vptechops 1b8bd843d9 fix: get_totp exact-name resolution + all-agent login validator
bw's name search is fuzzy: every agent email contains "coo"
(tsgstaff-coo-*), so `bw get totp "coo Cloudron"` matched 10 items and
errored. get_totp now resolves via get_item_id (exact-name filter)
first, mirroring get_item_password.

Added validate-all-logins.py: per-agent fresh-browser-context login
(shared contexts carry session cookies and hide the login form),
asserts password+TOTP round-trip, then verifies every stored API
credential against its system. First full run: 9/10 PASS.

Known failure: vp-compliance stored password does not match the
account ("Incorrect username or password" pre-TOTP) -- enrollment
typed a different value than stored. Needs Cloudron admin reset,
then update_item and re-validate.
2026-08-14 11:48:06 -05:00

Agent Identity Provisioning

Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage.

Overview

Each AI agent (VP TechOps, VP SecOps, etc.) gets:

  1. A dedicated Cloudron user (identity root — SSO provisions everywhere)
  2. TOTP 2FA enrolled and stored in Bitwarden
  3. API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden)
  4. All credentials owned by the agent, sourced via bw-run.sh (no ~/.creds/ files)

See ~/Q3/agent-identity-bootstrap.md for the full architecture.

Usage

# 1. Create the manifest from the example
cp agents.yaml.example agents.yaml
# Edit: add Cloudron invite links for each agent

# 2. Set BW credentials
export BW_CLIENTID="..."
export BW_CLIENTSECRET="..."

# 3. Build and run
docker compose up --build

# Or run a single agent
docker compose run --rm provision --agent vp-techops

Manifest format

See agents.yaml.example. Each agent defines:

  • Cloudron invite link
  • Display name
  • Priority (Q3 vs Q4)
  • System scopes (Redmine projects, Gitea orgs, Discourse categories)
S
Description
Playwright-based automation for provisioning AI agent identities (Cloudron enrollment, SSO login, API key generation, Bitwarden storage)
Readme
274 KiB
Languages
Python 88.4%
Shell 10%
Makefile 0.9%
Dockerfile 0.7%