Files
keycloak-pattern/docs/evidence/followup
DongHyeonkaandClaude Opus 5 98a74e90a5 docs: fill the untested items and record why the B layer has no graphs
The forward upgrade to 26.7.3 was zero downtime across 87 samples, and since databasechangelog stayed at 210 the rollback to 26.7.0 also succeeded, which narrows D-2's conclusion: rolling back fails when the schema moved, not because of the version number. The row count is the check.

Role changes never reach the upstream through request repetition; the session is a snapshot taken at login and only a new session picks up the new claim. Auditing the docs also surfaced that Prometheus scrapes only keycloak, kubelet, node-exporter and itself, so the B-layer experiments have no metrics to screenshot rather than missing screenshots.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-04 16:18:33 +09:00
..

후속 — 미측정으로 남겼던 항목을 채운 기록

2026-09-04 17:3518:20 KST 해설: docs/experiment-followup-untested-items.md

파일 무엇을 보여주는가
01-d2-forward-upgrade.txt D-2 정방향 26.7.0 → 26.7.3. 백업 396KB · 87회 요청 전부 200(무중단) · 마이그레이션 210 → 210(스키마 변경 없음) · 세션 3 유지 · Infinispan 16.0.12 → 16.0.14
02-d2-rollback-same-schema.txt 스키마가 안 바뀌면 롤백이 된다 — 26.7.3 → 26.7.0 성공. 다만 전환 순간 000 1회(3초 타임아웃)
03-b4-role-propagation.txt B-4 ③ IdP 에서 값을 바꿔도 12회 요청·6초 동안 옛 값. 세션 삭제 후 재인증에서야 새 값
04-observability-gap.txt B층에 관측이 없다 — Prometheus 는 keycloak·kubelet·node-exporter·prometheus 만 긁는다. Redis·BFF·PostgreSQL 지표가 0개

핵심 세 줄

  1. "롤백은 안 된다" 는 조건부였다. 스키마가 바뀌었으면 안 되고, 안 바뀌었으면 된다 — D-2 의 결론을 정밀화한다.
  2. role 변경은 요청 횟수와 무관하게 반영되지 않는다. --cookie-refresh 가 없으면 쿠키 만료나 재인증까지 옛 값이 간다.
  3. B층 실험에 Grafana 증거가 없는 이유가 확인됐다 — 관측 대상에 애초에 없다. 스크린샷이 없는 것이 아니라 지표가 없다.