TSYS Group COO c0eb1b383b feat: Gitea SSO + token generation working end-to-end
Working flows:
- Cloudron panel login (Pankow Vue UI: keyboard.type + role=button)
- Gitea SSO via Cloudron OIDC (redirects, auto-consent, authenticated)
- Gitea API token generation (JS-based form fill for hidden elements)
- Token extraction from flash-info message (regex for 40-char hex)
- Token verified via Gitea API (user=vptechops)
- Token stored in Bitwarden as "vp-techops Gitea"

Issues remaining:
- Redmine SSO: OIDC consent completes but redirects back to login page
  (likely Redmine OAuth config or user sync issue)
- Discourse: SSO button not found (needs different selector)
- 2FA: enable button not found on Cloudron profile page
  (TOTP section exists but button selector needs investigation)
- Gitea: stale token cleanup needed (old duplicate from failed runs)

Key pattern established for Cloudron SSO across all apps:
  1. cloudron_panel_login() to establish session
  2. sso_login() clicks app-specific SSO button
  3. OIDC handles auth automatically (session already active)
  4. Redirect back to app authenticated

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-13 18:37:20 -05:00

Agent Identity Provisioning

Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage.

Overview

Each AI agent (VP TechOps, VP SecOps, etc.) gets:

  1. A dedicated Cloudron user (identity root — SSO provisions everywhere)
  2. TOTP 2FA enrolled and stored in Bitwarden
  3. API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden)
  4. All credentials owned by the agent, sourced via bw-run.sh (no ~/.creds/ files)

See ~/Q3/agent-identity-bootstrap.md for the full architecture.

Usage

# 1. Create the manifest from the example
cp agents.yaml.example agents.yaml
# Edit: add Cloudron invite links for each agent

# 2. Set BW credentials
export BW_CLIENTID="..."
export BW_CLIENTSECRET="..."

# 3. Build and run
docker compose up --build

# Or run a single agent
docker compose run --rm provision --agent vp-techops

Manifest format

See agents.yaml.example. Each agent defines:

  • Cloudron invite link
  • Display name
  • Priority (Q3 vs Q4)
  • System scopes (Redmine projects, Gitea orgs, Discourse categories)
S
Description
Playwright-based automation for provisioning AI agent identities (Cloudron enrollment, SSO login, API key generation, Bitwarden storage)
Readme
274 KiB
Languages
Python 88.4%
Shell 10%
Makefile 0.9%
Dockerfile 0.7%