mrcharles
|
5b6baa7ff7
|
SKILL: fleet-proven procedure — per-app SSO scripts, admin key minting, access restrictions, vault fallbacks
Absorbs the 2026-09-09 fleet-wide rollout learnings: per-app SSO entry
points and quirks (discourse /auth/oidc + CSRF + confirm, redmine
oauth_provider=1, gitea username normalization), Cloudron app
accessRestriction management, central admin-lever key minting for
gitea/redmine/discourse (GLPI deferred on #947), and the
setfield-verify-recreate seed-storage pattern.
https://projects.knownelement.com/issues/942
|
2026-09-09 15:02:25 -05:00 |
|
TSYS Group COO
|
bde7845490
|
skills: agent-provisioning - codified identity stand-up workflow
Policy rulings (#942): unique passwords, Cloudron-only SSO accounts,
no reachableceo credentials, TOTP seeds MUST be captured to the vault.
Cloudron admin API wrapper, cookie-jar OIDC login, RFC-6238-tested
TOTP helper, per-system SSO/API references, incident log.
|
2026-09-08 04:07:14 -05:00 |
|