| |
|---|
| Document code | SPEC-GSSO-2026 / Report 05 |
| Version | 0.1-draft (EN source, governing) |
| Date | 2026-10-05 |
| Status | Draft |
| Companion reports | 00 RFP · 01 ADR · 02 Requirements · 03 Consumers & contract · 04 Technical documentation |
| Version | Date | Changes |
|---|
| 0.1-draft | 2026-10-05 | Phases S0–S5, MVP, risks, dependencies |
| Consumer milestone | Needs from GSSO | GSSO phase |
|---|
| CRM F0 (foundation) | CAP-GSSO-01: realm gstack, crm-gateway, service clients, locale, UUID sub | S1 |
| CRM F1+ / gDocFlow / gTenders | CAP-GSSO-03, 07 (sessions, token exchange) | S3 |
| gFlow G1 | role → users query, service principals per app | S3 |
| gInsight (deferred) | org_unit claims (CAP-GSSO-04) | S2 |
| Existing apps hardening | Removal of pattern A/C | S4 |
Each phase ends with a gate. Phase S0 cannot start coding until the ADRs in report 01 are Acceptat (DEV-PLAYBOOK §4).
- Create the repository
govtech/gstack/gsso, CLAUDE.md, gsso.jdl and test-scenarios.md, and accept the ADRs.
keycloak/:
- a Dockerfile on 26.6.3;
- baselines
gstack, cetatean and tenant-template through keycloak-config-cli;
- the GDS login theme in RO/RU/EN.
The extensions module is only a skeleton in this phase.
deploy/docker-compose.yml with Keycloak, two PostgreSQL databases and Kafka; docker-compose.test.yml.
- JHipster 9.1.0 generation of
gsso and gsso-gateway; gsso-web skeleton on GDS with the side bar and i18n. Versions are pinned.
- Gate: AC-001 and AC-002 pass locally, the ADRs are accepted, and
/gsast is clean.
- Realms (registry, template creation, switcher, scoping, adoption in dry-run).
- Platforms, clients, roles, bulk service clients and audience mappers.
- Users: list, create/invite, edit, enable/disable, credentials, sessions, unlock, projection.
- Reconciler: outbox jobs, worker, retry, full reconcile, drift
REPORT/ENFORCE, sync screen.
- GSSO’s own append-only events, without Kafka ingestion yet.
- The design screens Realms, Applications, Users (drawer), Roles and Sync.
- Gate: AC-003..009, 026, 027 (partial) and 028 pass. CAP-GSSO-01 is delivered in local and staging.
- Grants: the lifecycle, four-eyes, the inbox, expiry and notifications, bundles, org units and scoped roles.
- The Keycloak
gsso-kafka event listener, the consumer, the hash chain, GLog forwarding, back-fill, and the dashboard (KPIs, logins over 24 h, events, auth mix).
- Authentication policies: the methods screen, conditional MFA by sensitive role, LDAP federation, the MPass mock broker in
cetatean, and branding.
- Revocation publisher and access report.
- Gate: AC-010..019, 024, 025 pass. CAP-GSSO-02 and 04 are delivered.
gsso-spring-boot-starter and @gstack/gsso-angular.
api/v1/app (self-registration, lookups, roles, sessions, grant requests).
- Token-exchange permissions.
- Sample app and onboarding runbook.
- Pilot apps:
- gregistry (pattern B): moves to
gstack and the starter;
- glog: starter and scopes, and GSSO becomes an ingest client;
- the CRM gateway skeleton.
- Gate: AC-020..023 pass, SSO works across gsso-console + gregistry + glog, and CAP-GSSO-03, 06 and 07 are delivered.
- Production takeover of the live Keycloak (report 04 §11.1), with the owner’s approval and a maintenance window.
- Adopt realm
interdictii, then decide Q-GSSO-1.
