Scope
Finish the consumer matrix after dashboard, Kibana, EveBox, and Arkime so no protected hostname remains on the custom forward-auth stack.
Required work
- Implement the chosen OIDC/native or gateway integration for TANNER, Rev·Deck/Ghidra UI, embedded auth/settings surfaces, and every remaining protected router from Phase 0.
- Preserve application-specific paths, APIs, WebSockets/streaming, uploads/downloads, iframe/embed CSP, and logout/deep-link behavior.
- Assign least-privilege Keycloak client roles for each service.
- Prevent direct-network/header spoofing bypasses.
- Remove the old forward-auth middleware only after every route has a passing Keycloak access test.
- Explicitly classify decoy/public honeypot routes that must remain unauthenticated so they are not accidentally gated.
Acceptance criteria
Depends on Phases 0 and 1.
Scope
Finish the consumer matrix after dashboard, Kibana, EveBox, and Arkime so no protected hostname remains on the custom forward-auth stack.
Required work
Acceptance criteria
Depends on Phases 0 and 1.