docs(dev-sso): add three-repo dev-sso runbook + design rationale #23
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs/dev-sso-runbook"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Document how the Traefik-routed dev SSO stack works across bunyip, mokosh-server, and mokosh-apps: the DNS-to-dev-01 vs run-on-desktop-02-over-Nebula topology, the two Traefik entrypoints (web-secure LAN vs nebula-secure mesh), the design rationale (per-developer hostnames, why the OIDC client is registered once and its PKCE purpose, external network + recipe pre-create, list-syntax labels for the ${USER} interpolation bug, HOST_UID/HOST_GID bind-mount perms, on-disk OIDC keys, the transitional dual-issuer wiring), the ordered spin-up procedure, Mac client-side access (/etc/hosts + Chrome DoH + Mailpit tunnel), and every obstacle hit with root cause and fix. Link it from CLAUDE.md.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Document how the Traefik-routed dev SSO stack works across bunyip, mokosh-server, and mokosh-apps: the DNS-to-dev-01 vs run-on-desktop-02-over-Nebula topology, the two Traefik entrypoints (web-secure LAN vs nebula-secure mesh), the design rationale (per-developer hostnames, why the OIDC client is registered once and its PKCE purpose, external network + recipe pre-create, list-syntax labels for the ${USER} interpolation bug, HOST_UID/HOST_GID bind-mount perms, on-disk OIDC keys, the transitional dual-issuer wiring), the ordered spin-up procedure, Mac client-side access (/etc/hosts + Chrome DoH + Mailpit tunnel), and every obstacle hit with root cause and fix. Link it from CLAUDE.md. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>