2d01a9f9626eddb0b0c1a6f0c3a94d30cfb8ae2a
Discourse SSO flow: Cloudron login -> click "Log In" -> click OpenID Connect button -> complete signup (enter username) -> logged in. User API key generated via Discourse RSA-based flow: 1. Generate RSA keypair, submit public key 2. Authorize request on Discourse 3. Capture encrypted payload from POST response 4. Decrypt with PKCS1v15 padding (Discourse uses this, not OAEP) 5. Parse JSON to extract the key field API key verified working: User-Api-Key header returns 30 topics from /latest.json. Key stored in Bitwarden as "vp-techops Discourse". Redmine SSO is blocked: Cloudron returns "You do not have access" -- the vp-techops user needs app access granted by Cloudron admin. Also added cryptography==44.0.1 to requirements for RSA operations.
Agent Identity Provisioning
Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage.
Overview
Each AI agent (VP TechOps, VP SecOps, etc.) gets:
- A dedicated Cloudron user (identity root — SSO provisions everywhere)
- TOTP 2FA enrolled and stored in Bitwarden
- API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden)
- All credentials owned by the agent, sourced via
bw-run.sh(no~/.creds/files)
See ~/Q3/agent-identity-bootstrap.md for the full architecture.
Usage
# 1. Create the manifest from the example
cp agents.yaml.example agents.yaml
# Edit: add Cloudron invite links for each agent
# 2. Set BW credentials
export BW_CLIENTID="..."
export BW_CLIENTSECRET="..."
# 3. Build and run
docker compose up --build
# Or run a single agent
docker compose run --rm provision --agent vp-techops
Manifest format
See agents.yaml.example. Each agent defines:
- Cloudron invite link
- Display name
- Priority (Q3 vs Q4)
- System scopes (Redmine projects, Gitea orgs, Discourse categories)
Description
Playwright-based automation for provisioning AI agent identities (Cloudron enrollment, SSO login, API key generation, Bitwarden storage)
274 KiB
Languages
Python
88.4%
Shell
10%
Makefile
0.9%
Dockerfile
0.7%