Disabling persistent-user-sessions moves the session from PostgreSQL into the cluster, and the A-1 and A-8 outcomes flip to 400 Session not active while a new login during database loss starts working. The control group in each case still returns 200, so the injections cut only what they were meant to cut. This is the pair that makes the A layer legible: the conventional wisdom that sessions ride TCP 7800 is correct for Keycloak 24 and earlier, and the mistake is applying it to 26 without checking the version. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
16 lines
479 B
Plaintext
16 lines
479 B
Plaintext
keycloak-0=10.42.1.94 keycloak-1=10.42.0.45
|
|
|
|
=== [A-0 재실행] keycloak-0 에만 로그인 5회 → 캐시가 어디에 담기는가 ===
|
|
로그인완료
|
|
keycloak-0 sessions 캐시 5.0 건
|
|
keycloak-1 sessions 캐시 0.0 건
|
|
|
|
=== DB 에는 들어갔는가 (persistent 였을 때는 5건이 들어갔다) ===
|
|
offline_flag | count
|
|
--------------+-------
|
|
(0 rows)
|
|
|
|
|
|
=== 교차 노드 세션은 되는가 ===
|
|
keycloak-0 로그인 → keycloak-1 에서 refresh HTTP 200
|