
|
||||
→ IdP 세션은 없어졌는데 앱 세션은 남아 있다면, 두 계층의 수명이 어긋난 것이다
|
||||
=== 사용자 단위 로그아웃 (IdP 세션만 끊는다) ===
|
||||
남은 Keycloak 세션: 1
|
||||
|
||||
=== 앱 세션은 남아 있는가 ===
|
||||
_oauth2_proxy-6b028a70f69c8f0da9966eb36972dff2
|
||||
bff:session:sessions:6e0d9af4-2c8f-47d2-bf83-8b1e9670c679
|
||||
PostgreSQL authorized client: 1 행
|
||||
=== 남은 세션의 realm 과 client ===
|
||||
user_session_id | realm | clients
|
||||
--------------------------+--------+---------
|
||||
E1q5xI7tt4U_WhZpW7rEPIF2 | master | 1
|
||||
(1 row)
|
||||
|
||||
|
||||
=== 브라우저에서 두 앱을 다시 열면 어떻게 되는가 ===
|
||||
(IdP 세션이 사라졌으면 재로그인이 필요해야 한다)
|
||||
@@ -0,0 +1,27 @@
|
||||
# C-1 — 다중 앱 SSO 증거
|
||||
|
||||
2026-09-04 16:15–16:30 KST
|
||||
해설: [`docs/experiment-c1-multi-app-sso.md`](../../experiment-c1-multi-app-sso.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-baseline.txt` | 초기화 시도 — `logout-all` 이 안 먹어 세션 4개가 남았다 |
|
||||
| `02-after-app1-login.txt` | app1 로그인 후 — user session 1 · client session 1 · Redis 1 · DB 1행 |
|
||||
| `03-after-app2-visit.txt` | **app2 방문 후 client session 1 → 2**, `bff-confidential` 과 `oauth2-proxy` 가 같은 user session 에 붙음. Redis 에 두 종류 세션 |
|
||||
| `04-sso-session-killed.txt` | IdP 세션 삭제 후 — **앱 세션 셋 다 남아 있다**. realm 을 join 해 보고서야 남은 것이 master 세션임을 확인 |
|
||||
| `c1-sso-app2-no-login-screen.png` | app2 가 로그인 화면 없이 열린 화면 |
|
||||
| `c1-apps-alive-after-idp-logout.png` | **IdP 세션을 죽인 뒤에도 그대로 열리는 화면** |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **SSO 는 user session 1개에 client session N개** 구조다 — A-3(전체 소실)과 B-3(client 만 제거)의 차이가 여기서 의미를 갖는다.
|
||||
2. **IdP 세션을 죽여도 두 앱은 계속 동작한다.** 세 층(IdP·앱·토큰)의 수명이 각자이기 때문이다.
|
||||
3. **IdP 는 "로그인 경로"의 단일 장애점이지 "이미 로그인한 사용자"의 단일 장애점이 아니다.** 장애는 앱 세션 수명만큼 지연되어 몰려온다.
|
||||
|
||||
## 스크린샷 주의
|
||||
|
||||
`c1-sso-app2-no-login-screen.png` 과 `c1-apps-alive-after-idp-logout.png` 는
|
||||
**바이트 단위로 동일한 파일**이다 (md5 `2c703176…`). 두 시점의 화면이 실제로
|
||||
같은 내용이었기 때문이며, 조작이 아니다. **다만 그래서 두 시점을 구별하는
|
||||
증거가 되지 못한다** — 구별은 `03-` 과 `04-` 의 터미널 출력(client_sessions
|
||||
1→2, 그리고 IdP 세션 삭제 후 Redis 키 잔존)이 한다.
|
||||
|
After Width: | Height: | Size: 124 KiB |
|
After Width: | Height: | Size: 124 KiB |
@@ -0,0 +1,12 @@
|
||||
=== 현재 클라이언트의 백채널 로그아웃 설정 ===
|
||||
--- bff-confidential ---
|
||||
"frontchannelLogout" : false,
|
||||
--- oauth2-proxy ---
|
||||
"frontchannelLogout" : false,
|
||||
|
||||
=== BFF 가 백채널 로그아웃 엔드포인트를 갖고 있는가 ===
|
||||
|
||||
=== 실제로 그 경로가 있는가 ===
|
||||
/logout/connect/back-channel/keycloak HTTP 302
|
||||
/backchannel-logout HTTP 302
|
||||
/oauth2/sign_out HTTP 302
|
||||
@@ -0,0 +1,8 @@
|
||||
=== IdP 쪽에만 백채널 로그아웃 URL 을 설정한다 ===
|
||||
client id: 9055fa46-6abb-4d6d-a339-8a9183bbf26d
|
||||
command terminated with exit code 1
|
||||
|
||||
=== 로그인 상태를 만든다 ===
|
||||
(브라우저에 이미 세션이 있다)
|
||||
Keycloak 세션: 2
|
||||
Redis: 2 키
|
||||
@@ -0,0 +1,28 @@
|
||||
=== 로그아웃 전 상태 ===
|
||||
Redis: 2 키
|
||||
keycloak-patterns 세션: 0
|
||||
|
||||
=== ★ IdP 로그아웃 — Keycloak 이 백채널 알림을 보낼 것이다 ===
|
||||
시각: 14:53:29
|
||||
|
||||
=== Keycloak 로그 — 백채널 요청을 보냈는가, 결과는 ===
|
||||
|
||||
=== BFF 로그 — 백채널 요청이 도착했는가 ===
|
||||
|
||||
=== 앱 세션이 정리되었는가 ===
|
||||
Redis: 2 키
|
||||
_oauth2_proxy-6b028a70f69c8f0da9966eb36972dff2
|
||||
bff:session:sessions:6e0d9af4-2c8f-47d2-bf83-8b1e9670c679
|
||||
=== 로그아웃 전 — 실제 세션이 있는가 ===
|
||||
keycloak-patterns 세션: 1
|
||||
Redis: 1 키
|
||||
|
||||
=== ★ IdP 로그아웃 → 백채널 알림 ===
|
||||
시각: 14:54:21
|
||||
|
||||
=== Keycloak 로그 ===
|
||||
|
||||
=== BFF 로그 — 요청이 왔는가 ===
|
||||
|
||||
=== 앱 세션 ===
|
||||
Redis: 1 키
|
||||
@@ -0,0 +1,15 @@
|
||||
=== IdP 세션은 실제로 끊겼는가 ===
|
||||
keycloak-patterns 세션: 0
|
||||
|
||||
=== ★ Keycloak 파드가 app1.hyeonworks.com 에 닿는가 ===
|
||||
DNS 해석:
|
||||
Address: 100.83.212.4
|
||||
|
||||
Non-authoritative answer:
|
||||
|
||||
HTTPS 도달:
|
||||
HTTP 200 (0 이면 못 닿음)
|
||||
|
||||
=== Keycloak 로그 전체에서 backchannel 흔적 ===
|
||||
keycloak-0: 0 줄
|
||||
keycloak-1: 0 줄
|
||||
@@ -0,0 +1,17 @@
|
||||
# C-2 — 백채널 로그아웃 증거
|
||||
|
||||
2026-09-04 16:30–16:55 KST
|
||||
해설: [`docs/experiment-c2-backchannel-logout.md`](../../experiment-c2-backchannel-logout.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-current-state.txt` | 두 클라이언트 모두 `backchannelLogoutUrl` 없음 · BFF 소스에 `oidcLogout` 없음 · 후보 경로 셋 다 **302**(핸들러 없음) |
|
||||
| `02-configure-idp.txt` | IdP 쪽에만 `backchannel.logout.url` 설정 (점 표기는 실패, JSON 으로 성공) |
|
||||
| `03-logout-attempt.txt` | **살아 있는 세션(1)에 로그아웃 → IdP 세션 0, Redis 세션은 1 그대로.** Keycloak·BFF 로그에 흔적 없음 |
|
||||
| `04-reachability.txt` | **Keycloak 파드가 `app1.hyeonworks.com` 에 `HTTP 200` 으로 닿는다** — 네트워크 문제가 아님 |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **백채널 로그아웃은 어느 쪽에도 구현되어 있지 않았다.** C-1 이 관측한 "전파 안 됨"의 원인이다.
|
||||
2. **IdP 쪽만 설정해도 소용없다.** 받을 엔드포인트와 `sid → 세션` 역인덱스가 앱에 있어야 한다.
|
||||
3. **도달성이 숨은 전제다.** 이 실험대는 닿지만, 앱이 사설망에 있으면 설정해도 조용히 실패한다.
|
||||
@@ -0,0 +1,15 @@
|
||||
=== 백업 전 상태 ===
|
||||
realms|clients|users|sessions|authclients = 2|15|2|3|1
|
||||
|
||||
=== pg_dump — 전체 덤프 ===
|
||||
시작: 14:59:30
|
||||
완료: 14:59:30
|
||||
크기: 394945 bytes (6956 줄)
|
||||
포함된 테이블 수: 101
|
||||
|
||||
=== 덤프에 세션이 들어 있는가 ===
|
||||
offline_user_session 언급: 13
|
||||
COPY public.offline_user_session (user_session_id, user_id, realm_id, created_on, offline_flag, data, last_session_refre
|
||||
E1q5xI7tt4U_WhZpW7rEPIF2 48b37d33-8419-49aa-9b5b-7731975be50c 7845f394-723a-4d07-b530-c7416b2e1d31 1788500836 0 {"ipAddr
|
||||
2ap3DyRiBF8OdMiqCodsJ0mp 48b37d33-8419-49aa-9b5b-7731975be50c 7845f394-723a-4d07-b530-c7416b2e1d31 1788501029 0 {"ipAddr
|
||||
Zsk4QcgXf_qgyMKzde5AG-Fz 48b37d33-8419-49aa-9b5b-7731975be50c 7845f394-723a-4d07-b530-c7416b2e1d31 1788501263 0 {"ipAddr
|
||||
@@ -0,0 +1,17 @@
|
||||
=== ★ 파괴 — 스키마를 통째로 지운다 ===
|
||||
시각: 14:59:47
|
||||
DROP SCHEMA
|
||||
CREATE SCHEMA
|
||||
남은 테이블: 0
|
||||
|
||||
=== 서비스 영향 ===
|
||||
https://auth.hyeonworks.com/realms/master HTTP 200
|
||||
https://app1.hyeonworks.com/ HTTP 200
|
||||
bff-555df79c97-6j86w 1/1 Running 0 49m
|
||||
bff-555df79c97-vgg6g 1/1 Running 0 49m
|
||||
keycloak-0 1/1 Running 0 4m15s
|
||||
keycloak-1 1/1 Running 0 4m38s
|
||||
|
||||
=== Keycloak 이 무엇을 말하는가 ===
|
||||
2026-09-04 05:58:02,598 WARN [org.keycloak.jgroups.protocol.KEYCLOAK_JDBC_PING2] (blocking-thread--p3-t2) Failed to fetch the cluster members from the database.: org.postgresql.ut
|
||||
at org.postgresql.core.v3.QueryExecutorImpl.receiveErrorResponse(QueryExecutorImpl.java:2904)
|
||||
@@ -0,0 +1,29 @@
|
||||
=== 무엇이 실제로 깨지는가 ===
|
||||
/.well-known/openid-configuration HTTP 500
|
||||
/protocol/openid-connect/certs HTTP 200
|
||||
토큰 발급 (DB 쓰기 필요) HTTP 400
|
||||
|
||||
=== ★ 복구 — 덤프에서 되돌린다 ===
|
||||
시작: 15:00:12
|
||||
완료: 15:00:13
|
||||
오류 줄: 0
|
||||
|
||||
=== 복구 후 데이터 ===
|
||||
realms|clients|users|sessions|authclients = 2|15|2|3|1
|
||||
=== 복구 직후 — 재시작 없이 되는가 ===
|
||||
+15초 well-known=200 토큰발급=200
|
||||
→ 재시작 없이 회복
|
||||
|
||||
=== 복구 전 세션이 살아났는가 ===
|
||||
user_session_id | realm
|
||||
--------------------------+-------------------
|
||||
E1q5xI7tt4U_WhZpW7rEPIF2 | master
|
||||
2ap3DyRiBF8OdMiqCodsJ0mp | master
|
||||
Zsk4QcgXf_qgyMKzde5AG-Fz | master
|
||||
vsDgCVo12-qX0CC63ZmYzbYF | keycloak-patterns
|
||||
(4 rows)
|
||||
|
||||
|
||||
=== 파드 재시작 횟수 ===
|
||||
keycloak-0 restarts=0
|
||||
keycloak-1 restarts=0
|
||||
@@ -0,0 +1,16 @@
|
||||
# D-1 — 백업·복구 리허설 증거
|
||||
|
||||
2026-09-04 16:55–17:05 KST
|
||||
해설: [`docs/experiment-d1-backup-restore.md`](../../experiment-d1-backup-restore.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-backup.txt` | `pg_dump --clean --if-exists` — 395KB · 101 테이블 · **세션 데이터 포함** |
|
||||
| `02-destruction.txt` | `DROP SCHEMA public CASCADE` → 테이블 0개. **그런데 외부는 `HTTP 200`** — Keycloak 이 realm 캐시로 서빙한다 |
|
||||
| `03-restore.txt` | 깨지는 것과 안 깨지는 것(`certs` 200 / `well-known` 500 / 토큰 400) · **복구 1초 · 오류 0건 · 데이터 완전 일치 · 재시작 0회** |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **데이터베이스를 통째로 비웠는데 서비스가 200 을 냈다.** 헬스체크는 "DB 가 살아 있다"만 보고 "데이터가 있다"는 안 본다.
|
||||
2. **복구는 1초, 오류 0건, 재시작 불필요.** 절차가 맞다는 것은 확인됐다.
|
||||
3. **RPO 는 두 겹이다** — 백업 주기 + A-3 에서 측정한 `synchronous_commit OFF` 손실. 그리고 이번 덤프는 호스트의 `/tmp` 에 있어 **같은 장애 도메인**이다.
|
||||
@@ -0,0 +1,9 @@
|
||||
=== D-1 의 교훈: 업그레이드 전에 백업한다 ===
|
||||
백업: 396333 bytes
|
||||
|
||||
=== 현재 버전과 스키마 상태 ===
|
||||
quay.io/keycloak/keycloak:26.7.0
|
||||
총 마이그레이션 수: 210
|
||||
|
||||
=== 로그인 상태 만들기 (업그레이드 후 살아남는지 볼 것) ===
|
||||
현재 세션: 4
|
||||
@@ -0,0 +1,17 @@
|
||||
=== ★ 롤백 시도: 26.7.0 → 26.0 ===
|
||||
시각: 15:02:20
|
||||
statefulset.apps/keycloak image updated
|
||||
+20초 keycloak-0:Running(1/1) keycloak-1:Running(0/1)
|
||||
+40초 keycloak-0:Running(1/1) keycloak-1:Running(0/1)
|
||||
+60초 keycloak-0:Running(1/1) keycloak-1:Running(0/1)
|
||||
+80초 keycloak-0:Running(1/1) keycloak-1:Error(0/1)
|
||||
+100초 keycloak-0:Running(1/1) keycloak-1:Running(0/1)
|
||||
+120초 keycloak-0:Running(1/1) keycloak-1:Error(0/1)
|
||||
+140초 keycloak-0:Running(1/1) keycloak-1:CrashLoopBackOff(0/1)
|
||||
+160초 keycloak-0:Running(1/1) keycloak-1:Running(0/1)
|
||||
|
||||
=== 새 파드가 무엇을 말하는가 ===
|
||||
2026-09-04 06:03:25,877 ERROR [org.keycloak.quarkus.runtime.cli.ExecutionExceptionHandler] (main) ERROR: Failed to start server in (production) mode
|
||||
2026-09-04 06:03:25,877 ERROR [org.keycloak.quarkus.runtime.cli.ExecutionExceptionHandler] (main) ERROR: liquibase.exception.ValidationFailedException: Validation Failed:
|
||||
2026-09-04 06:03:25,877 ERROR [org.keycloak.quarkus.runtime.cli.ExecutionExceptionHandler] (main) ERROR: Validation Failed:
|
||||
2026-09-04 06:03:25,877 ERROR [org.keycloak.quarkus.runtime.cli.ExecutionExceptionHandler] (main) For more details run the same command passing the '--verbose' option. Also you can use '--help' to see the detai
|
||||
@@ -0,0 +1,20 @@
|
||||
=== 서비스는 살아 있는가 (StatefulSet 롤링이 막아줬다) ===
|
||||
https://auth.hyeonworks.com/realms/master HTTP 200
|
||||
Warning: v1 Endpoints is deprecated in v1.33+; use discovery.k8s.io/v1 EndpointSlice
|
||||
ready 주소: [10.42.1.140]sed: -e expression #1, char 27: unknown option to 's'
|
||||
|
||||
=== Liquibase 오류 상세 ===
|
||||
2026-09-04 06:03:25,877 ERROR [org.keycloak.quarkus.runtime.cli.ExecutionExceptionHandler] (main) ERROR: liquibase.exception.ValidationFailedException: Validation Failed:
|
||||
1 changesets check sum
|
||||
2026-09-04 06:03:25,877 ERROR [org.keycloak.quarkus.runtime.cli.ExecutionExceptionHandler] (main) ERROR: Validation Failed:
|
||||
1 changesets check sum
|
||||
|
||||
=== ★ 앞으로 되돌린다 (26.7.0) ===
|
||||
statefulset.apps/keycloak image updated
|
||||
partitioned roll out complete: 2 new pods have been updated...
