Sari la conținut

GSSO — Documentation package (SPEC-GSSO-2026)

Acest conținut nu este încă disponibil în limba selectată.

GSSO is the shared gStack identity, authentication, authorisation and single sign-on platform (PaaS). It is built as a control plane on top of the existing Keycloak 26.6.x:

  • Keycloak stays the identity runtime: login, tokens, sessions, MFA, MPass/eID and AD/LDAP federation.
  • GSSO adds:
    • a governed service catalog (platforms, clients, platform-namespaced roles);
    • access grants per user × platform role, with request, approval (four-eyes for sensitive roles), expiry and revocation within 60 s;
    • desired-state reconciliation into Keycloak, with drift detection;
    • append-only audit with forwarding to GLog;
    • one integration kit for every gStack app (gsso-spring-boot-starter, @gstack/gsso-angular);
    • a GDS console in RO/RU/EN.

Realm model:

  • gstack: staff, with real SSO across all apps;
  • cetatean: citizens, through the MPass broker;
  • tenant-*: isolated customers.

Stack: DEV-PLAYBOOK §2, meaning a JHipster 9.1.0 microservice gsso, a gateway gsso-gateway and the Angular SPA gsso-web on GDS.

#ReportFileContent
00Terms of Reference00-rfp.en.md · RO · RUpurpose, problem, goals, scope, actors, glossary, compliance, architecture, principles, AC-001..030, Q-GSSO-1..14
01Architecture Decision Records01-adr.en.md · RO · RUGSSO-ADR-001..014, all Proposed
02Requirements02-requirements.en.md · RO · RU116 functional (GSSO-FR-001..116) + 44 non-functional, traceability to CAP-GSSO-01..07, CU-*, NFRQ
03Consumers & contract03-consumers-and-contract.en.md · RO · RUevery gStack app (pattern today → target), migration recipe, API, token, events, starter, naming, onboarding checklist
04Technical documentation04-technical-documentation.en.md · RO · RUC4, components, data model, sequence flows, realm baseline, security, deployment, takeover runbook, sizing, testing, cost
05Roadmap05-roadmap.en.md · RO · RUphases S0–S5 with gates, MVP, risks, dependencies

Also at the package root:

  • ../../CLAUDE.md
  • ../../gsso.jdl (entity model)
  • ../../test-scenarios.md (TS-GSSO-NN)
  • ../PLAN.md (implementation plan)
  • gsso.dc.html (design; seed in gstyle/design/src/GStack/GSSO.dc.html)

Status: 0.1-draft, 2026-10-05. EN is the source and governing text; RO and RU are translations with a Translated from EN rev header.

Terminal window
bash ../saas_crm/docs/reports/_build/build.sh docs/reports # from the gsso root

The build renders Mermaid diagrams, produces landscape A4 DOCX/PDF into docx/ and pdf/, and flags stale translations.