Disabling persistent-user-sessions moves the session from PostgreSQL into the cluster, and the A-1 and A-8 outcomes flip to 400 Session not active while a new login during database loss starts working. The control group in each case still returns 200, so the injections cut only what they were meant to cut. This is the pair that makes the A layer legible: the conventional wisdom that sessions ride TCP 7800 is correct for Keycloak 24 and earlier, and the mistake is applying it to 26 without checking the version. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A-7 — volatile 모드 비교 증거
2026-09-04 13:45–14:15 KST
해설: docs/experiment-a7-volatile-comparison.md
| 파일 | 무엇을 보여주는가 |
|---|---|
01-switch-to-volatile.txt |
--features-disabled=persistent-user-sessions 적용, args 확인 |
02-a0-rerun.txt |
DB 0건인데 교차 노드 refresh 200 — 경로가 DB 에서 클러스터로 바뀌었다 |
03-a8-rerun-restart.txt |
롤링 재시작 후 400 Session not active — persistent 에서는 200 이었다 |
04-a1-rerun-partition.txt |
7800 차단 시 교차 노드 400 — persistent 에서는 200. 대조군(같은 노드)은 200 유지 |
05-a2-rerun-db-loss.txt |
DB 정지 중 새 로그인 200(persistent 에서는 500), refresh 는 500 |
06-restore-persistent.txt |
원복 확인 — args: ["start"], 로그인 후 DB 1건, 외부 200 |
뒤집힌 결과
| 실험 | persistent | volatile |
|---|---|---|
| A-1 7800 차단 후 교차 refresh | 200 |
400 |
| A-8 롤링 재시작 후 refresh | 200 |
400 |
| A-2 DB 정지 중 새 로그인 | 500 |
200 |
같은 주입, 같은 관측, 정반대 결과. A층 전체가 버전 조건부임을 보여주는 대조군이다.