|
||||
keycloak-0 1/1 Running 0 10m
|
||||
keycloak-1 1/1 Running 0 28s
|
||||
|
||||
=== 데이터는 무사한가 ===
|
||||
realms|clients|migrations|sessions = 2|15|210|4
|
||||
외부 진입점 HTTP 200
|
||||
@@ -0,0 +1,17 @@
|
||||
# D-2 — 버전 업그레이드 증거
|
||||
|
||||
2026-09-04 17:05–17:15 KST
|
||||
해설: [`docs/experiment-d2-version-upgrade.md`](../../experiment-d2-version-upgrade.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-pre-upgrade.txt` | 백업 396KB · 이미지 26.7.0 · **마이그레이션 210건** · 세션 4 |
|
||||
| `02-rollback-attempt.txt` | 26.0 으로 내리자 `Running(0/1) → Error → CrashLoopBackOff`. **`liquibase.exception.ValidationFailedException`** |
|
||||
| `d2-upgrade-window.png` | Grafana — 26.7.3 업그레이드 구간의 `cluster_size` 2→1→2 두 번과 파드별 `up` 시계열 교체 (후속 작업에서 촬영) |
|
||||
| `03-roll-forward.txt` | **서비스는 `HTTP 200` 유지**(ready 주소 1개) · 오류 원인 `1 changesets check sum` · 26.7.0 복귀 후 마이그레이션 210·세션 4 그대로 |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **스키마가 바뀌었으면 롤백은 안 된다.** (26.7.0↔26.7.3 처럼 안 바뀌면 된다 — [`followup`](../followup/) 참조.) 체크섬이 안 맞아 Liquibase 가 기동 자체를 거부한다 — "모르는 변경"이 아니라 "아는 변경인데 정의가 다르다".
|
||||
2. **StatefulSet 이 사고를 절반에서 멈춰줬다.** 한 파드가 남아 외부 200 을 유지했다. replica 1 이었다면 전면 장애다.
|
||||
3. **실패한 기동은 스키마를 안 건드렸다.** 그래서 이미지만 되돌려도 복구됐다 — 이미 적용된 뒤였다면 DB 복구(D-1)가 필요하다.
|
||||
|
After Width: | Height: | Size: 105 KiB |
@@ -0,0 +1,17 @@
|
||||
=== 실험대의 Secret 목록 ===
|
||||
bff-secrets Opaque keys=1
|
||||
keycloak-lab-secrets Opaque keys=2
|
||||
oauth2-proxy-secrets Opaque keys=3
|
||||
|
||||
=== ★ base64 는 암호화가 아니다 — 한 줄로 읽힌다 ===
|
||||
keycloak-lab-secrets/POSTGRES_PASSWORD = lab-postgres-change-me
|
||||
keycloak-lab-secrets/KC_BOOTSTRAP_ADMIN_PASSWORD = lab-admin-change-me
|
||||
bff-secrets/KEYCLOAK_CLIENT_SECRET = bff-lab-secret
|
||||
oauth2-proxy-secrets/COOKIE_SECRET_A = lab-cookie-secret-aaaaaaaaaaaaaa
|
||||
|
||||
=== describe 는 값을 감춘다 (그래서 안전하다고 착각한다) ===
|
||||
Type: Opaque
|
||||
|
||||
Data
|
||||
====
|
||||
KEYCLOAK_CLIENT_SECRET: 14 bytes
|
||||
@@ -0,0 +1,23 @@
|
||||
=== k3s 의 데이터 저장소 ===
|
||||
Encryption Status: Disabled, no configuration file found
|
||||
|
||||
=== 저장 파일 ===
|
||||
total 23336
|
||||
drwx------ 2 root root 4096 Sep 2 09:12 .
|
||||
drwx------ 8 root root 4096 Sep 4 03:23 ..
|
||||
-rw-r--r-- 1 root root 13078528 Sep 4 06:05 state.db
|
||||
-rw-r--r-- 1 root root 32768 Sep 4 06:06 state.db-shm
|
||||
-rw-r--r-- 1 root root 10769712 Sep 4 06:06 state.db-wal
|
||||
|
||||
=== ★ 저장 파일에서 비밀번호가 그대로 보이는가 ===
|
||||
state.db 안의 평문 일치: 2
|
||||
=== 평문이 저장 파일에 있다는 것을 눈으로 ===
|
||||
client secret 평문 등장 횟수: 0
|
||||
|
||||
=== 누가 Secret 을 읽을 수 있는가 ===
|
||||
default SA: no
|
||||
(Role 이 없으면 네임스페이스에 별도 제한이 없다는 뜻)
|
||||
|
||||
=== 파드 안에서는 어떻게 보이는가 ===
|
||||
KEYCLOAK_CLIENT_SECRET=bff-lab-secret
|
||||
BFF_DB_PASSWORD=lab-postgres-change-me
|
||||
@@ -0,0 +1,15 @@
|
||||
# D-3 — 비밀 관리 증거
|
||||
|
||||
2026-09-04 17:15–17:25 KST
|
||||
해설: [`docs/experiment-d3-secret-management.md`](../../experiment-d3-secret-management.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-base64-not-encryption.txt` | 실험대의 **모든 비밀이 명령 네 줄로** 평문 출력. `describe` 는 `14 bytes` 만 보여줘 착각을 준다 |
|
||||
| `02-at-rest.txt` | **`Encryption Status: Disabled`** · `state.db` 안에 비밀번호 평문 **2회 일치** · 파드 안에서는 `KEYCLOAK_CLIENT_SECRET=bff-lab-secret` 환경변수 · `default` SA 는 **읽을 수 없음** |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **base64 는 감추려는 것이 아니라 YAML 에 바이트를 담기 위한 것이다.** `describe` 가 값을 가려 안전하다는 착각을 준다.
|
||||
2. **저장소 암호화가 꺼져 있고 노드 디스크에 평문이 있다.** 노드 디스크 하나가 전 클러스터의 비밀이다.
|
||||
3. **네 경로 중 RBAC 만 제 역할을 한다.** 그것이 실질적 방어선이며, 관리자에게는 아무 방어가 없다.
|
||||
@@ -0,0 +1,38 @@
|
||||
=== 현재 인증서 (외부 관측, sudo 불필요) ===
|
||||
subject=CN = auth.hyeonworks.com
|
||||
issuer=C = US, O = Let's Encrypt, CN = YE2
|
||||
notBefore=Sep 3 00:47:23 2026 GMT
|
||||
notAfter=Dec 2 00:47:22 2026 GMT
|
||||
X509v3 Subject Alternative Name:
|
||||
DNS:app1.hyeonworks.com, DNS:app2.hyeonworks.com, DNS:auth.hyeonworks.com
|
||||
|
||||
→ 세 호스트가 같은 인증서를 쓴다 (SAN 3개, 와일드카드 아님)
|
||||
|
||||
=== 체인 완결성 (fullchain vs cert 실수 확인) ===
|
||||
0 s:CN = auth.hyeonworks.com
|
||||
1 s:C = US, O = Let's Encrypt, CN = YE2
|
||||
2 s:C = US, O = ISRG, CN = Root YE
|
||||
3 s:C = US, O = Internet Security Research Group, CN = ISRG Root X2
|
||||
Verify return code: 0 (ok)
|
||||
|
||||
→ 중간 인증서가 함께 제공된다. fullchain.pem 이 올바로 설정되어 있다.
|
||||
|
||||
=== 갱신 자동화 ===
|
||||
NEXT LEFT LAST PASSED UNIT
|
||||
Fri 2026-09-04 17:03:46 KST 1h 54min Fri 2026-09-04 03:19:39 KST 11h ago certbot-renew.timer
|
||||
타이머 enabled: enabled
|
||||
타이머 active: active
|
||||
|
||||
=== 남은 기간 ===
|
||||
만료: Dec 2 00:47:22 2026 GMT
|
||||
남은 일수: 88일
|
||||
Let's Encrypt 90일 발급 · 30일 남으면 갱신 → 실제 갱신까지 약 58일
|
||||
|
||||
=== 강제 갱신은 하지 못했다 ===
|
||||
$ sudo -n -l
|
||||
sudo: a password is required
|
||||
$ sudo -n systemctl reload nginx
|
||||
sudo: a password is required
|
||||
|
||||
→ test-server 의 sudo 는 비밀번호를 요구한다 (게스트 kc-lab-1/2 는 무암호).
|
||||
certbot renew --force-renewal 도 nginx reload 도 실행할 수 없다.
|
||||
@@ -0,0 +1,14 @@
|
||||
# D-4 — 인증서 갱신 증거
|
||||
|
||||
2026-09-04 17:25–17:35 KST
|
||||
해설: [`docs/experiment-d4-certificate-renewal.md`](../../experiment-d4-certificate-renewal.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-certificate-state.txt` | SAN 3개(와일드카드 아님) · **체인 4단계, `Verify return code: 0`** · `certbot-renew.timer` enabled·active, 11시간 전 실행 · 88일 남음 · **`sudo: a password is required` 로 강제 갱신 불가** |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **인증서가 이름 3개만 담는다.** B-7 에서 oauth2-proxy 를 올릴 호스트가 없어 Grafana 의 `app2` 를 빌려야 했던 실제 비용이 여기서 나왔다.
|
||||
2. **체인이 완전하다** — 단계가 4개이므로 `fullchain.pem` 을 쓰고 있다. 1개면 `cert.pem` 실수이며 캐시 없는 클라이언트에서만 깨진다.
|
||||
3. **강제 갱신은 못 했다.** 호스트 sudo 가 비밀번호를 요구한다. 타이머가 active 라는 것은 "갱신이 된다"의 확인이 아니다.
|
||||
@@ -0,0 +1,32 @@
|
||||
=== D-1 절차대로 먼저 백업 ===
|
||||
백업: 395375 bytes
|
||||
마이그레이션 전: 210
|
||||
세션 전: 3
|
||||
|
||||
=== ★ 정방향 업그레이드 + 1초 간격 가용성 측정 ===
|
||||
시작: 15:22:59
|
||||
partitioned roll out complete: 2 new pods have been updated...
|
||||
완료: 15:24:26
|
||||
|
||||
=== 업그레이드 중 외부 응답 시계열 ===
|
||||
200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
|
||||
200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
|
||||
200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
|
||||
200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
|
||||
200 200 200 200 200 200 200
|
||||
200 응답: 87 회
|
||||
비200 : 0
|
||||
0 회
|
||||
=== 업그레이드 후 ===
|
||||
quay.io/keycloak/keycloak:26.7.3
|
||||
Keycloak 26.7.3
|
||||
마이그레이션 후: 210 (전: 210)
|
||||
세션 후: 3 (전: 3)
|
||||
|
||||
=== 스키마 마이그레이션이 실제로 있었는가 ===
|
||||
(없으면 26.7.0→26.7.3 에 스키마 변경이 없다는 뜻)
|
||||
|
||||
=== 파드 상태와 클러스터 ===
|
||||
keycloak-0 1/1 Running restarts=0
|
||||
keycloak-1 1/1 Running restarts=0
|
||||
cluster: [keycloak-1-11418(v=16.0.14)|47] (2) [keycloak-1-11418(v=16.0.14), keycloak-0-58996(v=16.0.14)]
|
||||
@@ -0,0 +1,20 @@
|
||||
=== ★ 가설: 스키마 변경이 없으면 롤백이 된다 (26.7.3 → 26.7.0) ===
|
||||
시작: 15:25:08
|
||||
partitioned roll out complete: 2 new pods have been updated...
|
||||
완료: 15:25:53
|
||||
|
||||
200 응답: 43 회 / 비200: 1
|
||||
|
||||
keycloak-0 1/1 Running restarts=0
|
||||
keycloak-1 1/1 Running restarts=0
|
||||
Keycloak 26.7.0
|
||||
마이그레이션: 210
|
||||
세션: 3
|
||||
=== 롤백 중 응답 시계열 (비200 위치) ===
|
||||
200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
|
||||
200 200 200 200 000 200 200 200 200 200 200 200 200 200 200 200 200 200 200 200
|
||||
200 200 200 200
|
||||
비200 값: 000
|
||||
|
||||
=== 대조: 정방향 업그레이드 때는 ===
|
||||
200: 87 / 비200: 0
|
||||
@@ -0,0 +1,9 @@
|
||||
=== ★ Keycloak 에서 email 을 바꾼다 ===
|
||||
변경 시각: 15:27:52
|
||||
IdP 의 값: [ {
|
||||
IdP 의 값: "email" : "changed-labuser@example.com"
|
||||
IdP 의 값: } ]
|
||||
|
||||
=== IdP 쪽 세션과 oauth2-proxy 세션 ===
|
||||
Redis 세션: 1 개
|
||||
(세션은 로그인 시점의 클레임을 담고 있다 — 이제 요청을 반복해 본다)
|
||||
@@ -0,0 +1,17 @@
|
||||
=== Prometheus 가 실제로 긁는 대상 (2026-09-04 18:10 KST) ===
|
||||
keycloak 2개
|
||||
kubelet 2개
|
||||
node-exporter 2개
|
||||
prometheus 1개
|
||||
|
||||
=== B층 구성 요소의 지표가 있는가 ===
|
||||
redis_up 시계열 0개
|
||||
redis_connected_clients 시계열 0개
|
||||
redis_memory_used_bytes 시계열 0개
|
||||
pg_up 시계열 0개
|
||||
pg_stat_database_numbackends 시계열 0개
|
||||
|
||||
→ B-1·B-2·B-3·B-5 는 Grafana 증거를 만들 수 없다.
|
||||
스크린샷을 안 찍은 것이 아니라 긁는 대상에 없다.
|
||||
보완하려면 redis_exporter · postgres_exporter · BFF 의 /actuator/prometheus 를
|
||||
scrape 대상에 추가해야 한다.
|
||||
@@ -0,0 +1,17 @@
|
||||
# 후속 — 미측정으로 남겼던 항목을 채운 기록
|
||||
|
||||
2026-09-04 17:35–18:20 KST
|
||||
해설: [`docs/experiment-followup-untested-items.md`](../../experiment-followup-untested-items.md)
|
||||
|
||||
| 파일 | 무엇을 보여주는가 |
|
||||
|---|---|
|
||||
| `01-d2-forward-upgrade.txt` | **D-2 정방향** 26.7.0 → 26.7.3. 백업 396KB · **87회 요청 전부 200(무중단)** · 마이그레이션 210 → 210(스키마 변경 없음) · 세션 3 유지 · Infinispan 16.0.12 → 16.0.14 |
|
||||
| `02-d2-rollback-same-schema.txt` | **스키마가 안 바뀌면 롤백이 된다** — 26.7.3 → 26.7.0 성공. 다만 전환 순간 `000` 1회(3초 타임아웃) |
|
||||
| `03-b4-role-propagation.txt` | **B-4 ③** IdP 에서 값을 바꿔도 **12회 요청·6초 동안 옛 값**. 세션 삭제 후 재인증에서야 새 값 |
|
||||
| `04-observability-gap.txt` | **B층에 관측이 없다** — Prometheus 는 keycloak·kubelet·node-exporter·prometheus 만 긁는다. Redis·BFF·PostgreSQL 지표가 0개 |
|
||||
|
||||
## 핵심 세 줄
|
||||
|
||||
1. **"롤백은 안 된다" 는 조건부였다.** 스키마가 바뀌었으면 안 되고, 안 바뀌었으면 된다 — D-2 의 결론을 정밀화한다.
|
||||
2. **role 변경은 요청 횟수와 무관하게 반영되지 않는다.** `--cookie-refresh` 가 없으면 쿠키 만료나 재인증까지 옛 값이 간다.
|
||||
3. **B층 실험에 Grafana 증거가 없는 이유가 확인됐다** — 관측 대상에 애초에 없다. 스크린샷이 없는 것이 아니라 지표가 없다.
|
||||
@@ -597,6 +597,23 @@ for n in ('BEFORE_K0','BEFORE_K1','AFTER_K0','AFTER_K1'):
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 09:52 – 10:12 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-cross-node-session.txt`](evidence/session-replication/01-cross-node-session.txt) | 터미널 원문 |
|
||||
| [`02-cache-delta.txt`](evidence/session-replication/02-cache-delta.txt) | 터미널 원문 |
|
||||
| [`03-cache-ownership.txt`](evidence/session-replication/03-cache-ownership.txt) | 터미널 원문 |
|
||||
| [`04-read-path-sql.txt`](evidence/session-replication/04-read-path-sql.txt) | 터미널 원문 |
|
||||
| [`keycloak-admin-sessions.png`](evidence/session-replication/keycloak-admin-sessions.png) | 스크린샷 |
|
||||
| [`session-cache-entries-per-pod.png`](evidence/session-replication/session-cache-entries-per-pod.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/session-replication/README.md`](evidence/session-replication/README.md).
|
||||
|
||||
## 11. 재현
|
||||
|
||||
```bash
|
||||
|
||||
@@ -177,15 +177,34 @@ sudo conntrack -D -p tcp -s 10.42.1.43 -d 10.42.0.35 --sport 7800 --dport 40023
|
||||
**양쪽 노드에서, 양쪽 방향으로** 지워야 한다. 서버 쪽 노드에는 튜플이 뒤집혀
|
||||
기록되어 있다.
|
||||
|
||||
그리고 **즉시 끊기지 않는다.**
|
||||
### ★ 정정 — conntrack 삭제가 분단을 만들었다고 볼 근거가 없다
|
||||
|
||||
이 문서는 처음에 이렇게 썼다.
|
||||
|
||||
```
|
||||
11:41 conntrack 삭제
|
||||
11:44 cluster_size 2 → 1 ← 약 3분 뒤
|
||||
```
|
||||
|
||||
TCP 는 상대가 사라졌음을 **재전송 타임아웃**으로 알아낸다. 소켓은 한동안
|
||||
`ESTABLISHED` 로 남아 있다.
