Skip to content

feat: Knotree Accounts-only sign-in; Registry for the signed-in account via internal API - #10

Merged
vantanminh merged 2 commits into
mainfrom
feat/sso-only-internal-registry
Oct 3, 2026
Merged

vantanminh merged 2 commits into
mainfrom
feat/sso-only-internal-registry

Conversation

@vantanminh

Copy link
Copy Markdown
Owner

One Knotree account across services (decision 0012, IN-048). This supersedes DEC-0011.

Sign-in (US-049)

  • /auth/register and /auth/login are removed. /login and /register now only lead to Knotree Accounts; /auth/sso/start?intent=signup adds screen_hint=signup. SSO is required in production.
  • Users are keyed by Knotree sub. Email, name and preferred_username refresh on every sign-in.
  • users.email is no longer unique, since emails can move between Knotree accounts. SSO_ACCOUNT_LINK_REQUIRED is gone.
  • Migration 0023:
    • revokes the sessions of password-only users (their data is kept);
    • adds owner_issuer/owner_subject to knotree_registry_connections and backfills them from accounts and SSO identities;
    • clears the in-flight consent attempts.

Registry (US-050)

  • Picker, import (from-account) and pull credentials call Registry's cluster-only API (registry-internal:8081).
    • Authentication is a projected ServiceAccount token: audience knotree-registry-internal, 10 minutes, rotated by the kubelet.
    • The calls name the signed-in account. Registry only serves that account's namespace.
  • Pull credentials are per repository and pull-only, valid for 90 days. Cloud renews them when fewer than 30 days remain, before every deploy and every 6 hours, and rewrites the services' pull Secrets.
  • tag_updated deploys only when the event owner matches the connection owner.
  • Removed:
    • the consent flow (registry_consent.rs, /auth/knotree-registry/callback, account authorize/disconnect);
    • manual token connections and token rotation;
    • the web Connect, Reconnect and Disconnect buttons and the token fields.
  • The Integrations card now only shows the linked namespace.
  • grant_revoked handling stays for credentials from the retired flow. Its tables are dropped in a follow-up.
  • Helm adds knotreeRegistry.internal (projected token volume and KNOTREE_REGISTRY_INTERNAL_ORIGIN). No new GitHub config keys.

Depends on

  • vantanminh/knotree-registry#6 (internal API) must be deployed first.
  • vantanminh/knotree-auth#10 is needed for screen_hint=signup and preferred_username. Without it, sign-up falls back to sign-in.

Tests

  • New API tests:
    • registry_accounts: production trusts only the internal Service; links and renews only the account's own repositories against a fake Registry.
    • sso: no linking by email; email and username refresh by sub.
  • Locally cargo test passes except 2 html_pages tests, which fail the same way on main on Windows.
  • Web: tsc is clean. The vitest suites pass except the long AuthPage flow, which hits the 5s timeout under full-suite load. It passes alone (4.8s) and on CI.
  • helm lint and helm template are fine.

🤖 Generated with Claude Code

vantanminh and others added 2 commits October 3, 2026 22:40
…Cloud

- remove password register/login; /login and /register lead to Knotree
  Accounts (intent=signup -> screen_hint=signup); SSO is required in production
- users are keyed by Knotree sub; email, name and username refresh at sign-in;
  users.email is no longer unique; sessions of password-only users are revoked
- Registry picker, import and pull credentials go through Registry's internal
  API with a projected ServiceAccount token, acting for the signed-in account
- per-repository pull credentials renewed before deploys and every 6 hours;
  auto-deploy routes on the connection owner's sub
- remove consent, manual token connections and token rotation UI; the
  Integrations card shows the linked namespace only
- Helm: projected token volume (audience knotree-registry-internal)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant