Rebuild auth on Keycloak OIDC, fix rootless Ansible deploy
Replaces the single shared HTTP Basic service-account credential (which caused a production outage from a username mismatch) with per-user login: Keycloak (already running on this VM for gcnm, now also fronted on auth.friessn.de with its own "homekeeper" realm) authenticates the user once via the landing page, FastAPI verifies the OIDC id_token and mints its own signed session JWT as a cookie, and both Shiny apps forward that per-session token as a Bearer credential instead of a static shared one. Authorization is a simple ALLOWED_USERS allowlist; the old auth.users table and bcrypt seeding are gone entirely. Also carries forward the in-progress rootless Podman/Quadlet migration (gitea, homekeeper, podman roles) and fixes a pre-existing bug where each role's handlers were malformed inside tasks/main.yml instead of their own handlers/main.yml, which broke ansible-playbook entirely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FbiCdckkTX2HyAkyi1R39d
This commit is contained in:
+1
-15
@@ -21,20 +21,8 @@ def get_session():
|
||||
|
||||
|
||||
def init_db():
|
||||
"""Create schemas and tables, then seed initial users."""
|
||||
from app.auth import seed_users
|
||||
|
||||
"""Create schemas and tables."""
|
||||
with engine.connect() as conn:
|
||||
# Create auth schema and users table
|
||||
conn.execute(text("CREATE SCHEMA IF NOT EXISTS auth"))
|
||||
conn.execute(text("""
|
||||
CREATE TABLE IF NOT EXISTS auth.users (
|
||||
id SERIAL PRIMARY KEY,
|
||||
username TEXT NOT NULL UNIQUE,
|
||||
hashed_password TEXT NOT NULL
|
||||
)
|
||||
"""))
|
||||
|
||||
# Create lk schema and tables
|
||||
conn.execute(text("CREATE SCHEMA IF NOT EXISTS lk"))
|
||||
conn.execute(text("""
|
||||
@@ -239,5 +227,3 @@ def init_db():
|
||||
pass
|
||||
|
||||
conn.commit()
|
||||
|
||||
seed_users()
|
||||
|
||||
Reference in New Issue
Block a user