- Migrate the pattern-A apps (interdictii, gdocs, gnotify) and pattern C (drumuri: staff to
gstack, MPass to cetatean). Then gstorage (realm gstorage → gstack), cancelarie, platform and gportal.
- Retire
ROLE_ADMIN; delete the obsolete realms (gdocs, gnotify, gstorage, ultra) after migration.
- Create
tenant-* realms for the whitelabel sites.
- Gate: AC-030; no app mints tokens or keeps local passwords; the shared realm contains only
gstack platforms.
- Access review campaigns.
- Segregation-of-duties rules.
- The dormant-account report.
- QR cross-device login as a Keycloak authenticator for gsso_mob.
- Magic link.
- Keycloak Organizations.
gsso-cli or Terraform for CI onboarding.
- Helm chart production hardening (HA Keycloak).
- Risk-based login (rule-based only, GSSO-ADR-014).
The MVP is S0 + S1 + the dashboard, events and grants of S2, running locally and on the demo host against a local or staging Keycloak (not production). It is demonstrable with:
- The 6 screens of the design (Dashboard, Realms, Applications, Users with drawer, Roles, Authentication) plus Platforms, Grants and Sync, in RO/RU/EN.
- Registering a platform with clients and roles, which then appear in Keycloak.
- A grant request, approval and revocation that are visible in the user’s token and in the events.
- A drift made by hand in Keycloak that is detected and fixed.
- SSO between the GSSO console and one sample app.
| # | Risk | Impact | Mitigation |
|---|
| R1 | Takeover of the live Keycloak breaks all app logins | High | Same version, database backup, image-only swap first, rollback = previous image, maintenance window, owner approval |
| R2 | Keycloak Admin API or SPI changes in upgrades | Medium | Pinned 26.6.x; the IT suite gates upgrades (NFR-OPS-004); the adapter is isolated in KeycloakAdminGateway |
| R3 | Reconciler deletes objects created by hand | High | gsso.managed marker; unmanaged objects are never deleted; IGNORE for adopted realms; dry runs |
| R4 | Realm gstack is a single point of failure for all staff apps | High | HA Keycloak in the target; logins do not depend on GSSO, Kafka or GLog (NFR-AVL-003) |
| R5 | Migration of pattern-A apps is slower than planned | Medium | Role aliases in the starter; old client kept in parallel for one release; one app at a time |
| R6 | TLS renewal on the demo host is still broken | High | Fix before S4; certificate expiry alert (NFR-AVL-006) |
| R7 | MPass production access is delayed | Medium | Mock IdP; cetatean production waits for it (Q-GSSO-8) |
| R8 | Approval steps slow down admins | Low | Direct grants for non-sensitive roles, bundles, bulk approval |
| R9 | Secrets in plain-text notes leak | High | Rotate every client secret and admin password during takeover; secret store only |
| R10 | Shared demo host memory pressure | Medium | Memory budget (report 04 §8.1), Kafka optional (shared cluster if available) |
| Dependency | Needed for | Status |
|---|
| Keycloak 26.6.3 (live) | Takeover, adoption | Running |
| Kafka cluster | Events, revocation | Shared cluster planned; local single broker meanwhile |
| GLog | Audit forwarding | Running; GSSO needs a gsso-glog client with audit:write |
| GNotify | Notifications, alerts | Running; OIDC disabled, so S4 enables it |
GDS packages @gstack/gds-angular, @gstack/gds-core | Console, themes | Published (GitLab npm project 581) |
| MPass test environment | cetatean | Pending (Q-GSSO-2) |
| Institution AD/LDAP | Federation | Pending (Q-GSSO-3) |
Edge nginx + DNS gsso.gstack.esempla.systems | Demo deployment | Owner approval required |
- The EN text is governing. The RO and RU translations carry
Translated from EN rev.
- Changes are made by revision, with no renumbering.
- Phase gates are reviewed by the teamlead. Production actions (S4) need explicit owner approval each time.