Establishes a hard auth gate before any app is packaged: OIDC is
preferred, LDAP is acceptable (flagged risk), auth-proxy for user-less
utility apps, and local-only-auth apps are blocked from packaging
until they gain SSO.
- AGENTS.md: new "Authentication Policy" section with the verdict table
and Cloudron OIDC/LDAP/proxy-auth wiring notes.
- STATUS.md: new "Auth Status" matrix assessing all 7 completed
packages + the next candidates (draw.io proxy-eligible, Windmill
OIDC, NetBox OIDC but Redis-blocked, Gophish blocked-on-auth).
Flags tech debt: Webhook/WireViz need httpAuth proxy added; Puter
auth needs revisit.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
Mirror the agent workflow used across sibling TSYS/KNEL repos
(PFVCluster, KNEL-AIMiddleware): a living agent-maintained STATUS.md
plus a concise AGENTS.md carrying Git Policy and an Automatic Gardening
Protocol that keeps all docs in sync.
- Add STATUS.md: completed packages table (7), per-category progress,
known issues, next priorities, repo summary. Human read-only; agents
own it.
- Rewrite AGENTS.md (384 -> 140 lines): repo layout, git policy
(atomic, conventional, commit+push without prompting), gardening
protocol, packaging quick-reference. Fixes active model (GLM-4.7 ->
GLM-5.2), stale counts, and dead /home/tsys paths.
💘 Generated with Crush
Assisted-by: Crush:glm-5.2