Skip to content

feat(auth): add configurable CL Admin roster bootstrap - #154

Open
justin-hollick wants to merge 26 commits into
mainfrom
feat/bootstrap-cl-admin-roster
Open

feat(auth): add configurable CL Admin roster bootstrap#154
justin-hollick wants to merge 26 commits into
mainfrom
feat/bootstrap-cl-admin-roster

Conversation

@justin-hollick

Copy link
Copy Markdown
Contributor
  • Replaced the single-email bootstrap with INITIAL_CL_ADMIN_EMAILS, a validated JSON roster.
  • Added an explicit, transactional, idempotent packaged command for creating eligible CL Admin identities and assignments.
  • Preserved OIDC safety: first verified sign-in binds the IdP provider/subject pair; bootstrap never infers identity claims.
  • Added make bootstrap-cl-admin for non-destructive local execution after migrations.
  • Added focused configuration, conflict, rollback, command, and image-availability tests.
  • Documented the deferred post-migration pipeline contract and safe handling of roster identity data.

kevanadlard and others added 25 commits July 28, 2026 19:36
…h local tooling, OIDC-safe identity binding, tests, and a deferred pipeline execution contract.
Base automatically changed from release/MVP2 to main August 28, 2026 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants