c0eb1b383b7fcdbfe73906c643c9cda27384b2e1
Working flows:
- Cloudron panel login (Pankow Vue UI: keyboard.type + role=button)
- Gitea SSO via Cloudron OIDC (redirects, auto-consent, authenticated)
- Gitea API token generation (JS-based form fill for hidden elements)
- Token extraction from flash-info message (regex for 40-char hex)
- Token verified via Gitea API (user=vptechops)
- Token stored in Bitwarden as "vp-techops Gitea"
Issues remaining:
- Redmine SSO: OIDC consent completes but redirects back to login page
(likely Redmine OAuth config or user sync issue)
- Discourse: SSO button not found (needs different selector)
- 2FA: enable button not found on Cloudron profile page
(TOTP section exists but button selector needs investigation)
- Gitea: stale token cleanup needed (old duplicate from failed runs)
Key pattern established for Cloudron SSO across all apps:
1. cloudron_panel_login() to establish session
2. sso_login() clicks app-specific SSO button
3. OIDC handles auth automatically (session already active)
4. Redirect back to app authenticated
💘 Generated with Crush
Assisted-by: Crush:glm-5.2
Agent Identity Provisioning
Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage.
Overview
Each AI agent (VP TechOps, VP SecOps, etc.) gets:
- A dedicated Cloudron user (identity root — SSO provisions everywhere)
- TOTP 2FA enrolled and stored in Bitwarden
- API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden)
- All credentials owned by the agent, sourced via
bw-run.sh(no~/.creds/files)
See ~/Q3/agent-identity-bootstrap.md for the full architecture.
Usage
# 1. Create the manifest from the example
cp agents.yaml.example agents.yaml
# Edit: add Cloudron invite links for each agent
# 2. Set BW credentials
export BW_CLIENTID="..."
export BW_CLIENTSECRET="..."
# 3. Build and run
docker compose up --build
# Or run a single agent
docker compose run --rm provision --agent vp-techops
Manifest format
See agents.yaml.example. Each agent defines:
- Cloudron invite link
- Display name
- Priority (Q3 vs Q4)
- System scopes (Redmine projects, Gitea orgs, Discourse categories)
Description
Playwright-based automation for provisioning AI agent identities (Cloudron enrollment, SSO login, API key generation, Bitwarden storage)
274 KiB
Languages
Python
88.4%
Shell
10%
Makefile
0.9%
Dockerfile
0.7%