Repository navigation
feat: Knotree Accounts-only sign-in; Registry for the signed-in account via internal API - #10
Merged
Merged
Conversation
…Cloud - remove password register/login; /login and /register lead to Knotree Accounts (intent=signup -> screen_hint=signup); SSO is required in production - users are keyed by Knotree sub; email, name and username refresh at sign-in; users.email is no longer unique; sessions of password-only users are revoked - Registry picker, import and pull credentials go through Registry's internal API with a projected ServiceAccount token, acting for the signed-in account - per-repository pull credentials renewed before deploys and every 6 hours; auto-deploy routes on the connection owner's sub - remove consent, manual token connections and token rotation UI; the Integrations card shows the linked namespace only - Helm: projected token volume (audience knotree-registry-internal) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
One Knotree account across services (decision 0012, IN-048). This supersedes DEC-0011.
Sign-in (US-049)
/auth/registerand/auth/loginare removed./loginand/registernow only lead to Knotree Accounts;/auth/sso/start?intent=signupaddsscreen_hint=signup. SSO is required in production.sub. Email, name andpreferred_usernamerefresh on every sign-in.users.emailis no longer unique, since emails can move between Knotree accounts.SSO_ACCOUNT_LINK_REQUIREDis gone.0023:owner_issuer/owner_subjecttoknotree_registry_connectionsand backfills them from accounts and SSO identities;Registry (US-050)
from-account) and pull credentials call Registry's cluster-only API (registry-internal:8081).knotree-registry-internal, 10 minutes, rotated by the kubelet.tag_updateddeploys only when the event owner matches the connection owner.registry_consent.rs,/auth/knotree-registry/callback, account authorize/disconnect);grant_revokedhandling stays for credentials from the retired flow. Its tables are dropped in a follow-up.knotreeRegistry.internal(projected token volume andKNOTREE_REGISTRY_INTERNAL_ORIGIN). No new GitHub config keys.Depends on
vantanminh/knotree-registry#6(internal API) must be deployed first.vantanminh/knotree-auth#10is needed forscreen_hint=signupandpreferred_username. Without it, sign-up falls back to sign-in.Tests
registry_accounts: production trusts only the internal Service; links and renews only the account's own repositories against a fake Registry.sso: no linking by email; email and username refresh bysub.cargo testpasses except 2html_pagestests, which fail the same way onmainon Windows.tscis clean. The vitest suites pass except the longAuthPageflow, which hits the 5s timeout under full-suite load. It passes alone (4.8s) and on CI.helm lintandhelm templateare fine.🤖 Generated with Claude Code