ADR-0035 records the decision issue #177 asked for, which went the other way from its proposal. The stack is published through the existing labs Caddy over a reverse SSH tunnel, not through an in-cluster Caddy edge. The deciding facts: the Talos hypervisor sits behind office NAT with no inbound path, and the labs Caddy already holds 80/443 and the *.labs.respellion.tech wildcard certificate.
The ADR covers the chain (Caddy → openssh-server → tunnel → NodePorts), keycloakUrl / big.keycloakUrl, KC_PROXY_HEADERS, the optional demo OTP autofill, the alternatives (including the closed PR #178), and the costs: routing outside the cluster, two SSH hops, a single issuer string, public demo portals, and 401s after a Keycloak restart.
## What & why
ADR-0035 records the decision issue #177 asked for, which went the other way from its proposal. The stack is published through the **existing labs Caddy** over a reverse SSH tunnel, not through an in-cluster Caddy edge. The deciding facts: the Talos hypervisor sits behind office NAT with no inbound path, and the labs Caddy already holds 80/443 and the `*.labs.respellion.tech` wildcard certificate.
The ADR covers the chain (Caddy → `openssh-server` → tunnel → NodePorts), `keycloakUrl` / `big.keycloakUrl`, `KC_PROXY_HEADERS`, the optional demo OTP autofill, the alternatives (including the closed PR #178), and the costs: routing outside the cluster, two SSH hops, a single issuer string, public demo portals, and 401s after a Keycloak restart.
- `docs/architecture/adr-0035-public-access-through-the-labs-caddy.md` (new)
- `mkdocs.yml`: nav entry (`check-docs-nav.py` passes)
- `docs/runbooks/kubernetes-talos.md`: links the ADR from "Publishing through the labs Caddy"
Closes #177
## Definition of Done
- [x] Linked Gitea issue (above).
- [x] Conventional Commit referencing the issue.
- [ ] CI green
- [x] ADR added in `docs/architecture/`.
## Notes for reviewers
- The number 0035 was used in the unmerged #178 for the in-cluster ADR. That ADR never reached `main`, so the number is free there.
- Implementation PRs: #179, #180, #181. Related CI fixes: #183, #184.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Records the decision #177 asked for, the other way round: the hypervisor has no
inbound path and the labs Caddy already holds 80/443 and the wildcard cert, so
the portals go through it over a reverse SSH tunnel instead of an in-cluster
edge. Covers keycloakUrl, KC_PROXY_HEADERS and the optional demo OTP autofill.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
not
merged commit 1489f68796 into main2026-09-28 12:30:12 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What & why
ADR-0035 records the decision issue #177 asked for, which went the other way from its proposal. The stack is published through the existing labs Caddy over a reverse SSH tunnel, not through an in-cluster Caddy edge. The deciding facts: the Talos hypervisor sits behind office NAT with no inbound path, and the labs Caddy already holds 80/443 and the
*.labs.respellion.techwildcard certificate.The ADR covers the chain (Caddy →
openssh-server→ tunnel → NodePorts),keycloakUrl/big.keycloakUrl,KC_PROXY_HEADERS, the optional demo OTP autofill, the alternatives (including the closed PR #178), and the costs: routing outside the cluster, two SSH hops, a single issuer string, public demo portals, and 401s after a Keycloak restart.docs/architecture/adr-0035-public-access-through-the-labs-caddy.md(new)mkdocs.yml: nav entry (check-docs-nav.pypasses)docs/runbooks/kubernetes-talos.md: links the ADR from "Publishing through the labs Caddy"Closes #177
Definition of Done
docs/architecture/.Notes for reviewers
main, so the number is free there.🤖 Generated with Claude Code