Seen from ace on 2026-09-30 while grafana bound oidc-client (catalogue 1eb8fa36, #155).
mesh-keycloak fails every call with Keycloak token request failed: 401 {"error":"invalid_grant","error_description":"Invalid user credentials"} — both its runtime tools (keycloak_list_realms) and the new oidc-client provisioner (mesh_ace_grafana: create failed, will retry). Keycloak logs a LOGIN_ERROR for admin-cli on realm master every 5 s.
Cause: the manifest renders KEYCLOAK_ADMIN_PASSWORD from the minted admin own-secret and the sidecar reads the same file, but keycloak applies that variable only when it creates the master realm. mesh_novox_keycloak was adopted with its database; its master-realm admin user dates from 2022-01-14, so the real password predates the mesh and the minted one is inert. Not new today — visible since keycloak moved to the mesh.
Effect on consumers: mesh_ace_grafana's client is never created; grafana's SSO redirect (client_id=mesh_ace_grafana) fails at keycloak.
This is novox's module to settle (accept the real admin as the admin own-secret, or make keycloak's admin match the minted value). Related: the issuer setting {"issuer":"https://keycloak.novox.be/realms/Novox"} was set on novox's assignment from ace's session for #155; novox may want to own that too. See also #227 (resolver).
Seen from ace on 2026-09-30 while grafana bound `oidc-client` (catalogue 1eb8fa36, #155).
- `mesh-keycloak` fails every call with `Keycloak token request failed: 401 {"error":"invalid_grant","error_description":"Invalid user credentials"}` — both its runtime tools (`keycloak_list_realms`) and the new oidc-client provisioner (`mesh_ace_grafana: create failed, will retry`). Keycloak logs a `LOGIN_ERROR` for `admin-cli` on realm `master` every 5 s.
- Cause: the manifest renders `KEYCLOAK_ADMIN_PASSWORD` from the minted `admin` own-secret and the sidecar reads the same file, but keycloak applies that variable only when it creates the master realm. `mesh_novox_keycloak` was adopted with its database; its master-realm `admin` user dates from 2022-01-14, so the real password predates the mesh and the minted one is inert. Not new today — visible since keycloak moved to the mesh.
- Effect on consumers: `mesh_ace_grafana`'s client is never created; grafana's SSO redirect (`client_id=mesh_ace_grafana`) fails at keycloak.
This is novox's module to settle (accept the real admin as the `admin` own-secret, or make keycloak's admin match the minted value). Related: the issuer setting `{"issuer":"https://keycloak.novox.be/realms/Novox"}` was set on novox's assignment from ace's session for #155; novox may want to own that too. See also #227 (resolver).
Fixed 2026-10-01 and recorded as hq issue 179 (04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md). The predecessor's configuration is gone, so instead of secret accept with the real password, reality was made to match the mesh: keycloak's own kc.sh bootstrap-admin made a temporary admin, which set admin's password to the value the mesh minted (read from the sidecar's mounted secret on the machine, never printed); the temporary admin was removed. Verified through the console: keycloak_list_realms answers, and mesh_ace_grafana and mesh_ace_carhunt now exist in the realm. SSO for grafana and car-hunter can be retried from ace.
The design question — an own-secret that adopted software will not take — is left open in the record. hq's issues live in 04-ISSUES/; please close this tracker issue (the harness refuses me the close).
Fixed 2026-10-01 and recorded as hq issue 179 (`04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md`). The predecessor's configuration is gone, so instead of `secret accept` with the real password, reality was made to match the mesh: keycloak's own `kc.sh bootstrap-admin` made a temporary admin, which set `admin`'s password to the value the mesh minted (read from the sidecar's mounted secret on the machine, never printed); the temporary admin was removed. Verified through the console: `keycloak_list_realms` answers, and `mesh_ace_grafana` and `mesh_ace_carhunt` now exist in the realm. SSO for grafana and car-hunter can be retried from ace.
The design question — an own-secret that adopted software will not take — is left open in the record. hq's issues live in `04-ISSUES/`; please close this tracker issue (the harness refuses me the close).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Seen from ace on 2026-09-30 while grafana bound
oidc-client(catalogue 1eb8fa36, #155).mesh-keycloakfails every call withKeycloak token request failed: 401 {"error":"invalid_grant","error_description":"Invalid user credentials"}— both its runtime tools (keycloak_list_realms) and the new oidc-client provisioner (mesh_ace_grafana: create failed, will retry). Keycloak logs aLOGIN_ERRORforadmin-clion realmmasterevery 5 s.KEYCLOAK_ADMIN_PASSWORDfrom the mintedadminown-secret and the sidecar reads the same file, but keycloak applies that variable only when it creates the master realm.mesh_novox_keycloakwas adopted with its database; its master-realmadminuser dates from 2022-01-14, so the real password predates the mesh and the minted one is inert. Not new today — visible since keycloak moved to the mesh.mesh_ace_grafana's client is never created; grafana's SSO redirect (client_id=mesh_ace_grafana) fails at keycloak.This is novox's module to settle (accept the real admin as the
adminown-secret, or make keycloak's admin match the minted value). Related: the issuer setting{"issuer":"https://keycloak.novox.be/realms/Novox"}was set on novox's assignment from ace's session for #155; novox may want to own that too. See also #227 (resolver).Fixed 2026-10-01 and recorded as hq issue 179 (
04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md). The predecessor's configuration is gone, so instead ofsecret acceptwith the real password, reality was made to match the mesh: keycloak's ownkc.sh bootstrap-adminmade a temporary admin, which setadmin's password to the value the mesh minted (read from the sidecar's mounted secret on the machine, never printed); the temporary admin was removed. Verified through the console:keycloak_list_realmsanswers, andmesh_ace_grafanaandmesh_ace_carhuntnow exist in the realm. SSO for grafana and car-hunter can be retried from ace.The design question — an own-secret that adopted software will not take — is left open in the record. hq's issues live in
04-ISSUES/; please close this tracker issue (the harness refuses me the close).