From 39916b26e9c8e1474158271cf0c61d3aed984374 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 03:13:11 +0200 Subject: [PATCH] What stands between 3.1 and a running identity provider is a program MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 023 is fixed, so the design faults are gone and one concrete thing is left: the realm provisioner does not exist. Its manifest named an image nothing builds and no program backs, which has been removed — a manifest describing a program nobody wrote is the same mistake as the credential files that could never be read. Keycloak's manifest now says what is true today, and the gap is loud: it no longer claims to provide oidc-client, so a consumer asking for one is refused by name at plan time instead of resolving cleanly and waiting for a client nothing will create. The provisioner should be written against a real Keycloak in the lab rather than from the API documentation. The object store's took three corrections that only a running server produced. --- 03-DESIGN/01-to-be/00-work-breakdown.md | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/03-DESIGN/01-to-be/00-work-breakdown.md b/03-DESIGN/01-to-be/00-work-breakdown.md index 94242a4..a8e5e88 100644 --- a/03-DESIGN/01-to-be/00-work-breakdown.md +++ b/03-DESIGN/01-to-be/00-work-breakdown.md @@ -281,7 +281,27 @@ path named `.env` and read it as one, when a sealed file holds a password and no parsed and resolved and could never have worked, which is what a manifest checked only by a parser buys. Two tests now refuse both halves of it. -**023 is the whole of what remains before 3.1 runs.** +### 3.1 needs a program, not a decision — *2026-09-01* + +023 is fixed, and with it the two design faults are gone. What stands between 3.1 and a running +identity provider is now one concrete thing: **the realm provisioner does not exist.** + +Its manifest named an image — `mesh-provision-keycloak` — that nothing builds and no program +backs. That has been removed rather than left standing, because a manifest describing a program +nobody wrote is the same mistake as the credential files that could never be read: it parses, it +resolves, and it could never work. + +So Keycloak's manifest now says what is true today — a server the mesh runs, with its database +and its admin credential, both reaching it in a shape it can read. It no longer claims to provide +`oidc-client`, which means a consumer asking for one is **refused by name at plan time** rather +than resolving cleanly and waiting for a client nothing will create. + +The provisioner is the same shape as the two that exist: it reads what the mesh granted and +reconciles a realm and a client per consumer. **It should be written against a real Keycloak in +the lab**, not from the API documentation — the object store's took three corrections that only a +running server produced. + +The forge (3.2) and the mail system (3.3) need no provisioner and are not blocked on this. ## The conversion is done by hand, and that is a decision