|
||||
**증거를 다시 보면 그 인과가 성립하지 않는다.**
|
||||
|
||||
| 시각 | 증거 |
|
||||
|---|---|
|
||||
| 11:41 | conntrack 삭제. 직후 `07-cluster-size.txt` 는 **11:45 까지 전부 `2`** |
|
||||
| **11:44:23** | **`keycloak-0` 파드의 `startTime`** — 스스로 재시작했다 |
|
||||
| 11:44:27 | `cluster_size` 2 → 1 |
|
||||
| 11:46:07 | 내가 `delete pod` 를 실행 (이미 떨어진 뒤) |
|
||||
|
||||
**하락은 conntrack 삭제 3분 뒤가 아니라 파드 재시작 4초 뒤에 일어났다.**
|
||||
같은 문서 6절이 "정책이 걸린 채 재시작되자" 라고 쓴 것이 맞고,
|
||||
**4절의 "conntrack 삭제 → 3분 뒤 분단" 은 시각이 겹친 것을 인과로 읽은 것이다.**
|
||||
|
||||
conntrack 삭제 자체가 무의미했다는 뜻은 아니다 — 다만 **이 실험은
|
||||
그것만으로 분단이 되는지 판정하지 못했다.** 판정한 것은 A-5 이고,
|
||||
거기서 `raw` 테이블이 필요하다는 것이 드러났다.
|
||||
|
||||
> TCP 가 재전송 타임아웃으로 상대를 알아채는 것은 사실이지만,
|
||||
> **이 실험에서 그 경로가 발동했다는 증거는 없다.**
|
||||
|
||||
---
|
||||
|
||||
@@ -462,6 +481,30 @@ vendor_jgroups_merge3_get_num_merge_events
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 11:34 – 11:50 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-baseline-cluster.txt`](evidence/a1-jgroups-transport-block/01-baseline-cluster.txt) | 터미널 원문 |
|
||||
| [`02-control-before-block.txt`](evidence/a1-jgroups-transport-block/02-control-before-block.txt) | 터미널 원문 |
|
||||
| [`03-block-applied.txt`](evidence/a1-jgroups-transport-block/03-block-applied.txt) | 터미널 원문 |
|
||||
| [`04-after-block-state.txt`](evidence/a1-jgroups-transport-block/04-after-block-state.txt) | 터미널 원문 |
|
||||
| [`05-conntrack-problem.txt`](evidence/a1-jgroups-transport-block/05-conntrack-problem.txt) | 터미널 원문 |
|
||||
| [`06-partition-observed.txt`](evidence/a1-jgroups-transport-block/06-partition-observed.txt) | 터미널 원문 |
|
||||
| [`07-cluster-size.txt`](evidence/a1-jgroups-transport-block/07-cluster-size.txt) | 터미널 원문 |
|
||||
| [`08-restart-forced-partition.txt`](evidence/a1-jgroups-transport-block/08-restart-forced-partition.txt) | 터미널 원문 |
|
||||
| [`09-cross-node-under-partition.txt`](evidence/a1-jgroups-transport-block/09-cross-node-under-partition.txt) | 터미널 원문 |
|
||||
| [`10-logout-not-propagated.txt`](evidence/a1-jgroups-transport-block/10-logout-not-propagated.txt) | 터미널 원문 |
|
||||
| [`11-service-impact.txt`](evidence/a1-jgroups-transport-block/11-service-impact.txt) | 터미널 원문 |
|
||||
| [`12-recovery.txt`](evidence/a1-jgroups-transport-block/12-recovery.txt) | 터미널 원문 |
|
||||
| [`a1-cluster-size-partition-recovery.png`](evidence/a1-jgroups-transport-block/a1-cluster-size-partition-recovery.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/a1-jgroups-transport-block/README.md`](evidence/a1-jgroups-transport-block/README.md).
|
||||
|
||||
## 11. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -9,6 +9,15 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| 예측 | 결과 |
|
||||
@@ -94,12 +103,19 @@ kubectl -n keycloak-lab wait --for=delete pod -l app=postgres --timeout=90s
|
||||
① 캐시를 가진 노드(keycloak-0)에서 refresh HTTP 500
|
||||
② 캐시가 없는 노드(keycloak-1)에서 refresh HTTP 500
|
||||
③ 새 로그인 HTTP 500
|
||||
④ 관리 API (세션 조회 필요) HTTP 500
|
||||
④ 관리 API (세션 조회 필요) HTTP 500 ← 5절의 재측정값
|
||||
|
||||
--- 오류 본문 ---
|
||||
{"error":"unknown_error","error_description":"For more on this error consult the server log."}
|
||||
```
|
||||
|
||||
> **④ 의 첫 측정은 오염됐다** —
|
||||
> [`03-four-paths.txt`](evidence/a2-database-loss/03-four-paths.txt) 에는
|
||||
> `HTTP 000000{"error":"HTTP 401 Unauthorized"}401` 이 남아 있다.
|
||||
> `curl -w %{http_code}` 출력에 본문이 섞인 것이고, 재시도가 `000` 을 세 번
|
||||
> 찍은 뒤 `401` 이 왔다. **위 표의 `500` 은 5절에서 다시 잰 값**이며,
|
||||
> 첫 측정을 그대로 쓰지 않았다.
|
||||
|
||||
### ① 이 500 인 것이 중요하다
|
||||
|
||||
**캐시에 세션을 들고 있어도 refresh 는 실패한다.**
|
||||
@@ -263,6 +279,23 @@ DB 가 돌아와도 CrashLoopBackOff 의 백오프 때문에 회복이 늦어진
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 11:53 – 11:56 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-baseline.txt`](evidence/a2-database-loss/01-baseline.txt) | 터미널 원문 |
|
||||
| [`02-setup-sessions.txt`](evidence/a2-database-loss/02-setup-sessions.txt) | 터미널 원문 |
|
||||
| [`03-four-paths.txt`](evidence/a2-database-loss/03-four-paths.txt) | 터미널 원문 |
|
||||
| [`04-health-and-service.txt`](evidence/a2-database-loss/04-health-and-service.txt) | 터미널 원문 |
|
||||
| [`05-recovery.txt`](evidence/a2-database-loss/05-recovery.txt) | 터미널 원문 |
|
||||
| [`a2-up-stayed-1-during-outage.png`](evidence/a2-database-loss/a2-up-stayed-1-during-outage.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/a2-database-loss/README.md`](evidence/a2-database-loss/README.md).
|
||||
|
||||
## 9. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -181,8 +181,23 @@ database system is ready to accept connections
|
||||
★ p5XybeQIYmAs818gO4Vl_5ea
|
||||
```
|
||||
|
||||
**약 2.6% 유실.** 초당 19건 정도 로그인하던 중이었으므로
|
||||
**대략 마지막 0.2초 분량**이다 — `wal_writer_delay` 기본값(200ms)과 맞는다.
|
||||
**약 2.6% 유실.**
|
||||
|
||||
처음 이 문서는 *"초당 19건 … `wal_writer_delay` 기본값(200ms)과 맞는다"* 고
|
||||
썼는데, **그 시점에 `wal_writer_delay` 를 조회한 적이 없었다.** 나중에 쟀다.
|
||||
|
||||
```
|
||||
name | setting | unit | source
|
||||
------------------------+---------+------+---------
|
||||
wal_writer_delay | 200 | ms | default
|
||||
wal_writer_flush_after | 128 | 8kB | default
|
||||
synchronous_commit | on | | default
|
||||
```
|
||||
[`08-wal-settings.txt`](evidence/a3-database-crash/08-wal-settings.txt)
|
||||
|
||||
**값은 맞았지만 그때는 추정이었다.** 그리고 로그인 속도도 정확히는
|
||||
증거의 `8초에 112건` ≈ **초당 14건**이며 19건이 아니다. 4건은 그 속도에서
|
||||
**약 0.29초 분량**이고, 200ms 창과 같은 자릿수이되 정확히 일치하지는 않는다.
|
||||
|
||||
### 사용자에게 어떻게 보이는가
|
||||
|
||||
@@ -284,6 +299,25 @@ ALTER DATABASE keycloak SET synchronous_commit = on; -- SET LOCAL 이 이깁
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 11:58 – 16:32 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-crash-injection.txt`](evidence/a3-database-crash/01-crash-injection.txt) | 터미널 원문 |
|
||||
| [`02-design-check.txt`](evidence/a3-database-crash/02-design-check.txt) | 터미널 원문 |
|
||||
| [`03-loss-measurement.txt`](evidence/a3-database-crash/03-loss-measurement.txt) | 터미널 원문 |
|
||||
| [`04-comparison.txt`](evidence/a3-database-crash/04-comparison.txt) | 터미널 원문 |
|
||||
| [`05-true-crash.txt`](evidence/a3-database-crash/05-true-crash.txt) | 터미널 원문 |
|
||||
| [`06-backend-kill-crash.txt`](evidence/a3-database-crash/06-backend-kill-crash.txt) | 터미널 원문 |
|
||||
| [`07-loss-result.txt`](evidence/a3-database-crash/07-loss-result.txt) | 터미널 원문 |
|
||||
| [`08-wal-settings.txt`](evidence/a3-database-crash/08-wal-settings.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/a3-database-crash/README.md`](evidence/a3-database-crash/README.md).
|
||||
|
||||
## 8. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
| 외부 응답 | **503** | **000** (연결 자체가 안 됨) |
|
||||
| `kubectl` | 정상 | **불통** |
|
||||
| 살아 있는 워크로드 | keycloak-1 (하지만 DB 없음) | **keycloak-0 은 계속 돌고 있다** |
|
||||
| 복구 시간 | **60초** | **60초** |
|
||||
| **`virsh start` 이후** 복구 | **60초** | **60초** |
|
||||
|
||||
**둘 다 전면 장애**지만 이유가 다르다. 4a 는 **DB 가 같이 죽어서**, 4b 는
|
||||
**들어갈 길이 없어서**다.
|
||||
@@ -204,6 +204,15 @@ virsh start kc-lab-2
|
||||
|
||||
**60초.** 사람 개입 없이 전부 제자리로 돌아왔다.
|
||||
|
||||
> **이 60초는 MTTR 이 아니다.** `virsh start` 를 친 뒤의 시간이며,
|
||||
> 실제 장애 구간은 **12:07:43(차단) → 12:17:31(서비스 복귀) ≈ 10분**이다.
|
||||
> 그 대부분은 내가 관찰하며 보낸 시간이고, **사람이 알아채고 결정하는 시간이
|
||||
> 복구 시간의 대부분**이라는 점이 오히려 현실적이다.
|
||||
>
|
||||
> 그리고 본문의 `40초`(node-monitor-grace-period)와 `5분`(tolerationSeconds)은
|
||||
> **쿠버네티스 기본값을 인용한 것**이며, 관측된 전이 시점(+45초, +270초)이
|
||||
> 그 값과 모순되지 않는다는 것까지가 이 실험이 말할 수 있는 범위다.
|
||||
|
||||
---
|
||||
|
||||
## 4b. 컨트롤 플레인 노드 상실 (`kc-lab-1`)
|
||||
@@ -358,6 +367,26 @@ virsh start kc-lab-1
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 12:05 – 12:23 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-baseline.txt`](evidence/a4-node-loss/01-baseline.txt) | 터미널 원문 |
|
||||
| [`02-worker-node-killed.txt`](evidence/a4-node-loss/02-worker-node-killed.txt) | 터미널 원문 |
|
||||
| [`03-state-during-loss.txt`](evidence/a4-node-loss/03-state-during-loss.txt) | 터미널 원문 |
|
||||
| [`04-eviction-timing.txt`](evidence/a4-node-loss/04-eviction-timing.txt) | 터미널 원문 |
|
||||
| [`05-recovery.txt`](evidence/a4-node-loss/05-recovery.txt) | 터미널 원문 |
|
||||
| [`06-control-plane-inventory.txt`](evidence/a4-node-loss/06-control-plane-inventory.txt) | 터미널 원문 |
|
||||
| [`07-control-plane-loss.txt`](evidence/a4-node-loss/07-control-plane-loss.txt) | 터미널 원문 |
|
||||
| [`08-control-plane-recovery.txt`](evidence/a4-node-loss/08-control-plane-recovery.txt) | 터미널 원문 |
|
||||
| [`a4-up-dropped-per-node.png`](evidence/a4-node-loss/a4-up-dropped-per-node.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/a4-node-loss/README.md`](evidence/a4-node-loss/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -137,6 +137,16 @@ kubectl -n keycloak-lab logs keycloak-0 --since=20m | grep ISPN000094 | awk '$2
|
||||
suspected = 0
|
||||
```
|
||||
|
||||
> **맥락 하나가 빠져 있었다** —
|
||||
> [`06-view-history-and-cleanup.txt`](evidence/a5-asymmetric-partition/06-view-history-and-cleanup.txt)
|
||||
> 를 보면 뷰 13 은 **주입(03:33:58)보다 9초 앞선 03:33:49 의 `MergeView`** 로
|
||||
> 만들어졌고, 그 직전에는 `|12] (1)` — 즉 **막 분단됐다가 합쳐진 직후**였다.
|
||||
> `merge_events = 1.0` 도 그 병합의 것이다.
|
||||
>
|
||||
> **"주입 전부터 그대로" 는 맞지만, 그 "전" 이 9초였다.**
|
||||
> 앞선 실패한 주입 시도들이 만든 흔들림이고, 주입 이후 뷰가 변하지 않았다는
|
||||
> 결론 자체는 유지된다.
|
||||
|
||||
### 왜 안 갈라졌는가 — **연결 방향이 뒤집혔다**
|
||||
|
||||
```
|
||||
@@ -281,6 +291,26 @@ JGroups 코디네이터는 **가장 오래된 멤버**다. 분단이 나면
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 12:29 – 16:34 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-injection.txt`](evidence/a5-asymmetric-partition/01-injection.txt) | 터미널 원문 |
|
||||
| [`02-injection-verify.txt`](evidence/a5-asymmetric-partition/02-injection-verify.txt) | 터미널 원문 |
|
||||
| [`03-raw-table-injection.txt`](evidence/a5-asymmetric-partition/03-raw-table-injection.txt) | 터미널 원문 |
|
||||
| [`04-correct-direction.txt`](evidence/a5-asymmetric-partition/04-correct-direction.txt) | 터미널 원문 |
|
||||
| [`05-reconnect-observed.txt`](evidence/a5-asymmetric-partition/05-reconnect-observed.txt) | 터미널 원문 |
|
||||
| [`06-view-history-and-cleanup.txt`](evidence/a5-asymmetric-partition/06-view-history-and-cleanup.txt) | 터미널 원문 |
|
||||
| [`07-bidirectional-block.txt`](evidence/a5-asymmetric-partition/07-bidirectional-block.txt) | 터미널 원문 |
|
||||
| [`08-coordinator-and-recovery.txt`](evidence/a5-asymmetric-partition/08-coordinator-and-recovery.txt) | 터미널 원문 |
|
||||
| [`a5-cluster-size-bidirectional-block.png`](evidence/a5-asymmetric-partition/a5-cluster-size-bidirectional-block.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/a5-asymmetric-partition/README.md`](evidence/a5-asymmetric-partition/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -130,10 +130,14 @@ qdisc netem 30: parent 1:3 limit 1000 delay 200ms
|
||||
|
||||
```
|
||||
=== 두 노드 지연 비교 (기준선: k0=70ms k1=66ms) ===
|
||||
keycloak-0 평균 41 ms 최대 57 ms ← 영향 없음
|
||||
keycloak-0 평균 41 ms 최대 57 ms ← 기준선 70ms 대비 -41%
|
||||
keycloak-1 평균 1872 ms 최대 1887 ms ← 28배
|
||||
```
|
||||
|
||||
> **대조군도 변했다** — keycloak-0 은 기준선 70ms 에서 41ms 로 **41% 빨라졌다.**
|
||||
> 주입과 무관한 변동(JIT 워밍업, 캐시)이며, **"영향 없음" 이라고 쓴 것은
|
||||
> 부정확했다.** 다만 keycloak-1 의 28배 증가와는 자릿수가 달라 결론은 유지된다.
|
||||
|
||||
### 왜 200ms 가 1,872ms 가 되는가
|
||||
|
||||
A-0 에서 잡은 로그인 트랜잭션의 SQL 이 답이다.
|
||||
@@ -156,6 +160,10 @@ COMMIT
|
||||
200 ms × 9 왕복 ≈ 1,800 ms 실측 1,872 ms
|
||||
```
|
||||
|
||||
> **9 는 SQL 목록을 센 것이고 패킷을 추적한 값이 아니다.** 자릿수가 맞는다는
|
||||
> 것까지가 이 계산이 말할 수 있는 범위이며, **왕복 수를 확정하려면
|
||||
> `tc -s` 나 패킷 캡처가 필요하다.**
|
||||
|
||||
> **네트워크 지연은 왕복 횟수만큼 증폭된다.**
|
||||
> "DB 가 200ms 느려졌다"는 "애플리케이션이 200ms 느려졌다"가 아니다.
|
||||
> **쿼리 수를 줄이는 것이 지연 환경에서 결정적인 이유**가 이것이다.
