Skip to content

Identity P1.4: Keycloak generator — app access from the People roster #889

Description

@gangster

Part of #884. Strategy §2.4/§2.6. The other half of the single roster: today keycloak-config uses a hardcoded users map, so people would be declared twice.

Scope

  • keycloak-config derives realm users + group membership from gitops/people/ (joined with the role catalog, P1.2) instead of its hardcoded users input.
  • Retire the seed-users; people are declared once (in the roster).
  • Same [must] projection-hardening posture as P1.3 (intent-vs-effected for the emitted Keycloak objects).

Done when: a Person in the roster appears in Keycloak with the right groups/roles; the hardcoded users map is gone; one roster feeds both AWS (P1.3) and apps.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions