Sari la conținut

GSSO — Roadmap

Acest conținut nu este încă disponibil în limba selectată.

Document codeSPEC-GSSO-2026 / Report 05
Version0.1-draft (EN source, governing)
Date2026-10-05
StatusDraft
Companion reports00 RFP · 01 ADR · 02 Requirements · 03 Consumers & contract · 04 Technical documentation
VersionDateChanges
0.1-draft2026-10-05Phases S0–S5, MVP, risks, dependencies
Consumer milestoneNeeds from GSSOGSSO phase
CRM F0 (foundation)CAP-GSSO-01: realm gstack, crm-gateway, service clients, locale, UUID subS1
CRM F1+ / gDocFlow / gTendersCAP-GSSO-03, 07 (sessions, token exchange)S3
gFlow G1role → users query, service principals per appS3
gInsight (deferred)org_unit claims (CAP-GSSO-04)S2
Existing apps hardeningRemoval of pattern A/CS4

Each phase ends with a gate. Phase S0 cannot start coding until the ADRs in report 01 are Acceptat (DEV-PLAYBOOK §4).

  • Create the repository govtech/gstack/gsso, CLAUDE.md, gsso.jdl and test-scenarios.md, and accept the ADRs.
  • keycloak/:
    • a Dockerfile on 26.6.3;
    • baselines gstack, cetatean and tenant-template through keycloak-config-cli;
    • the GDS login theme in RO/RU/EN. The extensions module is only a skeleton in this phase.
  • deploy/docker-compose.yml with Keycloak, two PostgreSQL databases and Kafka; docker-compose.test.yml.
  • JHipster 9.1.0 generation of gsso and gsso-gateway; gsso-web skeleton on GDS with the side bar and i18n. Versions are pinned.
  • Gate: AC-001 and AC-002 pass locally, the ADRs are accepted, and /gsast is clean.

S1 — Console & catalog MVP (≈ 4 weeks)

Section titled “S1 — Console & catalog MVP (≈ 4 weeks)”
  • Realms (registry, template creation, switcher, scoping, adoption in dry-run).
  • Platforms, clients, roles, bulk service clients and audience mappers.
  • Users: list, create/invite, edit, enable/disable, credentials, sessions, unlock, projection.
  • Reconciler: outbox jobs, worker, retry, full reconcile, drift REPORT/ENFORCE, sync screen.
  • GSSO’s own append-only events, without Kafka ingestion yet.
  • The design screens Realms, Applications, Users (drawer), Roles and Sync.
  • Gate: AC-003..009, 026, 027 (partial) and 028 pass. CAP-GSSO-01 is delivered in local and staging.
  • Grants: the lifecycle, four-eyes, the inbox, expiry and notifications, bundles, org units and scoped roles.
  • The Keycloak gsso-kafka event listener, the consumer, the hash chain, GLog forwarding, back-fill, and the dashboard (KPIs, logins over 24 h, events, auth mix).
  • Authentication policies: the methods screen, conditional MFA by sensitive role, LDAP federation, the MPass mock broker in cetatean, and branding.
  • Revocation publisher and access report.
  • Gate: AC-010..019, 024, 025 pass. CAP-GSSO-02 and 04 are delivered.

S3 — Integration kit & pilot (≈ 3 weeks)

Section titled “S3 — Integration kit & pilot (≈ 3 weeks)”
  • gsso-spring-boot-starter and @gstack/gsso-angular.
  • api/v1/app (self-registration, lookups, roles, sessions, grant requests).
  • Token-exchange permissions.
  • Sample app and onboarding runbook.
  • Pilot apps:
    • gregistry (pattern B): moves to gstack and the starter;
    • glog: starter and scopes, and GSSO becomes an ingest client;
    • the CRM gateway skeleton.
  • Gate: AC-020..023 pass, SSO works across gsso-console + gregistry + glog, and CAP-GSSO-03, 06 and 07 are delivered.

S4 — Migration of existing apps (≈ 6 weeks, app by app)

Section titled “S4 — Migration of existing apps (≈ 6 weeks, app by app)”
  • Production takeover of the live Keycloak (report 04 §11.1), with the owner’s approval and a maintenance window.
  • Adopt realm interdictii, then decide Q-GSSO-1.
  • Migrate the pattern-A apps (interdictii, gdocs, gnotify) and pattern C (drumuri: staff to gstack, MPass to cetatean). Then gstorage (realm gstorage → gstack), cancelarie, platform and gportal.
  • Retire ROLE_ADMIN; delete the obsolete realms (gdocs, gnotify, gstorage, ultra) after migration.
  • Create tenant-* realms for the whitelabel sites.
  • Gate: AC-030; no app mints tokens or keeps local passwords; the shared realm contains only gstack platforms.
  • Access review campaigns.
  • Segregation-of-duties rules.
  • The dormant-account report.
  • QR cross-device login as a Keycloak authenticator for gsso_mob.
  • Magic link.
  • Keycloak Organizations.
  • gsso-cli or Terraform for CI onboarding.
  • Helm chart production hardening (HA Keycloak).
  • Risk-based login (rule-based only, GSSO-ADR-014).

The MVP is S0 + S1 + the dashboard, events and grants of S2, running locally and on the demo host against a local or staging Keycloak (not production). It is demonstrable with:

  1. The 6 screens of the design (Dashboard, Realms, Applications, Users with drawer, Roles, Authentication) plus Platforms, Grants and Sync, in RO/RU/EN.
  2. Registering a platform with clients and roles, which then appear in Keycloak.
  3. A grant request, approval and revocation that are visible in the user’s token and in the events.
  4. A drift made by hand in Keycloak that is detected and fixed.
  5. SSO between the GSSO console and one sample app.
#RiskImpactMitigation
R1Takeover of the live Keycloak breaks all app loginsHighSame version, database backup, image-only swap first, rollback = previous image, maintenance window, owner approval
R2Keycloak Admin API or SPI changes in upgradesMediumPinned 26.6.x; the IT suite gates upgrades (NFR-OPS-004); the adapter is isolated in KeycloakAdminGateway
R3Reconciler deletes objects created by handHighgsso.managed marker; unmanaged objects are never deleted; IGNORE for adopted realms; dry runs
R4Realm gstack is a single point of failure for all staff appsHighHA Keycloak in the target; logins do not depend on GSSO, Kafka or GLog (NFR-AVL-003)
R5Migration of pattern-A apps is slower than plannedMediumRole aliases in the starter; old client kept in parallel for one release; one app at a time
R6TLS renewal on the demo host is still brokenHighFix before S4; certificate expiry alert (NFR-AVL-006)
R7MPass production access is delayedMediumMock IdP; cetatean production waits for it (Q-GSSO-8)
R8Approval steps slow down adminsLowDirect grants for non-sensitive roles, bundles, bulk approval
R9Secrets in plain-text notes leakHighRotate every client secret and admin password during takeover; secret store only
R10Shared demo host memory pressureMediumMemory budget (report 04 §8.1), Kafka optional (shared cluster if available)
DependencyNeeded forStatus
Keycloak 26.6.3 (live)Takeover, adoptionRunning
Kafka clusterEvents, revocationShared cluster planned; local single broker meanwhile
GLogAudit forwardingRunning; GSSO needs a gsso-glog client with audit:write
GNotifyNotifications, alertsRunning; OIDC disabled, so S4 enables it
GDS packages @gstack/gds-angular, @gstack/gds-coreConsole, themesPublished (GitLab npm project 581)
MPass test environmentcetateanPending (Q-GSSO-2)
Institution AD/LDAPFederationPending (Q-GSSO-3)
Edge nginx + DNS gsso.gstack.esempla.systemsDemo deploymentOwner approval required
  • The EN text is governing. The RO and RU translations carry Translated from EN rev.
  • Changes are made by revision, with no renumbering.
  • Phase gates are reviewed by the teamlead. Production actions (S4) need explicit owner approval each time.