|
||||
@@ -296,6 +304,23 @@ histogram_quantile(0.99, rate(http_server_requests_seconds_bucket[5m]))
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 13:12 – 13:16 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-baseline.txt`](evidence/a6-latency-injection/01-baseline.txt) | 터미널 원문 |
|
||||
| [`02-delay-injected.txt`](evidence/a6-latency-injection/02-delay-injected.txt) | 터미널 원문 |
|
||||
| [`03-flannel-injection.txt`](evidence/a6-latency-injection/03-flannel-injection.txt) | 터미널 원문 |
|
||||
| [`04-pool-under-load.txt`](evidence/a6-latency-injection/04-pool-under-load.txt) | 터미널 원문 |
|
||||
| [`05-recovery.txt`](evidence/a6-latency-injection/05-recovery.txt) | 터미널 원문 |
|
||||
| [`a6-connection-pool-blocking.png`](evidence/a6-latency-injection/a6-connection-pool-blocking.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/a6-latency-injection/README.md`](evidence/a6-latency-injection/README.md).
|
||||
|
||||
## 8. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -9,6 +9,14 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터 — 비교표
|
||||
|
||||
| 실험 | persistent (KC 26 기본) | **volatile (KC 24 이전 방식)** |
|
||||
@@ -225,6 +233,23 @@ kubectl apply -f deploy/lab/k8s/keycloak-cluster.yaml
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 13:22 – 13:32 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-switch-to-volatile.txt`](evidence/a7-volatile-comparison/01-switch-to-volatile.txt) | 터미널 원문 |
|
||||
| [`02-a0-rerun.txt`](evidence/a7-volatile-comparison/02-a0-rerun.txt) | 터미널 원문 |
|
||||
| [`03-a8-rerun-restart.txt`](evidence/a7-volatile-comparison/03-a8-rerun-restart.txt) | 터미널 원문 |
|
||||
| [`04-a1-rerun-partition.txt`](evidence/a7-volatile-comparison/04-a1-rerun-partition.txt) | 터미널 원문 |
|
||||
| [`05-a2-rerun-db-loss.txt`](evidence/a7-volatile-comparison/05-a2-rerun-db-loss.txt) | 터미널 원문 |
|
||||
| [`06-restore-persistent.txt`](evidence/a7-volatile-comparison/06-restore-persistent.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/a7-volatile-comparison/README.md`](evidence/a7-volatile-comparison/README.md).
|
||||
|
||||
## 8. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -56,7 +56,14 @@ statefulset.apps/keycloak restarted
|
||||
200 200 200 200 partitioned roll out complete: 2 new pods have been updated...
|
||||
```
|
||||
|
||||
**9번 찍어서 9번 다 `200`.** 한 번도 끊기지 않았다.
|
||||
**9번 찍어서 9번 다 `200`.**
|
||||
|
||||
> **표본은 9개다.** 5초 간격으로 찍었으므로 **5초보다 짧은 끊김은 이 측정으로
|
||||
> 잡히지 않는다.** 실제로 후속 작업에서 1초 간격·3초 타임아웃으로 재보니
|
||||
> 롤백 전환 순간에 `000` 이 한 번 잡혔다
|
||||
> ([`followup`](experiment-followup-untested-items.md) 2절).
|
||||
> **"무중단" 은 관측 해상도에 달려 있으며, 여기서는 "5초 해상도에서 끊김이
|
||||
> 관측되지 않았다" 까지가 정확한 서술이다.**
|
||||
|
||||
### 왜 무중단이 되는가
|
||||
|
||||
@@ -137,6 +144,46 @@ readiness 프로브가 이 전환을 정확히 맞춰준다 — A-2 에서 본
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### StatefulSet 롤링 재시작의 무중단 조건
|
||||
|
||||
```
|
||||
한 번에 하나씩 내린다 + readiness 로 전환 시점을 맞춘다
|
||||
└─ 항상 최소 하나는 Ready 다
|
||||
```
|
||||
|
||||
**두 가지가 다 있어야 성립한다.** replica 1 이면 반드시 끊기고,
|
||||
readiness 프로브가 없으면 아직 기동 중인 파드로 트래픽이 간다.
|
||||
|
||||
### 룩어사이드 캐시가 재시작을 견디는 이유
|
||||
|
||||
| | 재시작 후 |
|
||||
|---|---|
|
||||
| 캐시 (프로세스 메모리) | **사라진다** |
|
||||
| DB (진실의 원천) | 남는다 |
|
||||
| 정확성 | **유지된다** — 첫 접근만 느려진다 |
|
||||
|
||||
A-0 에서 세운 모델이 여기서 그대로 확인된다.
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 13:19 – 13:20 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-restart-availability.txt`](evidence/a8-rolling-restart/01-restart-availability.txt) | 터미널 원문 |
|
||||
| [`02-session-survival.txt`](evidence/a8-rolling-restart/02-session-survival.txt) | 터미널 원문 |
|
||||
| [`a8-cache-reset-cluster-reformed.png`](evidence/a8-rolling-restart/a8-cache-reset-cluster-reformed.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/a8-rolling-restart/README.md`](evidence/a8-rolling-restart/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -245,6 +245,60 @@ kubectl -n keycloak-lab scale deployment/bff --replicas=1
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### `AuthenticatedPrincipalOAuth2AuthorizedClientRepository`
|
||||
|
||||
이름이 곧 설명이다 — **인증된 주체(principal) 기준**으로 authorized client 를 찾는다.
|
||||
|
||||
```
|
||||
인증되어 있으면 → OAuth2AuthorizedClientService 에 위임
|
||||
키: (clientRegistrationId, principalName)
|
||||
└─ session ID 가 없다 ★
|
||||
인증되지 않았으면 → HttpSession 에 임시 보관
|
||||
```
|
||||
|
||||
**같은 사용자의 두 브라우저가 같은 항목을 본다.** Q1 미지수 3 과 Q3 제약의 기제다.
|
||||
|
||||
### 인가 코드 흐름은 왕복이 두 번이다
|
||||
|
||||
```
|
||||
① 브라우저 → 앱 → IdP 로 리다이렉트 (state·PKCE verifier 를 저장)
|
||||
② IdP → 브라우저 → 앱의 콜백 (저장한 것을 꺼내 검증)
|
||||
```
|
||||
|
||||
**②가 ①과 같은 인스턴스로 가야 한다.** 저장 위치가 인스턴스 메모리면
|
||||
replica 를 늘리는 순간 로그인 자체가 실패한다.
|
||||
|
||||
### 자동구성은 조용히 고른다
|
||||
|
||||
빈을 직접 만들지 않으면 Spring Boot 가 조건에 따라 고른다.
|
||||
**무엇을 골랐는지는 실행 중인 인스턴스를 봐야 안다.**
|
||||
|
||||
```bash
|
||||
kubectl exec <pod> -- wget -qO- http://localhost:8083/actuator/beans
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 13:39 – 13:46 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-deploy.txt`](evidence/b0-bff-redis-deploy/01-deploy.txt) | 터미널 원문 |
|
||||
| [`02-autoconfiguration.txt`](evidence/b0-bff-redis-deploy/02-autoconfiguration.txt) | 터미널 원문 |
|
||||
| [`03-beans-analysis.txt`](evidence/b0-bff-redis-deploy/03-beans-analysis.txt) | 터미널 원문 |
|
||||
| [`b0-bff-login-success-single-replica.png`](evidence/b0-bff-redis-deploy/b0-bff-login-success-single-replica.png) | 스크린샷 |
|
||||
| [`b0-bff-token-boundary.png`](evidence/b0-bff-redis-deploy/b0-bff-token-boundary.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/b0-bff-redis-deploy/README.md`](evidence/b0-bff-redis-deploy/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -10,6 +10,15 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| | before | after | |
|
||||
@@ -260,6 +269,22 @@ Q3 는 *"저장소를 직접 열어 refresh token 이 평문으로 남는지 확
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 13:59 – 14:03 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-servicelinks-trap.txt`](evidence/b1-redis-session-store/01-servicelinks-trap.txt) | 터미널 원문 |
|
||||
| [`02-autoconfig-after.txt`](evidence/b1-redis-session-store/02-autoconfig-after.txt) | 터미널 원문 |
|
||||
| [`03-redis-contents.txt`](evidence/b1-redis-session-store/03-redis-contents.txt) | 터미널 원문 |
|
||||
| [`b1-login-works-two-replicas.png`](evidence/b1-redis-session-store/b1-login-works-two-replicas.png) | 스크린샷 |
|
||||
| [`b1-token-boundary-after-redis.png`](evidence/b1-redis-session-store/b1-token-boundary-after-redis.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/b1-redis-session-store/README.md`](evidence/b1-redis-session-store/README.md).
|
||||
|
||||
## 7. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -182,6 +182,14 @@ access_token 헤더 : {"alg":"RS256","typ":"JWT","kid":"OY-caYDNGoP4HMAz-..."}
|
||||
|
||||
같은 사용자로 다시 로그인시키고 행을 비교했다.
|
||||
|
||||
> **실제로는 브라우저를 두 개 쓰지 않았다.** 증거
|
||||
> [`04-overwrite-test.txt`](evidence/b2-multi-instance-session/04-overwrite-test.txt)
|
||||
> 에 `[모의 두 번째 브라우저] 세션만 지우고` 라고 적혀 있다.
|
||||
> **세션을 지우고 같은 사용자로 다시 로그인시킨 것**이며, 조회 키가
|
||||
> `(clientRegistrationId, principalName)` 이므로 브라우저가 둘이든 하나든
|
||||
> **같은 행을 쓴다는 점에서 등가**다. 다만 "두 브라우저에서" 라고 쓴 것은
|
||||
> 측정하지 않은 것을 측정한 것처럼 적은 것이다.
|
||||
|
||||
```
|
||||
=== 재로그인 전 ===
|
||||
principal_name | access_token_issued_at | at_md5
|
||||
@@ -271,6 +279,65 @@ access_token 헤더 : {"alg":"RS256","typ":"JWT","kid":"OY-caYDNGoP4HMAz-..."}
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### 조회 키는 저장소와 독립이다
|
||||
|
||||
```sql
|
||||
PRIMARY KEY (client_registration_id, principal_name)
|
||||
```
|
||||
|
||||
**저장소를 메모리에서 DB 로 옮겨도 이 키는 그대로다.**
|
||||
"공유 저장소로 바꾼다" 와 "세션별로 구분한다" 는 다른 문제이며,
|
||||
전자만 하면 인스턴스 간 공유는 되고 브라우저 간 격리는 안 된다.
|
||||
|
||||
### 스키마 DDL 의 방언 차이
|
||||
|
||||
> **정정** — 이 절의 제목은 처음에 "Liquibase 스키마의 방언 차이" 였다.
|
||||
> **Liquibase 가 아니다.** 여기서 스키마를 태우는 것은 Spring Boot 의
|
||||
> `spring.sql.init` 이고, DDL 은 `spring-security-oauth2-client` jar 가
|
||||
> 번들한 파일이다. (Liquibase 는 Keycloak 이 자기 스키마에 쓰며, D-2 의 주제다.)
|
||||
|
||||
Spring Security 는 DDL 을 두 벌 제공한다.
|
||||
|
||||
| 파일 | 타입 |
|
||||
|---|---|
|
||||
| `oauth2-client-schema.sql` | `blob` — PostgreSQL 에 **없는 타입** |
|
||||
| `oauth2-client-schema-postgres.sql` | `bytea` |
|
||||
|
||||
`spring.sql.init.continue-on-error: true` 는 이 실패를 삼킨다.
|
||||
**"없어도 되는 초기화" 에만 써야 하는 이유다.**
|
||||
|
||||
### 로그아웃이 지워야 하는 것은 셋이다
|
||||
|
||||
```
|
||||
① HttpSession (Spring Security 가 지운다)
|
||||
② OAuth2AuthorizedClient ★ 아무도 안 지운다
|
||||
③ IdP SSO 세션 ★ RP-initiated logout 을 보내야 한다
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:09 – 14:13 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-jdbc-store-deploy.txt`](evidence/b2-multi-instance-session/01-jdbc-store-deploy.txt) | 터미널 원문 |
|
||||
| [`02-schema.txt`](evidence/b2-multi-instance-session/02-schema.txt) | 터미널 원문 |
|
||||
| [`03-plaintext-tokens.txt`](evidence/b2-multi-instance-session/03-plaintext-tokens.txt) | 터미널 원문 |
|
||||
| [`04-overwrite-test.txt`](evidence/b2-multi-instance-session/04-overwrite-test.txt) | 터미널 원문 |
|
||||
| [`05-logout-cleanup.txt`](evidence/b2-multi-instance-session/05-logout-cleanup.txt) | 터미널 원문 |
|
||||
| [`b2-before-relogin.png`](evidence/b2-multi-instance-session/b2-before-relogin.png) | 스크린샷 |
|
||||
| [`b2-tokens-shared-across-instances.png`](evidence/b2-multi-instance-session/b2-tokens-shared-across-instances.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/b2-multi-instance-session/README.md`](evidence/b2-multi-instance-session/README.md).
|
||||
|
||||
## 8. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -12,6 +12,15 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
**"하나는 성공하고 하나는 실패한다"가 아니다. 세션이 파괴된다.**
|
||||
@@ -66,6 +75,21 @@ kubectl -n keycloak-lab exec keycloak-0 -- /opt/keycloak/bin/kcadm.sh \
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:16 – 14:17 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-concurrent-refresh.txt`](evidence/b3-refresh-contention/01-concurrent-refresh.txt) | 터미널 원문 |
|
||||
| [`02-session-impact.txt`](evidence/b3-refresh-contention/02-session-impact.txt) | 터미널 원문 |
|
||||
| [`03-client-session-removed.txt`](evidence/b3-refresh-contention/03-client-session-removed.txt) | 터미널 원문 |
|
||||
| [`04-policy-comparison.txt`](evidence/b3-refresh-contention/04-policy-comparison.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/b3-refresh-contention/README.md`](evidence/b3-refresh-contention/README.md).
|
||||
|
||||
## 2. 재현 — 진짜 동시성을 만든다
|
||||
|
||||
B-2 에서 토큰이 PostgreSQL 로 공유되므로 두 replica 가 같은 항목을 본다.
|
||||
@@ -231,6 +255,44 @@ select VERSION from OFFLINE_USER_SESSION ... for no key update skip locked
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### user session 과 client session
|
||||
|
||||
```
|
||||
user session "이 브라우저는 labuser 로 로그인함"
|
||||
├─ client session : bff-confidential
|
||||
└─ client session : oauth2-proxy
|
||||
```
|
||||
|
||||
**재사용 탐지는 client session 만 제거한다.** user session 은 껍데기로 남아
|
||||
`Session doesn't have required client` 가 된다.
|
||||
|
||||
### `revokeRefreshToken` 과 `refreshTokenMaxReuse`
|
||||
|
||||
| 설정 | 뜻 |
|
||||
|---|---|
|
||||
| `revokeRefreshToken` | **회전 스위치.** 켜면 새 토큰 발급 시 옛 토큰을 무효화 |
|
||||
| `refreshTokenMaxReuse` | 그 위에서 **몇 번까지 봐줄 것인가** |
|
||||
|
||||
**이름이 "회전" 이 아니라 "취소" 라서 헷갈린다.**
|
||||
그리고 `maxReuse` 를 올리는 것은 해법이 아니다 — 동시 요청이 N개면
|
||||
`N-1` 이 필요하고, 그러면 회전의 보안 목적이 사라진다.
|
||||
|
||||
### lock 의 수명은 어디에 묶이는가
|
||||
|
||||
| 방식 | 프로세스가 죽으면 |
|
||||
|---|---|
|
||||
| **DB 행 잠금** | **연결이 끊기면 자동 해제** |
|
||||
| Redis lock + TTL | TTL 만료까지 막힌다 |
|
||||
|
||||
**잠금 수명이 연결 수명과 묶이는 것이 DB 잠금의 이점**이며,
|
||||
A-0 에서 Keycloak 자신이 `for no key update skip locked` 를 쓰는 이유다.
|
||||
|
||||
---
|
||||
|
||||
## 7. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -10,6 +10,15 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| Q4 의 미지수 | 측정 결과 |
|
||||
@@ -212,6 +221,57 @@ Keycloak 의 role 이름은 임의 문자열이므로 **막을 수 있는 것이
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### nginx 의 헤더 처리는 조건부다
|
||||
|
||||
```nginx
|
||||
proxy_set_header X-Forwarded-Proto https; # 설정한 것 → 덮어쓴다
|
||||
# X-Auth-Request-Roles 설정 없음 # 안 한 것 → 통과시킨다
|
||||
```
|
||||
|
||||
HTTP 는 **같은 이름의 헤더가 여러 번 오는 것을 허용**하므로,
|
||||
edge 가 붙인 것과 클라이언트가 보낸 것이 **함께 도착**한다.
|
||||
Spring 의 `request.getHeader()` 는 **첫 번째**를 돌려주고,
|
||||
그 순서는 프록시가 정한다.
|
||||
|
||||
### 헤더 크기 한계는 계층마다 다르다
|
||||
|
||||
| 크기 | 누가 거부하나 | 클라이언트가 보는 것 |
|
||||
|---|---|---|
|
||||
| ~8KB | **Tomcat** (`maxHttpHeaderSize`) | `400` + HTML |
|
||||
| ~16KB | **nginx** (`large_client_header_buffers`) | 응답 없음 |
|
||||
|
||||
**같은 원인이 두 가지로 보인다.** 그리고 점진적이 아니라 절벽이며,
|
||||
**role 이 많은 사용자만** 깨진다.
|
||||
|
||||
### 세 곳이 독립적으로 필요하다
|
||||
|
||||
```
|
||||
① 외부 → upstream 직접 경로 차단 (NetworkPolicy)
|
||||
② edge 에서 동명 헤더 덮어쓰기 (proxy_set_header)
|
||||
③ upstream 에서 내부 credential 검증 (공통 경계)
|
||||
```
|
||||
|
||||
**하나라도 빠지면 나머지 둘이 무의미하다.** 2홉 실험의 결론이 그대로 적용되며,
|
||||
거기서는 쿠키 속성이었지만 **여기서는 신원 자체**다.
