Skip to content

Phase 05 Plan S30: Isolated Synthetic Rehearsal Summary

The isolated rehearsal passed its full Task 2 verify command on 2026-10-03. Ordinary staging stayed on Auth0 throughout. The rehearsal was then removed through a two-stage GitOps teardown.

Live run (Task 2), 2026-10-03

Chris ran the operator wrapper. It runs live-smoke.sh --environment staging --expected-provider openiddict --isolated-rehearsal --require-two-replicas --require-forwarded-header-matrix from the approved worktree agents/s30-live, which was at origin/main.

The evidence file was redaction-checked and is kept private (mode 0600). Its results:

Assertion Result
live-smoke.sh exit code 0 (result: pass)
Password sign-in through the BFF pass
/api/auth/me pass
Account and admin pages, with the admin API pass
Representative protected API pass
Refresh and logout pass
SignalR negotiate and reconnect pass
Password reset journey (Mailpit tag:rehearsal) pass
Replicas / shared-session replicas 2 / 2
Forwarded-header matrix 5 of 5 rows: discovery and the BFF callback, trusted and untrusted, plus an emailed link requested under untrusted headers
Google operator-attested (google: false, googleJourney: "operator-attested"). Chris signed in with Google in a desktop browser at 2026-10-03T01:46Z. He landed signed in, /api/auth/me returned 200, and Google was listed under ExternalLogins
Old-cookie rejection after a generation change not checked (old_cookie_unauthorized_checked: false)

Account set-up on 2026-10-02, done through the UI only:

  • registration with the Mailpit verification link;
  • the Identity /Account/Admission profile step;
  • an admin grant on the synthetic account (SyrfGroups: "administrator");
  • the Google link, with its emailed step-up.

Not exercised live: passkeys, optional MFA, Google unlink, token-claim inspection, Swagger, confirmation resend and forced-reset admission. They stay open in the M005-VALIDATION full-matrix box.

Fixes needed on the way:

  • camaradesuk/syrf#3940 bounds and resumes dropped post-login navigations. It also adds the operator-attested Google mode.
  • camaradesuk/syrf#3951 renames the reset test, whose title tripped redaction rule 8.
  • The run must come from an approved agents/ or pr/ worktree: assert-worktree.sh rejects main.
  • On this CI host, Playwright ran inside mcr.microsoft.com/playwright:v1.58.2-noble to avoid ERR_NETWORK_CHANGED.

These lessons are recorded in Send non-production email to Mailpit.

Known issue found: camaradesuk/syrf#3935. Opening the verification link before the Register POST returns rolls the new account back.

Provision (Task 1 refresh)

camaradesuk/cluster-gitops#1508 (merge f86176a2, 2026-10-02) re-applied #1188 and #1265 on current main. It pinned the four services to staging's then-current validated artifacts and replaced the ignored Atlas annotation with mongodb.com/atlas-resource-policy: delete (camaradesuk/syrf#3834).

Teardown (Task 3)

See S30-PLAN, "Teardown evidence (2026-10-03)".

Kept for S09/S27-style runs

  • the GCP secret camarades-google-oauth-rehearsal and its non-production Google OAuth client;
  • the operator's run wrapper and its containerised Playwright wrapper;
  • the agents/s30-live worktree;
  • the S08A valkey-nonprod rehearsal ACL user.

Next

S09: the ordinary staging switch and its Auth0 rollback. Its prerequisite is still the staging API's ProxySettings/forwarded-header trust before bffAuth is enabled.