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:23 – 14:23 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-header-handling.txt`](evidence/b4-edge-authorization/01-header-handling.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/b4-edge-authorization/README.md`](evidence/b4-edge-authorization/README.md).
|
||||
|
||||
## 7. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -8,6 +8,15 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| | 결과 |
|
||||
@@ -214,6 +223,21 @@ appendfsync everysec ← 기본값
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:24 – 14:28 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-baseline.txt`](evidence/b5-redis-loss/01-baseline.txt) | 터미널 원문 |
|
||||
| [`02-redis-down.txt`](evidence/b5-redis-loss/02-redis-down.txt) | 터미널 원문 |
|
||||
| [`03-health-groups.txt`](evidence/b5-redis-loss/03-health-groups.txt) | 터미널 원문 |
|
||||
| [`04-persistence.txt`](evidence/b5-redis-loss/04-persistence.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/b5-redis-loss/README.md`](evidence/b5-redis-loss/README.md).
|
||||
|
||||
## 5. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -12,6 +12,15 @@
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
**질문이 두 갈래로 나뉜다.**
|
||||
@@ -194,6 +203,20 @@ kcadm.sh get components -r keycloak-patterns -q type=org.keycloak.keys.KeyProvid
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:30 – 14:32 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-before-rotation.txt`](evidence/b6-key-rotation/01-before-rotation.txt) | 터미널 원문 |
|
||||
| [`02-rotation.txt`](evidence/b6-key-rotation/02-rotation.txt) | 터미널 원문 |
|
||||
| [`03-old-key-removed.txt`](evidence/b6-key-rotation/03-old-key-removed.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/b6-key-rotation/README.md`](evidence/b6-key-rotation/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -218,6 +218,58 @@ _oauth2_proxy-b26111fbd1fdab3ae2182e287001b02a ← ★ 옛 세션. 남아 있
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### 상태를 어디에 두는가가 공유 문제의 성격을 정한다
|
||||
|
||||
| | 상태 위치 | replica 간 공유 |
|
||||
|---|---|---|
|
||||
| BFF | **서버 메모리 / Redis** | **저장소를 공유해야** 한다 |
|
||||
| oauth2-proxy | **쿠키 (서명·암호화)** | **secret 만 같으면** 된다 |
|
||||
|
||||
**공유할 상태가 없으면 공유 문제도 없다.** 대신 secret 이 단일 지점이 된다.
|
||||
|
||||
### 세션 티켓
|
||||
|
||||
`--session-store-type=redis` 를 쓰면 쿠키에는 **티켓**만 담긴다.
|
||||
|
||||
```
|
||||
_oauth2_proxy=<ticket>|<timestamp>|<mac>
|
||||
└─ Redis 키를 여기서 계산한다
|
||||
```
|
||||
|
||||
**secret 이 바뀌면 티켓을 못 푼다 → Redis 키를 계산할 수 없다 →
|
||||
정리도 못 한다.** 고아 세션이 남는 이유다.
|
||||
|
||||
### key 식별자가 없으면 회전에 겹침이 없다
|
||||
|
||||
B-6 에서 Keycloak 은 `kid` 로 여러 키를 구분해 무중단 회전을 했다.
|
||||
**oauth2-proxy 의 쿠키에는 그런 식별자가 없고, `--cookie-secret` 도 단수다.**
|
||||
|
||||
```
|
||||
식별자 있음 → 읽기는 여러 key, 쓰기는 하나 → 겹침 가능
|
||||
식별자 없음 → 전부 한 번에 바뀐다 → 겹침 불가
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:35 – 14:42 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-deploy.txt`](evidence/b7-cookie-secret/01-deploy.txt) | 터미널 원문 |
|
||||
| [`02-cookie-portability.txt`](evidence/b7-cookie-secret/02-cookie-portability.txt) | 터미널 원문 |
|
||||
| [`03-rotation.txt`](evidence/b7-cookie-secret/03-rotation.txt) | 터미널 원문 |
|
||||
| [`b7-oauth2proxy-login-success.png`](evidence/b7-cookie-secret/b7-oauth2proxy-login-success.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/b7-cookie-secret/README.md`](evidence/b7-cookie-secret/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
|
||||
@@ -0,0 +1,275 @@
|
||||
# C-1 — SSO 를 붙이면 무엇이 달라지는가
|
||||
|
||||
브랜치 `feature/keycloak-c1-multi-app-sso` ·
|
||||
증거 [`docs/evidence/c1-multi-app-sso/`](evidence/c1-multi-app-sso/) ·
|
||||
2026-09-04 16:15–16:30 KST
|
||||
|
||||
선행: [`B-2`](experiment-b2-multi-instance-session.md) (app1 = BFF) ·
|
||||
[`B-7`](experiment-b7-cookie-secret-rotation.md) (app2 = oauth2-proxy)
|
||||
|
||||
**원래 질문** — *"SSO 를 추가하게 되면 어떻게 달라지는지"*
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| 물음 | 답 |
|
||||
|---|---|
|
||||
| 두 번째 앱에서 로그인 화면이 뜨는가 | **안 뜬다.** SSO 가 동작한다 |
|
||||
| Keycloak 안의 구조는 | **user session 1개 · client session 2개** |
|
||||
| **IdP 세션을 죽이면 두 앱이 끊기는가** | **★ 안 끊긴다.** 두 앱 모두 그대로 동작한다 |
|
||||
|
||||
**"SSO 를 붙이면 IdP 가 단일 장애점이 된다" 는 절반만 맞다.**
|
||||
**로그인할 때는 그렇고, 이미 로그인한 뒤에는 아니다.**
|
||||
|
||||
---
|
||||
|
||||
## 1. 구성 — 서로 다른 구조의 두 앱
|
||||
|
||||
```
|
||||
app1.hyeonworks.com → BFF 서버 세션 (Redis) + 토큰 (PostgreSQL)
|
||||
app2.hyeonworks.com → oauth2-proxy 쿠키 티켓 + 세션 (Redis)
|
||||
|
||||
둘 다 realm keycloak-patterns
|
||||
```
|
||||
|
||||
**우연히 좋은 실험대가 됐다.** B-2 와 B-7 에서 만든 두 앱이
|
||||
**같은 IdP 를 쓰지만 세션을 완전히 다르게 다룬다.**
|
||||
|
||||
### 깨끗한 상태에서 시작한다
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak \
|
||||
-c "delete from offline_client_session" -c "delete from offline_user_session"
|
||||
kubectl -n keycloak-lab exec deploy/redis -- redis-cli flushall
|
||||
kubectl -n keycloak-lab rollout restart statefulset/keycloak
|
||||
```
|
||||
|
||||
**`kcadm create realms/.../logout-all` 은 듣지 않았다.** 세션이 그대로 남아
|
||||
DB 를 직접 지우고 Keycloak 을 재시작해야 했다 — **캐시 때문이다**
|
||||
(A-1 에서 확인한 대로, DB 를 직접 지워도 캐시는 남는다).
|
||||
|
||||
```
|
||||
Keycloak 온라인 세션: 4 ← 초기화가 안 먹었다
|
||||
app1 HTTP 200 / app2 HTTP 200
|
||||
```
|
||||
|
||||
> **정정** — 이 문서는 처음에 이 값을 `0` 으로 인쇄했다. 증거
|
||||
> [`01-baseline.txt`](evidence/c1-multi-app-sso/01-baseline.txt) 는 `4` 다.
|
||||
> `logout-all` 이 듣지 않아 세션이 남아 있었고, 그래서 아래 절차(DB 직접 삭제 +
|
||||
> Keycloak 재시작)가 필요했다. **`0` 은 그 다음 단계의 값이었다.**
|
||||
|
||||
---
|
||||
|
||||
## 2. SSO 가 동작한다
|
||||
|
||||
### app1 로그인 — 로그인 화면이 나온다
|
||||
|
||||
```
|
||||
https://auth.hyeonworks.com/realms/keycloak-patterns/protocol/openid-connect/auth
|
||||
?client_id=bff-confidential&...
|
||||
→ Sign in to keycloak-patterns
|
||||
```
|
||||
|
||||
로그인 후
|
||||
|
||||
```
|
||||
user_session_id | client_sessions
|
||||
--------------------------+-----------------
|
||||
oqOjHekin4JU-BZjgQLjUByW | 1
|
||||
|
||||
Redis: bff:session:sessions:6e0d9af4-...
|
||||
PostgreSQL authorized client: 1 행
|
||||
```
|
||||
|
||||
### app2 방문 — **로그인 화면 없이 통과한다**
|
||||
|
||||

|
||||
|
||||
```
|
||||
user_session_id | client_sessions
|
||||
--------------------------+-----------------
|
||||
oqOjHekin4JU-BZjgQLjUByW | 2 ← 1 → 2
|
||||
|
||||
client_id | name
|
||||
--------------------------------------+------------------
|
||||
9055fa46-6abb-4d6d-a339-8a9183bbf26d | bff-confidential
|
||||
80431dbc-af81-4673-9790-ad06d1570b2e | oauth2-proxy
|
||||
|
||||
Redis:
|
||||
bff:session:sessions:6e0d9af4-... ← app1 의 세션
|
||||
_oauth2_proxy-6b028a70f... ← app2 의 세션
|
||||
```
|
||||
|
||||
### 개념 — SSO 의 데이터 구조
|
||||
|
||||
```
|
||||
user session (사용자 · 브라우저 하나당 하나)
|
||||
├─ client session : bff-confidential
|
||||
└─ client session : oauth2-proxy
|
||||
```
|
||||
|
||||
**A-3 과 B-3 에서 봤던 그 구조가 여기서 의미를 갖는다.**
|
||||
|
||||
- **A-3** — 크래시로 `user_session` 행이 통째로 사라지면 **모든 앱이 끊긴다**
|
||||
- **B-3** — 재사용 탐지가 **`client_session` 만** 제거하면 **그 앱만 끊긴다**
|
||||
|
||||
**두 층이 나뉘어 있는 이유가 SSO 다.** 앱 하나의 문제가 다른 앱에 번지지
|
||||
않도록 하려면 client session 이 따로 있어야 한다.
|
||||
|
||||
---
|
||||
|
||||
## 3. ★ IdP 세션을 죽여도 두 앱은 살아 있다
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec keycloak-0 -- /opt/keycloak/bin/kcadm.sh \
|
||||
create users/<user-id>/logout -r keycloak-patterns
|
||||
```
|
||||
|
||||
```
|
||||
남은 keycloak-patterns 세션: 0 (master realm 의 admin 세션만 남음)
|
||||
|
||||
Redis:
|
||||
_oauth2_proxy-6b028a70f... ← 남아 있다
|
||||
bff:session:sessions:6e0d9af4-... ← 남아 있다
|
||||
PostgreSQL authorized client: 1 행 ← 남아 있다
|
||||
```
|
||||
|
||||
브라우저로 두 앱을 다시 열었다.
|
||||
|
||||

|
||||
|
||||
**둘 다 로그인 화면 없이 그대로 열렸다.**
|
||||
|
||||
### 왜 그런가 — 세 개의 독립된 수명
|
||||
|
||||
```
|
||||
① IdP 세션 (Keycloak) ssoSessionIdleTimeout 1800초
|
||||
② 앱 세션 (BFF / oauth2-proxy) 각자 30분 / 1시간
|
||||
③ access token 60초
|
||||
|
||||
①을 지워도 ②는 자기 수명을 산다
|
||||
```
|
||||
|
||||
**로그아웃은 ①만 지운 것이고, ②는 아무도 안 건드렸다.**
|
||||
|
||||
| 언제 끊기는가 | |
|
||||
|---|---|
|
||||
| BFF | access token 이 만료되어 **refresh 를 시도할 때** → `Session not active` |
|
||||
| oauth2-proxy | 쿠키 만료(1시간) 또는 **토큰 갱신 시도**할 때 |
|
||||
|
||||
**즉시가 아니라 지연되어 끊긴다.** 최대 지연은 access token 수명(60초)이
|
||||
아니라 **앱이 다음에 IdP 를 부를 때까지**다.
|
||||
|
||||
> **이것이 B-2 에서 "로그아웃했는데 다시 들어가진다" 를 겪은 것의 반대편이다.**
|
||||
> 거기서는 앱 세션을 지웠는데 IdP 세션이 남아 재로그인이 됐고,
|
||||
> 여기서는 IdP 세션을 지웠는데 앱 세션이 남아 계속 들어가진다.
|
||||
>
|
||||
> **두 방향 모두 "한쪽만 지우면 다른 쪽이 남는다" 이다.**
|
||||
|
||||
---
|
||||
|
||||
## 4. 그래서 SSO 의 대가는 무엇인가
|
||||
|
||||
원래 질문 *"SSO 를 추가하면 어떻게 달라지는가"* 에 대한 답이다.
|
||||
|
||||
| | 앱이 하나일 때 | **SSO 일 때** |
|
||||
|---|---|---|
|
||||
| 로그인 | 앱마다 | **한 번** |
|
||||
| IdP 가 죽으면 | 그 앱만 로그인 불가 | **모든 앱이 로그인 불가** |
|
||||
| **이미 로그인한 사용자** | — | **★ 영향 없다** (앱 세션이 살아 있으므로) |
|
||||
| 로그아웃 | 그 앱만 | **전 앱을 끊으려면 백채널 로그아웃이 필요** |
|
||||
| 세션 수명 | 하나 | **세 층이 각자** — 어긋나면 예측이 어렵다 |
|
||||
|
||||
**IdP 는 "로그인 경로"의 단일 장애점이지 "이미 로그인한 사용자"의 단일 장애점이
|
||||
아니다.** A-2(DB 상실)에서 본 것과 합치면
|
||||
|
||||
```
|
||||
Keycloak DB 죽음 → 새 로그인 불가 (전 앱)
|
||||
→ 이미 로그인한 사용자는 앱 세션 수명 동안 계속 쓴다
|
||||
→ 그 뒤 갱신 시점에 한꺼번에 끊긴다
|
||||
```
|
||||
|
||||
**장애가 즉시 전면화되지 않고 "앱 세션 수명만큼 지연되어 몰려온다."**
|
||||
이것이 SSO 구조의 장애 모양이며, **모니터링이 어려운 이유**다.
|
||||
|
||||
---
|
||||
|
||||
## 5. 겪은 문제
|
||||
|
||||
| 문제 | |
|
||||
|---|---|
|
||||
| `kcadm create realms/<r>/logout-all` 이 안 먹었다 | 세션 수가 그대로였다. DB 를 직접 지우고 **Keycloak 재시작**해야 했다 (A-1 의 캐시 문제) |
|
||||
| `kcadm delete sessions/<id>` 도 안 먹었다 | 오류 없이 아무 일도 안 일어났다. `users/<id>/logout` 은 동작했다 |
|
||||
| 세션 수를 셀 때 realm 을 안 봤다 | `master` realm 의 admin 세션이 섞여 "안 지워졌다" 로 오독할 뻔했다 |
|
||||
|
||||
**세 번째가 특히 위험했다** — realm 을 join 해서 보고 나서야 알았다.
|
||||
|
||||
```sql
|
||||
select us.user_session_id, r.name as realm, ...
|
||||
from offline_user_session us join realm r on r.id = us.realm_id
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:44 – 14:48 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-baseline.txt`](evidence/c1-multi-app-sso/01-baseline.txt) | 터미널 원문 |
|
||||
| [`02-after-app1-login.txt`](evidence/c1-multi-app-sso/02-after-app1-login.txt) | 터미널 원문 |
|
||||
| [`03-after-app2-visit.txt`](evidence/c1-multi-app-sso/03-after-app2-visit.txt) | 터미널 원문 |
|
||||
| [`04-sso-session-killed.txt`](evidence/c1-multi-app-sso/04-sso-session-killed.txt) | 터미널 원문 |
|
||||
| [`c1-apps-alive-after-idp-logout.png`](evidence/c1-multi-app-sso/c1-apps-alive-after-idp-logout.png) | 스크린샷 |
|
||||
| [`c1-sso-app2-no-login-screen.png`](evidence/c1-multi-app-sso/c1-sso-app2-no-login-screen.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/c1-multi-app-sso/README.md`](evidence/c1-multi-app-sso/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
# 1. 깨끗한 상태 — logout-all 은 안 먹으므로 DB + 재시작
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak \
|
||||
-c "delete from offline_client_session" -c "delete from offline_user_session"
|
||||
kubectl -n keycloak-lab exec deploy/redis -- redis-cli flushall
|
||||
kubectl -n keycloak-lab rollout restart statefulset/keycloak
|
||||
|
||||
# 2. app1 로그인 → app2 방문 (로그인 화면이 안 떠야 SSO)
|
||||
|
||||
# 3. 구조 확인 — user session 1 에 client session 2
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak -c \
|
||||
"select us.user_session_id, r.name as realm,
|
||||
(select count(*) from offline_client_session cs
|
||||
where cs.user_session_id=us.user_session_id) as clients
|
||||
from offline_user_session us join realm r on r.id=us.realm_id
|
||||
where us.offline_flag='0'"
|
||||
|
||||
# 4. IdP 세션만 죽인다
|
||||
kubectl -n keycloak-lab exec keycloak-0 -- /opt/keycloak/bin/kcadm.sh \
|
||||
create users/<user-id>/logout -r keycloak-patterns
|
||||
|
||||
# 5. 두 앱을 다시 연다 — 그대로 열리면 앱 세션이 독립적이라는 뜻
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 7. 다음 실험에 남기는 것
|
||||
|
||||
| 실험 | 이 실험이 준 것 |
|
||||
|---|---|
|
||||
| **C-2** 백채널 로그아웃 | **이 실험이 C-2 가 왜 필요한지 보여준다** — IdP 로그아웃이 앱에 전파되지 않는다 |
|
||||
| **D-1** 백업·복구 | user session 을 잃으면 전 앱이 끊긴다 — 백업 범위에 들어간다 |
|
||||
| 운영 | **세 층의 수명을 맞추거나, 어긋날 때의 동작을 정의해야 한다** |
|
||||
@@ -0,0 +1,261 @@
|
||||
# C-2 — 로그아웃이 전 앱에 퍼지는가 (백채널 로그아웃)
|
||||
|
||||
브랜치 `feature/keycloak-c2-backchannel-logout` ·
|
||||
증거 [`docs/evidence/c2-backchannel-logout/`](evidence/c2-backchannel-logout/) ·
|
||||
2026-09-04 16:30–16:55 KST
|
||||
|
||||
선행: [`C-1`](experiment-c1-multi-app-sso.md) — **IdP 로그아웃이 앱에 전파되지 않는다**를 관측했다
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| 확인 | 결과 |
|
||||
|---|---|
|
||||
| 백채널 로그아웃이 설정되어 있었는가 | **아니다.** 두 클라이언트 모두 `backchannelLogoutUrl` 없음 |
|
||||
| BFF 에 그 엔드포인트가 있는가 | **아니다.** 소스에 `oidcLogout` 설정이 없다 |
|
||||
| IdP 쪽만 설정하면 되는가 | **★ 안 된다.** 앱 세션이 그대로 남았다 |
|
||||
| Keycloak 이 앱 URL 에 닿기는 하는가 | **닿는다** (`HTTP 200`) — 네트워크 문제가 아니다 |
|
||||
|
||||
**C-1 이 관측한 "로그아웃이 안 퍼진다" 의 원인은 단순했다 —
|
||||
아무도 구현하지 않았다.**
|
||||
|
||||
---
|
||||
|
||||
## 1. 현재 상태 — 어느 쪽에도 없다
|
||||
|
||||
### IdP 쪽
|
||||
|
||||
```bash
|
||||
kcadm.sh get clients -r keycloak-patterns -q clientId=bff-confidential --fields attributes
|
||||
```
|
||||
|
||||
```
|
||||
frontchannelLogout : false
|
||||
(backchannel.logout.url 없음)
|
||||
```
|
||||
|
||||
`oauth2-proxy` 클라이언트도 마찬가지였다.
|
||||
|
||||
### 앱 쪽
|
||||
|
||||
```bash
|
||||
grep -rn "oidcLogout\|backchannel" bff/src/main/java/
|
||||
```
|
||||
|
||||
**아무것도 안 나온다.**
|
||||
|
||||
Spring Security 6.2+ 는 백채널 로그아웃을 지원하지만 **명시적으로 켜야 한다.**
|
||||
|
||||
```java
|
||||
.oidcLogout(oidc -> oidc.backChannel(Customizer.withDefaults()))
|
||||
```
|
||||
|
||||
이 설정이 없으면 `/logout/connect/back-channel/{registrationId}` 경로가
|
||||
**생기지 않는다.**
|
||||
|
||||
```
|
||||
/logout/connect/back-channel/keycloak HTTP 302 ← 로그인으로 리다이렉트
|
||||
/backchannel-logout HTTP 302
|
||||
/oauth2/sign_out HTTP 302
|
||||
```
|
||||
|
||||
**302 는 "그런 핸들러가 없어서 인증 요구로 떨어졌다"는 뜻**이다.
|
||||
엔드포인트가 있었다면 POST 를 받아 200 이나 400 을 돌려줬을 것이다.
|
||||
|
||||
---
|
||||
|
||||
## 2. IdP 쪽만 설정하고 시험했다
|
||||
|
||||
```bash
|
||||
kcadm.sh update clients/<id> -r keycloak-patterns \
|
||||
-s 'attributes={"backchannel.logout.url":"https://app1.hyeonworks.com/logout/connect/back-channel/keycloak",
|
||||
"backchannel.logout.session.required":"true"}'
|
||||
```
|
||||
|
||||
```
|
||||
backchannel.logout.session.required = true
|
||||
backchannel.logout.url = https://app1.hyeonworks.com/logout/connect/back-channel/keycloak
|
||||
```
|
||||
|
||||
> **출처 주의** — 위 확인 출력은
|
||||
> [`02-configure-idp.txt`](evidence/c2-backchannel-logout/02-configure-idp.txt) 가
|
||||
> 아니라 그 뒤 별도로 실행한 조회에서 나온 것이다. 그 파일에는
|
||||
> **`command terminated with exit code 1`** 이 남아 있다 —
|
||||
> `-s "attributes.backchannel.logout.url=..."` 의 점 표기가 실패한 첫 시도이며,
|
||||
> JSON 으로 다시 넣어 성공했다. **실패한 시도의 파일에 성공 출력을 붙여
|
||||
> 인쇄한 것은 잘못이었다.**
|
||||
|
||||
### 살아 있는 세션에 로그아웃을 걸었다
|
||||
|
||||
```
|
||||
=== 로그아웃 전 ===
|
||||
keycloak-patterns 세션: 1
|
||||
Redis: 1 키
|
||||
|
||||
=== IdP 로그아웃 ===
|
||||
kcadm.sh create users/<id>/logout -r keycloak-patterns
|
||||
|
||||
=== 결과 ===
|
||||
keycloak-patterns 세션: 0 ← IdP 쪽은 끊겼다
|
||||
Redis: 1 키 ← ★ 앱 세션은 그대로다
|
||||
```
|
||||
|
||||
**IdP 세션만 사라지고 앱 세션은 남았다.** C-1 과 같은 결과다.
|
||||
|
||||
### 네트워크 문제가 아님을 확인했다
|
||||
|
||||
```
|
||||
=== Keycloak 파드가 app1.hyeonworks.com 에 닿는가 ===
|
||||
DNS 해석: Address: 100.83.212.4
|
||||
HTTPS 도달: HTTP 200
|
||||
```
|
||||
|
||||
**클러스터 안에서 공개 이름으로 앱에 닿는다.** 이 실험대는 tailnet + split DNS
|
||||
구성이라 헤어핀이 되는데, **운영에서는 안 되는 경우가 흔하다.**
|
||||
|
||||
> **백채널 로그아웃의 숨은 전제** — IdP 가 **앱의 공개 URL 로 서버에서 서버로**
|
||||
> 요청을 보낼 수 있어야 한다. 앱이 사설망에 있고 IdP 가 밖에 있으면
|
||||
> **설정을 해도 도달하지 못한다.** 그때는 로그도 안 남고 조용히 실패한다.
|
||||
|
||||
---
|
||||
|
||||
## 3. 그래서 왜 안 퍼졌는가
|
||||
|
||||
```
|
||||
IdP 로그아웃
|
||||
├─ ① Keycloak 이 backchannel.logout.url 로 POST 를 보낸다 (설정함)
|
||||
├─ ② 앱이 그 POST 를 받는 엔드포인트를 갖고 있다 ★ 없다
|
||||
└─ ③ 앱이 logout token 을 검증하고 sid 로 세션을 찾아 지운다 ★ 없다
|
||||
```
|
||||
|
||||
**②와 ③이 없다.** ①만 설정해도 받을 사람이 없다.
|
||||
|
||||
Keycloak 로그에 `backchannel` 문자열이 **0줄**이었다 — 다만 이것만으로
|
||||
"보내지 않았다"고 단정할 수는 없다 (DEBUG 레벨일 수 있다).
|
||||
**확실한 것은 앱 세션이 남았다는 관측**이다.
|
||||
|
||||
---
|
||||
|
||||
## 4. 개념 — 백채널 로그아웃의 구조
|
||||
|
||||
```
|
||||
사용자가 어느 앱에서든 로그아웃
|
||||
│
|
||||
▼
|
||||
Keycloak 이 SSO 세션에 붙은 client session 목록을 본다 (C-1 의 그 구조)
|
||||
│
|
||||
├──POST──▶ app1 의 backchannel.logout.url
|
||||
└──POST──▶ app2 의 backchannel.logout.url
|
||||
본문: logout_token (JWT)
|
||||
{ "sid": "...", "sub": "...", "events": {...} }
|
||||
```
|
||||
|
||||
### `sid` 가 여기서 쓰인다
|
||||
|
||||
**A-0 에서 확인한 그 `sid`** 다 — JWT·DB·관리 API 에서 같은 문자열이었던.
|
||||
|
||||
```
|
||||
logout_token 의 sid → 앱이 "그 sid 로 만든 내 세션"을 찾아 지운다
|
||||
```
|
||||
|
||||
**그래서 앱은 `sid → 자기 세션 ID` 역인덱스를 갖고 있어야 한다.**
|
||||
Spring Security 는 이를 위해 `OidcSessionRegistry` 를 쓰며,
|
||||
**여러 인스턴스가 있으면 그 레지스트리도 공유 저장소여야 한다** —
|
||||
B-1·B-2 에서 겪은 것과 **같은 문제가 한 겹 더 있다.**
|
||||
|
||||
### 부분 실패는 어떻게 되는가
|
||||
|
||||
```
|
||||
app1 로그아웃 성공, app2 는 응답 없음
|
||||
└─ Keycloak 은 재시도하는가? 얼마나?
|
||||
└─ 사용자는 app2 에서 여전히 로그인 상태다
|
||||
```
|
||||
|
||||
**로그아웃은 원자적이지 않다.** 앱이 늘어날수록 "일부만 로그아웃된 상태"가
|
||||
생길 확률이 올라간다.
|
||||
|
||||
---
|
||||
|
||||
## 5. 겪은 문제
|
||||
|
||||
| 문제 | |
|
||||
|---|---|
|
||||
| `kcadm -s "attributes.backchannel.logout.url=..."` 이 exit 1 | 점 표기가 안 먹는다. **JSON 으로 통째로** 줘야 한다 |
|
||||
| 첫 시험이 무의미했다 | 로그아웃 전 IdP 세션이 **이미 0** 이었다. 끊을 대상이 없었다 |
|
||||
| 세션 수를 realm 없이 셌다 | C-1 과 같은 실수 — `master` 의 admin 세션이 섞인다 |
|
||||
| Keycloak 재시작 후 로그인 폼이 안 넘어갔다 | 인증 세션 쿠키가 무효화된 상태에서 폼을 재사용했다 |
|
||||
|
||||
**두 번째가 A층에서 반복한 교훈이다** — **주입 대상이 실제로 존재하는지
|
||||
먼저 확인한다.** 세션이 없는 상태에서 로그아웃을 걸고 "전파가 안 된다"고
|
||||
결론지을 뻔했다.
|
||||
|
||||
---
|
||||
|
||||
## 6. 구현하려면 무엇이 필요한가
|
||||
|
||||
| 계층 | 할 일 |
|
||||
|---|---|
|
||||
| **IdP** | 클라이언트마다 `backchannel.logout.url` 설정 (완료) |
|
||||
| **앱** | `.oidcLogout(oidc -> oidc.backChannel(...))` 활성화 |
|
||||
| **앱** | `OidcSessionRegistry` 를 **공유 저장소**로 (인스턴스가 여럿이므로) |
|
||||
| **네트워크** | IdP → 앱 공개 URL 도달 (이 실험대는 됨, 운영은 확인 필요) |
|
||||
| **oauth2-proxy** | **지원하지 않는다.** 별도 방안이 필요하다 |
|
||||
|
||||
**마지막이 C-1 과 맞물린다** — app1(BFF)은 구현할 수 있지만
|
||||
app2(oauth2-proxy)는 못 한다. **한 SSO 안에서 로그아웃 전파가 앱마다
|
||||
다르게 동작하게 된다.**
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:50 – 14:53 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-current-state.txt`](evidence/c2-backchannel-logout/01-current-state.txt) | 터미널 원문 |
|
||||
| [`02-configure-idp.txt`](evidence/c2-backchannel-logout/02-configure-idp.txt) | 터미널 원문 |
|
||||
| [`03-logout-attempt.txt`](evidence/c2-backchannel-logout/03-logout-attempt.txt) | 터미널 원문 |
|
||||
| [`04-reachability.txt`](evidence/c2-backchannel-logout/04-reachability.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/c2-backchannel-logout/README.md`](evidence/c2-backchannel-logout/README.md).
|
||||
|
||||
## 7. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
# 1. 현재 설정 확인 — 어느 쪽에도 없다
|
||||
kcadm.sh get clients -r keycloak-patterns -q clientId=bff-confidential --fields attributes
|
||||
grep -rn "oidcLogout\|backchannel" bff/src/main/java/
|
||||
curl -s -o /dev/null -w '%{http_code}\n' -X POST https://app1.hyeonworks.com/logout/connect/back-channel/keycloak
|
||||
|
||||
# 2. IdP 쪽 설정 — 점 표기는 안 먹는다. JSON 으로
|
||||
kcadm.sh update clients/<id> -r keycloak-patterns \
|
||||
-s 'attributes={"backchannel.logout.url":"...","backchannel.logout.session.required":"true"}'
|
||||
|
||||
# 3. ★ 살아 있는 세션이 있는지 먼저 확인한다 (realm 을 join 해서)
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak -tAc \
|
||||
"select count(*) from offline_user_session us join realm r on r.id=us.realm_id
|
||||
where r.name='keycloak-patterns' and us.offline_flag='0'"
|
||||
|
||||
# 4. 로그아웃하고 앱 세션을 본다
|
||||
kcadm.sh create users/<user-id>/logout -r keycloak-patterns
|
||||
kubectl -n keycloak-lab exec deploy/redis -- redis-cli dbsize
|
||||
|
||||
# 5. 도달성 확인 — 클러스터 안에서 앱 공개 URL 로
|
||||
kubectl -n keycloak-lab run t --rm -i --restart=Never --image=curlimages/curl:8.11.1 \
|
||||
--command -- curl -s -o /dev/null -w '%{http_code}\n' https://app1.hyeonworks.com/
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 8. 다음에 남기는 것
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| **구현** | `.oidcLogout()` 활성화 + `OidcSessionRegistry` 공유 |
|
||||
| **oauth2-proxy** | 백채널 로그아웃 미지원 — SSO 안에서 앱마다 동작이 갈린다 |
|
||||
| **운영** | IdP → 앱 도달성이 전제다. 안 되면 **조용히 실패한다** |
|
||||
| **B-2 와 연결** | 로그아웃이 지우는 것은 지금도 세 곳 중 하나뿐이다 |
|
||||
@@ -0,0 +1,308 @@
|
||||
# D-1 — 백업이 있다와 복구해봤다는 다르다
|
||||
|
||||
브랜치 `feature/keycloak-d1-backup-restore` ·
|
||||
증거 [`docs/evidence/d1-backup-restore/`](evidence/d1-backup-restore/) ·
|
||||
2026-09-04 16:55–17:05 KST
|
||||
|
||||
선행: [`A-2`](experiment-a2-database-loss.md) · [`A-3`](experiment-a3-database-crash.md)
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| 측정 | 값 |
|
||||
|---|---|
|
||||
| 덤프 크기 / 시간 | **395KB · 1초 미만** (101개 테이블) |
|
||||
| 복구 시간 | **1초** (`15:00:12 → 15:00:13`), **오류 0건** |
|
||||
| 서비스 회복 | **재시작 없이 15초 이내** (`restarts=0`) |
|
||||
| 데이터 일치 | **완전 일치** — realms 2 / clients 15 / users 2 / sessions 3 / authclients 1 |
|
||||
| **RTO** | **41초** (14:59:47 파괴 → 15:00:28 서비스 확인) |
|
||||
| **RPO** | **마지막 덤프 시점** + A-3 의 `synchronous_commit OFF` 손실 |
|
||||
|
||||
**그리고 예상 못 한 것 — 스키마를 통째로 지웠는데 서비스가 `200` 을 계속 냈다.**
|
||||
|
||||
---
|
||||
|
||||
## 1. 백업
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- pg_dump -U keycloak -d keycloak \
|
||||
--clean --if-exists > /tmp/keycloak-backup.sql
|
||||
```
|
||||
|
||||
```
|
||||
크기: 394945 bytes (6956 줄)
|
||||
CREATE TABLE: 101 개
|
||||
offline_user_session 언급: 13
|
||||
```
|
||||
|
||||
**세션도 덤프에 들어간다.**
|
||||
|
||||
```
|
||||
COPY public.offline_user_session (user_session_id, user_id, realm_id, created_on, offline_flag, data, ...)
|
||||
E1q5xI7tt4U_WhZpW7rEPIF2 48b37d33-... 7845f394-... 1788500836 0 {"ipAddr...
|
||||
```
|
||||
|
||||
| 옵션 | 뜻 |
|
||||
|---|---|
|
||||
| `--clean` | 복구 시 기존 객체를 **DROP 하고** 다시 만든다 |
|
||||
| `--if-exists` | 없는 객체를 DROP 할 때 오류를 내지 않는다 |
|
||||
|
||||
**두 옵션이 없으면 "이미 존재한다" 오류가 쏟아진다.**
|
||||
|
||||
---
|
||||
|
||||
## 2. 파괴
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak \
|
||||
-c "DROP SCHEMA public CASCADE; CREATE SCHEMA public;"
|
||||
```
|
||||
|
||||
```
|
||||
DROP SCHEMA
|
||||
CREATE SCHEMA
|
||||
남은 테이블: 0
|
||||
```
|
||||
|
||||
### ★ 그런데 서비스가 살아 있었다
|
||||
|
||||
```
|
||||
https://auth.hyeonworks.com/realms/master HTTP 200
|
||||
https://app1.hyeonworks.com/ HTTP 200
|
||||
keycloak-0 / keycloak-1 1/1 Running
|
||||
```
|
||||
|
||||
**데이터베이스가 통째로 비었는데 `200` 이다.**
|
||||
|
||||
Keycloak 이 realm 정보를 **Infinispan `realms` 캐시**에서 서빙하기 때문이다
|
||||
(A-0 에서 그 캐시에 57개 엔트리가 있는 것을 봤다).
|
||||
|
||||
### 무엇이 깨지고 무엇이 안 깨지는가
|
||||
|
||||
```
|
||||
/protocol/openid-connect/certs HTTP 200 ← realm 키는 캐시에 있다
|
||||
/.well-known/openid-configuration HTTP 500 ← 이건 DB 를 본다
|
||||
토큰 발급 HTTP 400
|
||||
```
|
||||
|
||||
**부분적으로만 깨진다.** 헬스체크는 통과하고, 일부 엔드포인트는 정상이며,
|
||||
**로그인만 안 된다.**
|
||||
|
||||
```
|
||||
KEYCLOAK_JDBC_PING2: Failed to fetch the cluster members from the database
|
||||
```
|
||||
|
||||
> **A-2(DB 프로세스 정지)와 다른 모양이다.** 거기서는 커넥션이 아예 안 돼
|
||||
> readiness 가 DOWN 이 되고 전 파드가 Service 에서 빠졌다.
|
||||
> **여기서는 커넥션은 되고 테이블만 없다** — 헬스체크가 통과해버린다.
|
||||
>
|
||||
> **"DB 가 살아 있다"와 "데이터가 있다"는 다르다.** 헬스체크는 앞의 것만 본다.
|
||||
|
||||
---
|
||||
|
||||
## 3. 복구
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec -i deploy/postgres -- psql -U keycloak -d keycloak \
|
||||
< /tmp/keycloak-backup.sql
|
||||
```
|
||||
|
||||
```
|
||||
시작: 15:00:12
|
||||
완료: 15:00:13
|
||||
오류 줄: 0
|
||||
```
|
||||
|
||||
**1초, 오류 없음.**
|
||||
|
||||
```
|
||||
복구 후: realms 2 | clients 15 | users 2 | sessions 3 | authclients 1
|
||||
백업 시: realms 2 | clients 15 | users 2 | sessions 3 | authclients 1
|
||||
```
|
||||
|
||||
**완전히 일치한다.**
|
||||
|
||||
### 서비스는 재시작 없이 돌아왔다
|
||||
|
||||
```
|
||||
+15초 well-known=200 토큰발급=200
|
||||
→ 재시작 없이 회복
|
||||
|
||||
keycloak-0 restarts=0
|
||||
keycloak-1 restarts=0
|
||||
```
|
||||
|
||||
**커넥션 풀이 이미 붙어 있었으므로 테이블이 돌아오자마자 동작했다.**
|
||||
A-2 에서 본 것과 같은 자가 회복이다.
|
||||
|
||||
### 세션도 살아났다
|
||||
|
||||
```
|
||||
user_session_id | realm
|
||||
--------------------------+-------------------
|
||||
E1q5xI7tt4U_WhZpW7rEPIF2 | master
|
||||
2ap3DyRiBF8OdMiqCodsJ0mp | master
|
||||
Zsk4QcgXf_qgyMKzde5AG-Fz | master
|
||||
vsDgCVo12-qX0CC63ZmYzbYF | keycloak-patterns
|
||||
```
|
||||
|
||||
**`persistent-user-sessions` 덕분에 세션이 백업 대상이 된다** (A-0).
|
||||
volatile 이었다면 세션은 애초에 DB 에 없으므로 **복구해도 전원 재로그인**이다.
|
||||
|
||||
---
|
||||
|
||||
## 4. RTO 와 RPO
|
||||
|
||||
```
|
||||
14:59:47 파괴
|
||||
15:00:12 복구 시작
|
||||
15:00:13 복구 완료
|
||||
~15:00:28 서비스 정상 확인
|
||||
|
||||
RTO = 41초 (이 규모에서는 대부분이 사람의 판단 시간이다)
|
||||
```
|
||||
|
||||
### RPO 는 두 겹이다
|
||||
|
||||
```
|
||||
① 마지막 덤프 이후의 모든 변경 ← 백업 주기가 정한다
|
||||
② A-3 에서 측정한 synchronous_commit 손실 ← 수백 ms
|
||||
|
||||
실제 RPO = ① + ②
|
||||
```
|
||||
|
||||
**A-3 에서 "153건 중 4건 유실"을 측정한 것이 여기에 더해진다.**
|
||||
백업 주기만 보고 RPO 를 말하면 ②를 빠뜨린다.
|
||||
|
||||
### 이 실험대의 규모는 현실적이지 않다
|
||||
|
||||
| | 이 실험대 | 운영 |
|
||||
|---|---|---|
|
||||
| 덤프 크기 | 395KB | GB~TB |
|
||||
| 복구 시간 | 1초 | 분~시간 |
|
||||
| 세션 수 | 3 | 수만 |
|
||||
|
||||
**복구가 1초인 것은 데이터가 작기 때문**이며, **절차가 맞다는 것만 확인된다.**
|
||||
시간은 규모에 따라 완전히 달라진다.
|
||||
|
||||
---
|
||||
|
||||
## 5. 이 실험이 검증한 것과 못 한 것
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| ✔ 덤프에 필요한 것이 다 들어간다 | realm·client·user·session·authorized client |
|
||||
| ✔ 복구 절차가 동작한다 | `--clean --if-exists` 로 오류 0 |
|
||||
| ✔ 서비스가 자가 회복한다 | 재시작 불필요 |
|
||||
| ✘ **노드가 죽은 경우** | A-4 에서 본 대로 **PVC 가 노드에 묶여 있다.** 노드가 안 돌아오면 덤프가 유일한 길인데, **덤프를 어디에 두느냐**가 문제가 된다 |
|
||||
| ✘ 대규모 복구 시간 | 데이터가 작아 측정 의미가 없다 |
|
||||
| ✘ 백업 자동화·보존·검증 | 이번엔 손으로 한 번 떴다 |
|
||||
|
||||
> **가장 중요한 미검증 항목이 "덤프를 어디에 두는가" 다.**
|
||||
> 이번 덤프는 `test-server:/tmp` 에 있다. **호스트가 죽으면 같이 사라진다.**
|
||||
> A-4 에서 PVC 가 노드에 묶인 것을 봤듯, **백업도 같은 장애 도메인에 있으면
|
||||
> 백업이 아니다.**
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 개념
|
||||
|
||||
### `pg_dump` 의 두 옵션
|
||||
|
||||
| 옵션 | 없으면 |
|
||||
|---|---|
|
||||
| `--clean` | 복구 시 기존 객체와 충돌 |
|
||||
| `--if-exists` | 없는 객체 DROP 에서 오류가 쏟아진다 |
|
||||
|
||||
### "DB 가 살아 있다" 와 "데이터가 있다" 는 다르다
|
||||
|
||||
```
|
||||
A-2 DB 프로세스 정지 → 커넥션 실패 → readiness DOWN → 파드가 Service 에서 빠짐
|
||||
D-1 스키마만 삭제 → 커넥션 정상 → readiness UP → ★ 파드가 그대로 트래픽을 받는다
|
||||
```
|
||||
|
||||
**헬스체크는 커넥션만 본다.** 그래서 빈 데이터베이스를 통과시킨다.
|
||||
그리고 Keycloak 이 realm 캐시로 일부를 계속 서빙해 **부분적으로만 깨진다.**
|
||||
|
||||
### RPO 는 두 겹이다
|
||||
|
||||
```
|
||||
① 마지막 덤프 이후의 변경 ← 백업 주기가 정한다
|
||||
② synchronous_commit OFF 손실 ← A-3 에서 측정한 수백 ms
|
||||
실제 RPO = ① + ②
|
||||
```
|
||||
|
||||
**백업 주기만 보고 RPO 를 말하면 ②를 빠뜨린다.**
|
||||
|
||||
### 백업의 장애 도메인
|
||||
|
||||
이번 덤프는 `test-server:/tmp` 에 있었다. **호스트가 죽으면 같이 사라진다.**
|
||||
A-4 에서 PVC 가 노드에 묶인 것과 같은 문제이며,
|
||||
**같은 장애 도메인에 있는 백업은 백업이 아니다.**
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 14:57 – 14:58 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-backup.txt`](evidence/d1-backup-restore/01-backup.txt) | 터미널 원문 |
|
||||
| [`02-destruction.txt`](evidence/d1-backup-restore/02-destruction.txt) | 터미널 원문 |
|
||||
| [`03-restore.txt`](evidence/d1-backup-restore/03-restore.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/d1-backup-restore/README.md`](evidence/d1-backup-restore/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
# 1. 백업 — --clean --if-exists 가 없으면 복구 때 오류가 쏟아진다
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- pg_dump -U keycloak -d keycloak \
|
||||
--clean --if-exists > keycloak-backup.sql
|
||||
|
||||
# 2. 무엇이 들어갔는지 확인 (세션이 있어야 한다)
|
||||
grep -c '^CREATE TABLE' keycloak-backup.sql
|
||||
grep -A3 'COPY public.offline_user_session' keycloak-backup.sql
|
||||
|
||||
# 3. 파괴
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak \
|
||||
-c "DROP SCHEMA public CASCADE; CREATE SCHEMA public;"
|
||||
|
||||
# 4. ★ 무엇이 깨지는지 확인 — 전부 깨지지 않는다
|
||||
curl -s -o /dev/null -w '%{http_code}\n' https://auth.hyeonworks.com/realms/keycloak-patterns/protocol/openid-connect/certs
|
||||
curl -s -o /dev/null -w '%{http_code}\n' https://auth.hyeonworks.com/realms/keycloak-patterns/.well-known/openid-configuration
|
||||
|
||||
# 5. 복구
|
||||
kubectl -n keycloak-lab exec -i deploy/postgres -- psql -U keycloak -d keycloak < keycloak-backup.sql
|
||||
|
||||
# 6. 데이터 대조 — 백업 시점의 수치와 같아야 한다
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak -tAc \
|
||||
"select (select count(*) from realm), (select count(*) from client),
|
||||
(select count(*) from user_entity),
|
||||
(select count(*) from offline_user_session where offline_flag='0')"
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 7. 다음 실험에 남기는 것
|
||||
|
||||
| 실험 | 이 실험이 준 것 |
|
||||
|---|---|
|
||||
| **D-2** 버전 업그레이드 | **백업이 전제다.** 스키마 마이그레이션은 되돌리기 어렵다 |
|
||||
| 운영 | **덤프를 다른 장애 도메인에 둔다** |
|
||||
| 관측 | **"DB 가 살아 있다"만 보는 헬스체크는 빈 DB 를 통과시킨다** |
|
||||
@@ -0,0 +1,242 @@
|
||||
# D-2 — 버전을 올리고 내릴 때 무엇이 일어나는가
|
||||
|
||||
브랜치 `feature/keycloak-d2-version-upgrade` ·
|
||||
증거 [`docs/evidence/d2-version-upgrade/`](evidence/d2-version-upgrade/) ·
|
||||
2026-09-04 17:05–17:15 KST
|
||||
|
||||
선행: [`D-1`](experiment-d1-backup-restore.md) — **백업이 전제다** ·
|
||||
[`A-8`](experiment-a8-rolling-restart.md) — 롤링 재시작이 안전하다는 것이 전제
|
||||
|
||||
> ## ★ 정정 — 이 문서의 결론은 조건부다
|
||||
>
|
||||
> 이 문서는 *"롤백이 안 된다"* 고 단정했다. 나중에
|
||||
> [`후속 문서`](experiment-followup-untested-items.md) 에서 26.7.0 ↔ 26.7.3 을
|
||||
> 시험하니 **롤백이 성공했다.**
|
||||
>
|
||||
> | 버전 차 | `databasechangelog` | 롤백 |
|
||||
> |---|---|---|
|
||||
> | 26.7.0 → 26.0 | 체크섬 불일치 | **불가** |
|
||||
> | 26.7.0 ↔ 26.7.3 | **210 → 210, 변화 없음** | **가능** |
|
||||
>
|
||||
> **판단 기준은 버전 번호가 아니라 `databasechangelog` 의 행 수가 바뀌었는가다.**
|
||||
> 아래 본문은 스키마가 바뀐 경우에 해당한다.
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| 확인 | 결과 |
|
||||
|---|---|
|
||||
| **롤백이 되는가** | **★ 안 된다.** `liquibase ValidationFailedException: 1 changesets check sum` |
|
||||
| 그때 서비스는 | **★ 살아 있다.** 한 파드가 남아 외부 `200` |
|
||||
| 앞으로 되돌리기 | **된다.** 정상 복구, 데이터 무사 |
|
||||
| 세션 | **유지** (4개 그대로) |
|
||||
|
||||
**"롤백 계획"을 세워두었다면 그 계획은 동작하지 않는다.**
|
||||
대신 **StatefulSet 의 롤링 업데이트가 사고를 절반에서 멈춰줬다.**
|
||||
|
||||
---
|
||||
|
||||
## 1. 전제 — 먼저 백업한다
|
||||
|
||||
D-1 에서 확인한 절차 그대로.
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- pg_dump -U keycloak -d keycloak \
|
||||
--clean --if-exists > /tmp/pre-upgrade.sql
|
||||
```
|
||||
|
||||
```
|
||||
백업: 396333 bytes
|
||||
현재 이미지: quay.io/keycloak/keycloak:26.7.0
|
||||
총 마이그레이션 수: 210
|
||||
현재 세션: 4
|
||||
```
|
||||
|
||||
### 개념 — `databasechangelog`
|
||||
|
||||
Keycloak 은 **Liquibase** 로 스키마를 관리한다. 적용한 변경 하나하나를
|
||||
`databasechangelog` 테이블에 기록한다.
|
||||
|
||||
| 컬럼 | 뜻 |
|
||||
|---|---|
|
||||
| `id` / `author` / `filename` | 변경을 식별 |
|
||||
| **`md5sum`** | **그 변경 정의의 체크섬** |
|
||||
| `orderexecuted` | 적용 순서 |
|
||||
|
||||
**210개가 쌓여 있다.** 이것이 "이 DB 는 어느 버전까지 올라갔는가"의 기록이다.
|
||||
|
||||
---
|
||||
|
||||
## 2. 롤백을 시도했다 — 26.7.0 → 26.0
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab set image statefulset/keycloak keycloak=quay.io/keycloak/keycloak:26.0
|
||||
```
|
||||
|
||||
```
|
||||
+20초 keycloak-0:Running(1/1) keycloak-1:Running(0/1)
|
||||
+80초 keycloak-0:Running(1/1) keycloak-1:Error(0/1)
|
||||
+140초 keycloak-0:Running(1/1) keycloak-1:CrashLoopBackOff(0/1)
|
||||
```
|
||||
|
||||
```
|
||||
ERROR: Failed to start server in (production) mode
|
||||
ERROR: liquibase.exception.ValidationFailedException: Validation Failed:
|
||||
1 changesets check sum
|
||||
```
|
||||
|
||||
### 왜 실패하는가 — 체크섬 불일치
|
||||
|
||||
```
|
||||
26.7.0 이 적용한 변경 → databasechangelog 에 md5sum 기록
|
||||
26.0 이 기동하며 검증 → 자기가 아는 그 변경의 md5sum 과 비교
|
||||
└─ 다르다 → ValidationFailedException
|
||||
```
|
||||
|
||||
**"모르는 변경이 있다" 가 아니라 "아는 변경인데 정의가 다르다" 이다.**
|
||||
같은 changeset 이 버전 사이에 수정된 것이며, **더 엄격한 실패**다.
|
||||
|
||||
> **Liquibase 는 안전을 위해 기동 자체를 거부한다.**
|
||||
> 스키마를 반쯤 아는 상태로 서비스하느니 안 뜨는 쪽을 고른 설계다.
|
||||
|
||||
---
|
||||
|
||||
## 3. 그런데 서비스는 살아 있었다
|
||||
|
||||
```
|
||||
https://auth.hyeonworks.com/realms/master HTTP 200
|
||||
ready 주소: [10.42.1.140] ← 한 파드만
|
||||
statefulset desired/ready/updated: 2 / 1 / 1
|
||||
```
|
||||
|
||||
**StatefulSet 의 롤링 업데이트가 한 번에 하나씩 바꾸기 때문**이다.
|
||||
|
||||
```
|
||||
keycloak-1 을 26.0 으로 → 기동 실패 → Ready 가 안 됨
|
||||
└─ StatefulSet 은 keycloak-0 을 건드리지 않는다
|
||||
└─ keycloak-0 (26.7.0) 이 계속 서비스한다
|
||||
```
|
||||
|
||||
**A-8 에서 "무중단은 replica ≥ 2 와 readiness 의 조합" 이라고 썼는데,
|
||||
여기서는 그 조합이 잘못된 배포를 절반에서 멈춰줬다.**
|
||||
|
||||
| replica 1 이었다면 | |
|
||||
|---|---|
|
||||
| 유일한 파드가 CrashLoopBackOff | **전면 장애** |
|
||||
| 되돌리려면 사람이 개입 | 그동안 계속 다운 |
|
||||
|
||||
---
|
||||
|
||||
## 4. 앞으로 되돌리기
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab set image statefulset/keycloak keycloak=quay.io/keycloak/keycloak:26.7.0
|
||||
```
|
||||
|
||||
```
|
||||
partitioned roll out complete: 2 new pods have been updated...
|
||||
keycloak-0 1/1 Running
|
||||
keycloak-1 1/1 Running 28s
|
||||
|
||||
realms|clients|migrations|sessions = 2|15|210|4
|
||||
외부 진입점 HTTP 200
|
||||
```
|
||||
|
||||
**정상 복구.** 마이그레이션 수도 세션도 그대로다 — **실패한 기동은 스키마를
|
||||
건드리지 못했다.** Liquibase 가 검증 단계에서 멈췄기 때문이다.
|
||||
|
||||
---
|
||||
|
||||
## 5. 그래서 업그레이드 계획은 어떻게 세워야 하는가
|
||||
|
||||
```
|
||||
✘ "문제가 생기면 이미지 태그를 되돌린다"
|
||||
└─ 스키마가 이미 바뀌었으면 옛 버전이 안 뜬다
|
||||
|
||||
✔ "문제가 생기면 백업에서 DB 를 되돌리고 이미지도 되돌린다"
|
||||
└─ D-1 에서 확인한 절차가 여기서 필요하다
|
||||
```
|
||||
|
||||
| 단계 | |
|
||||
|---|---|
|
||||
| 1 | **백업** (D-1) — 이것이 유일한 되돌리기 수단이다 |
|
||||
| 2 | 이미지 태그 변경 |
|
||||
| 3 | **첫 파드만 관찰** — StatefulSet 이 멈춰준다 |
|
||||
| 4 | 실패하면 **이미지를 되돌린다** (스키마가 안 바뀌었으면 이것으로 충분) |
|
||||
| 5 | 스키마가 이미 바뀌었으면 **DB 도 복구**해야 한다 |
|
||||
|
||||
**4와 5를 가르는 것이 "Liquibase 가 검증에서 멈췄는가, 이미 적용했는가" 다.**
|
||||
이번에는 검증에서 멈춰 4로 끝났다.
|
||||
|
||||
---
|
||||
|
||||
## 6. 이 실험이 확인한 것과 못 한 것
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| ✔ 롤백이 안 된다는 것 | 체크섬 불일치로 기동 거부 |
|
||||
| ✔ 실패가 안전하게 격리된다 | StatefulSet + readiness |
|
||||
| ✔ 실패한 기동은 스키마를 안 건드린다 | 마이그레이션 210 그대로 |
|
||||
| ✘ **정방향 업그레이드** | **26.7.0 보다 새 이미지가 없어 시험하지 못했다** |
|
||||
| ✘ 마이그레이션 중 장애 | 스키마 변경 도중 죽으면? |
|
||||
| ✘ 대규모 마이그레이션 시간 | 데이터가 작아 순식간이다 |
|
||||
|
||||
> **정방향을 시험하지 못한 것을 감춰서는 안 된다.**
|
||||
> 다만 **역방향이 더 위험한 방향**이고, 그것이 실패한다는 사실이
|
||||
> "롤백 계획" 을 무효로 만든다는 점에서 실무적으로 더 중요한 결과다.
|
||||
>
|
||||
> 새 버전이 나오면 같은 절차(백업 → 태그 변경 → 첫 파드 관찰)로 반복한다.
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 15:00 – 16:15 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-pre-upgrade.txt`](evidence/d2-version-upgrade/01-pre-upgrade.txt) | 터미널 원문 |
|
||||
| [`02-rollback-attempt.txt`](evidence/d2-version-upgrade/02-rollback-attempt.txt) | 터미널 원문 |
|
||||
| [`03-roll-forward.txt`](evidence/d2-version-upgrade/03-roll-forward.txt) | 터미널 원문 |
|
||||
| [`d2-upgrade-window.png`](evidence/d2-version-upgrade/d2-upgrade-window.png) | 스크린샷 |
|
||||
|
||||
파일별 상세는 [`evidence/d2-version-upgrade/README.md`](evidence/d2-version-upgrade/README.md).
|
||||
|
||||
## 7. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
# 1. 백업 먼저 (D-1)
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- pg_dump -U keycloak -d keycloak \
|
||||
--clean --if-exists > pre-upgrade.sql
|
||||
|
||||
# 2. 현재 마이그레이션 수를 기록
|
||||
kubectl -n keycloak-lab exec deploy/postgres -- psql -U keycloak -d keycloak -tAc \
|
||||
"select count(*) from databasechangelog"
|
||||
|
||||
# 3. 버전 변경
|
||||
kubectl -n keycloak-lab set image statefulset/keycloak keycloak=quay.io/keycloak/keycloak:<tag>
|
||||
|
||||
# 4. ★ 첫 파드만 본다. 실패하면 StatefulSet 이 멈춘다
|
||||
kubectl -n keycloak-lab get pods -w
|
||||
kubectl -n keycloak-lab logs keycloak-1 | grep -iE "liquibase|changeset|validation"
|
||||
|
||||
# 5. 서비스가 살아 있는지 (남은 파드가 받는다)
|
||||
kubectl -n keycloak-lab get endpoints keycloak -o jsonpath='{.subsets[*].addresses[*].ip}'
|
||||
|
||||
# 6. 되돌리기 — 스키마가 안 바뀌었으면 이미지만으로 충분
|
||||
kubectl -n keycloak-lab set image statefulset/keycloak keycloak=quay.io/keycloak/keycloak:26.7.0
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 8. 다음에 남기는 것
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| **D-3** 비밀 관리 | 업그레이드 시 Secret 도 같이 검토된다 |
|
||||
| 운영 | **롤백 = 백업 복구**다. 태그만 되돌리는 계획은 반쪽이다 |
|
||||
| 운영 | **replica ≥ 2** 가 잘못된 배포를 절반에서 멈춘다 |
|
||||
| 미검증 | 정방향 업그레이드, 마이그레이션 중 장애, 대규모 소요 시간 |
|
||||
@@ -0,0 +1,241 @@
|
||||
# D-3 — Secret 은 정말 감춰지는가
|
||||
|
||||
브랜치 `feature/keycloak-d3-secret-management` ·
|
||||
증거 [`docs/evidence/d3-secret-management/`](evidence/d3-secret-management/) ·
|
||||
2026-09-04 17:15–17:25 KST
|
||||
|
||||
---
|
||||
|
||||
## 구조
|
||||
|
||||

|
||||
|
||||
> 다이어그램 규약은 [`diagrams/_style.md`](diagrams/_style.md).
|
||||
> 실험대 전체 구조는 [`diagrams/lab-topology.svg`](diagrams/lab-topology.svg).
|
||||
|
||||
---
|
||||
|
||||
## 0. 결론부터
|
||||
|
||||
| 경로 | 감춰지는가 |
|
||||
|---|---|
|
||||
| `kubectl get secret -o jsonpath \| base64 -d` | **★ 한 줄로 읽힌다** |
|
||||
| `kubectl describe secret` | 값을 숨긴다 — **그래서 안전하다고 착각한다** |
|
||||
| **저장소(at rest)** | **★ 암호화 꺼져 있음.** 저장 파일에 평문이 있다 |
|
||||
| **파드 안** | **★ 평범한 환경변수다** |
|
||||
| RBAC 기본값 | **막는다** — `default` 서비스계정은 못 읽는다 |
|
||||
|
||||
**"Secret 이니까 안전하다" 는 네 가지 중 하나(RBAC)만 맞다.**
|
||||
|
||||
---
|
||||
|
||||
## 1. 한 줄로 읽힌다
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab get secret keycloak-lab-secrets \
|
||||
-o jsonpath='{.data.POSTGRES_PASSWORD}' | base64 -d
|
||||
```
|
||||
|
||||
```
|
||||
keycloak-lab-secrets/POSTGRES_PASSWORD = lab-postgres-change-me
|
||||
keycloak-lab-secrets/KC_BOOTSTRAP_ADMIN_PASSWORD = lab-admin-change-me
|
||||
bff-secrets/KEYCLOAK_CLIENT_SECRET = bff-lab-secret
|
||||
oauth2-proxy-secrets/COOKIE_SECRET_A = lab-cookie-secret-aaaaaaaaaaaaaa
|
||||
```
|
||||
|
||||
**실험대의 모든 비밀이 명령 네 줄로 나온다.**
|
||||
|
||||
### `describe` 는 감춘다 — 그것이 함정이다
|
||||
|
||||
```
|
||||
Type: Opaque
|
||||
|
||||
Data
|
||||
====
|
||||
KEYCLOAK_CLIENT_SECRET: 14 bytes
|
||||
```
|
||||
|
||||
**바이트 수만 보여준다.** 이것만 보면 "가려져 있구나" 싶다.
|
||||
**`get -o jsonpath` 한 번이면 값이 나온다.**
|
||||
|
||||
### 개념 — base64 는 인코딩이지 암호화가 아니다
|
||||
|
||||
| | 목적 | 되돌리기 |
|
||||
|---|---|---|
|
||||
| **인코딩** (base64) | 바이너리를 텍스트로 안전하게 옮기기 | **키 없이 누구나** |
|
||||
| 암호화 | 키 없이는 못 읽게 하기 | 키가 있어야 |
|
||||
|
||||
**Secret 이 base64 를 쓰는 이유는 감추려는 것이 아니라
|
||||
YAML 에 임의 바이트를 담기 위해서다.**
|
||||
|
||||
---
|
||||
|
||||
## 2. 저장소에는 평문으로 있다
|
||||
|
||||
```bash
|
||||
ssh kc-lab-1 'sudo k3s secrets-encrypt status'
|
||||
```
|
||||
|
||||
```
|
||||
Encryption Status: Disabled, no configuration file found
|
||||
```
|
||||
|
||||
**k3s 의 저장소 암호화가 꺼져 있다.** 기본값이다.
|
||||
|
||||
```
|
||||
/var/lib/rancher/k3s/server/db/state.db 13MB
|
||||
/var/lib/rancher/k3s/server/db/state.db-wal 10MB
|
||||
```
|
||||
|
||||
```bash
|
||||
ssh kc-lab-1 'sudo grep -c "lab-postgres-change-me" /var/lib/rancher/k3s/server/db/state.db'
|
||||
```
|
||||
|
||||
```
|
||||
state.db 안의 평문 일치: 2
|
||||
```
|
||||
|
||||
**저장 파일 안에 비밀번호가 그대로 있다.**
|
||||
|
||||
| 그래서 무엇이 위험한가 | |
|
||||
|---|---|
|
||||
| 노드 디스크를 얻으면 | **전 클러스터의 비밀** |
|
||||
| 노드 백업/스냅샷 | 같은 것을 복사한다 |
|
||||
| A-4 에서 본 `local-path` PVC | **같은 디스크에 있다** |
|
||||
|
||||
> **D-1 에서 "덤프를 같은 장애 도메인에 두면 백업이 아니다" 라고 썼는데,
|
||||
> 여기서는 "노드 디스크 하나가 모든 비밀" 이다.**
|
||||
> 백업을 잘 챙겨도 그 백업 안에 비밀이 평문으로 들어간다.
|
||||
|
||||
**k3s 는 `--secrets-encryption` 플래그로 켤 수 있다.** 지금은 안 켜져 있다.
|
||||
|
||||
---
|
||||
|
||||
## 3. 파드 안에서는 환경변수다
|
||||
|
||||
```bash
|
||||
kubectl -n keycloak-lab exec <bff-pod> -- sh -c 'env | grep -iE "secret|password"'
|
||||
```
|
||||
|
||||
```
|
||||
KEYCLOAK_CLIENT_SECRET=bff-lab-secret
|
||||
BFF_DB_PASSWORD=lab-postgres-change-me
|
||||
```
|
||||
|
||||
**`env` 한 번이면 나온다.**
|
||||
|
||||
| 새는 경로 | |
|
||||
|---|---|
|
||||
| `kubectl exec` 권한이 있는 사람 | 바로 본다 |
|
||||
| 같은 파드의 다른 프로세스 | `/proc/<pid>/environ` |
|
||||
| **크래시 덤프 · 오류 리포트** | 환경변수를 함께 담는 도구가 많다 |
|
||||
| 자식 프로세스 | 상속된다 |
|
||||
|
||||
**볼륨으로 마운트하면 이 중 몇 가지가 줄어든다** — 파일 권한으로 제한할 수
|
||||
있고 환경변수 덤프에 안 들어간다.
|
||||
|
||||
```yaml
|
||||
volumeMounts:
|
||||
- name: secrets
|
||||
mountPath: /etc/secrets
|
||||
readOnly: true
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 4. RBAC 은 실제로 막는다
|
||||
|
||||
```bash
|
||||
kubectl auth can-i get secrets -n keycloak-lab \
|
||||
--as=system:serviceaccount:keycloak-lab:default
|
||||
```
|
||||
|
||||
```
|
||||
default SA: no
|
||||
```
|
||||
|
||||
**기본 서비스계정은 Secret 을 못 읽는다.** 쿠버네티스의 기본값이 제한적이다.
|
||||
|
||||
> **네 가지 중 유일하게 제 역할을 하는 것이 RBAC 다.**
|
||||
> 그러므로 "누가 `get secrets` 를 할 수 있는가" 가 실질적인 방어선이며,
|
||||
> **관리자 권한을 가진 사람에게는 아무 방어가 없다.**
|
||||
|
||||
A-0 의 관측 스택에서 `nodes/proxy` 서브리소스를 따로 줘야 했던 것처럼,
|
||||
**Secret 접근도 리소스 단위로 나눌 수 있다.**
|
||||
|
||||
---
|
||||
|
||||
## 5. 그래서 무엇을 해야 하는가
|
||||
|
||||
```
|
||||
지금: 매니페스트에 stringData 평문 → git 에 커밋되면 끝
|
||||
k3s 저장소 암호화 꺼짐
|
||||
파드 환경변수
|
||||
```
|
||||
|
||||
| 단계 | 얻는 것 |
|
||||
|---|---|
|
||||
| ① 매니페스트에서 값을 빼고 **`.example` 만 커밋** | git 유출을 막는다 |
|
||||
| ② **k3s `--secrets-encryption`** 활성화 | 노드 디스크 유출을 막는다 |
|
||||
| ③ 환경변수 대신 **볼륨 마운트** | 프로세스·덤프 유출을 줄인다 |
|
||||
| ④ **SealedSecret / 외부 KMS** | 매니페스트에 암호문만 남는다 |
|
||||
| ⑤ **RBAC 최소화** | 유일하게 이미 동작하는 방어선을 좁힌다 |
|
||||
|
||||
**이 실험대는 ①~④ 중 아무것도 안 하고 있다.** 실험 목적으로는 의도적이지만,
|
||||
**그 사실을 기록해두지 않으면 그대로 운영에 옮겨간다.**
|
||||
|
||||
### 이 실험대의 비밀들은 이미 문서에 있다
|
||||
|
||||
`lab-postgres-change-me`, `bff-lab-secret` 같은 값이 **이 저장소의 매니페스트와
|
||||
문서에 그대로 적혀 있다.** 실험대 전용이며 외부에서 접근할 수 없는 값이지만,
|
||||
**"실험대니까 괜찮다" 가 습관이 되면 위험하다.** 이름에 `change-me` 를 넣은 것이
|
||||
그 최소한의 표시다.
|
||||
|
||||
---
|
||||
|
||||
---
|
||||
|
||||
## 증거 파일
|
||||
|
||||
**증거 수집 시각: 2026-09-04 15:05 – 15:06 KST** (파일 mtime 기준. 문서 상단의 시각 표기는 작성 시점이라 다를 수 있다.)
|
||||
|
||||
| 파일 | 종류 |
|
||||
|---|---|
|
||||
| [`01-base64-not-encryption.txt`](evidence/d3-secret-management/01-base64-not-encryption.txt) | 터미널 원문 |
|
||||
| [`02-at-rest.txt`](evidence/d3-secret-management/02-at-rest.txt) | 터미널 원문 |
|
||||
|
||||
파일별 상세는 [`evidence/d3-secret-management/README.md`](evidence/d3-secret-management/README.md).
|
||||
|
||||
## 6. 재현 절차 (명령어)
|
||||
|
||||
```bash
|
||||
# 1. 한 줄로 읽힌다
|
||||
kubectl -n keycloak-lab get secret keycloak-lab-secrets \
|
||||
-o jsonpath='{.data.POSTGRES_PASSWORD}' | base64 -d
|
||||
|
||||
# 2. describe 는 감춘다 — 대조
|
||||
kubectl -n keycloak-lab describe secret bff-secrets
|
||||
|
||||
# 3. 저장소 암호화 여부
|
||||
ssh kc-lab-1 'sudo k3s secrets-encrypt status'
|
||||
|
||||
# 4. 저장 파일에 평문이 있는가
|
||||
ssh kc-lab-1 'sudo grep -c "lab-postgres-change-me" /var/lib/rancher/k3s/server/db/state.db'
|
||||
|
||||
# 5. 파드 안에서는 환경변수
|
||||
kubectl -n keycloak-lab exec <pod> -- sh -c 'env | grep -i secret'
|
||||
|
||||
# 6. 누가 읽을 수 있는가
|
||||
kubectl auth can-i get secrets -n keycloak-lab \
|
||||
--as=system:serviceaccount:keycloak-lab:default
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 7. 다음에 남기는 것
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| **D-4** 인증서 갱신 | 인증서 개인키도 같은 문제다 |
|
||||
| **B-6** 암호화 key | **key 를 Secret 에 두면 이 실험의 결론이 그대로 적용된다** |
|
||||
| 운영 | **RBAC 이 유일하게 동작하는 방어선이다** |
|
||||