CI / k8s (push) Successful in 8s
CI / build (push) Successful in 1m43s
CI / lint (push) Successful in 2m1s
CI / unit (push) Successful in 1m41s
CI / frontend (push) Successful in 2m28s
Deploy to Talos / deploy (push) Successful in 2m26s
CI / mutation (push) Successful in 4m58s
CI / verify-stack (push) Canceled after 7m18s
## What & why ADR-0035 records the decision issue #177 asked for, which went the other way from its proposal. The stack is published through the **existing labs Caddy** over a reverse SSH tunnel, not through an in-cluster Caddy edge. The deciding facts: the Talos hypervisor sits behind office NAT with no inbound path, and the labs Caddy already holds 80/443 and the `*.labs.respellion.tech` wildcard certificate. The ADR covers the chain (Caddy → `openssh-server` → tunnel → NodePorts), `keycloakUrl` / `big.keycloakUrl`, `KC_PROXY_HEADERS`, the optional demo OTP autofill, the alternatives (including the closed PR #178), and the costs: routing outside the cluster, two SSH hops, a single issuer string, public demo portals, and 401s after a Keycloak restart. - `docs/architecture/adr-0035-public-access-through-the-labs-caddy.md` (new) - `mkdocs.yml`: nav entry (`check-docs-nav.py` passes) - `docs/runbooks/kubernetes-talos.md`: links the ADR from "Publishing through the labs Caddy" Closes #177 ## Definition of Done - [x] Linked Gitea issue (above). - [x] Conventional Commit referencing the issue. - [ ] CI green - [x] ADR added in `docs/architecture/`. ## Notes for reviewers - The number 0035 was used in the unmerged #178 for the in-cluster ADR. That ADR never reached `main`, so the number is free there. - Implementation PRs: #179, #180, #181. Related CI fixes: #183, #184. 🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #185
100 lines
5.5 KiB
YAML
100 lines
5.5 KiB
YAML
site_name: register-referentie
|
|
site_description: Reference application for Respellion's Common Ground architecture pattern
|
|
docs_dir: docs
|
|
|
|
theme:
|
|
name: material
|
|
features:
|
|
- navigation.sections
|
|
- navigation.top
|
|
- content.code.copy
|
|
palette:
|
|
- scheme: default
|
|
toggle:
|
|
icon: material/brightness-7
|
|
name: Switch to dark mode
|
|
- scheme: slate
|
|
toggle:
|
|
icon: material/brightness-4
|
|
name: Switch to light mode
|
|
|
|
nav:
|
|
- Home: index.md
|
|
- Product Requirements: PRD.md
|
|
- Architecture:
|
|
- "ADR-0001: Loose coupling": architecture/adr-0001-loose-coupling.md
|
|
- "ADR-0002: Catalogus design": architecture/adr-0002-catalogus-design.md
|
|
- "ADR-0003: ACL default-fill": architecture/adr-0003-default-fill.md
|
|
- "ADR-0004: BDD framework": architecture/adr-0004-bdd-framework.md
|
|
- "ADR-0005: Mutation testing": architecture/adr-0005-mutation-testing.md
|
|
- "ADR-0006: ACL integration test provisioning": architecture/adr-0006-integration-test-provisioning.md
|
|
- "ADR-0007: OpenZaak → NRC notification wiring": architecture/adr-0007-notification-wiring.md
|
|
- "ADR-0008: Read projection store": architecture/adr-0008-read-projection-store.md
|
|
- "ADR-0009: External-task job worker": architecture/adr-0009-external-task-job-worker.md
|
|
- "ADR-0010: BFF OIDC validation": architecture/adr-0010-bff-oidc.md
|
|
- "ADR-0011: Approval status flow": architecture/adr-0011-approval-status-flow.md
|
|
- "ADR-0012: Citizen reference correlation": architecture/adr-0012-citizen-reference-correlation.md
|
|
- "ADR-0013: Behandel-portal wiring": architecture/adr-0013-behandel-portal-wiring.md
|
|
- "ADR-0014: Withdrawal cancels the process": architecture/adr-0014-withdrawal-cancels-the-process.md
|
|
- "ADR-0015: Beoordeling escalation": architecture/adr-0015-beoordeling-escalation.md
|
|
- "ADR-0016: Diploma eligibility DMN": architecture/adr-0016-diploma-eligibility-dmn.md
|
|
- "ADR-0017: Document-wait timeout": architecture/adr-0017-document-wait-timeout-cancellation.md
|
|
- "ADR-0018: Diploma upload via the ACL": architecture/adr-0018-diploma-upload-via-acl-documenten.md
|
|
- "ADR-0019: Zaak cancellation on timeout": architecture/adr-0019-zaak-cancellation-on-timeout.md
|
|
- "ADR-0020: Local stack self-seeds": architecture/adr-0020-local-stack-self-seeds.md
|
|
- "ADR-0021: Zaaktype by identificatie": architecture/adr-0021-acl-resolves-zaaktype-by-identificatie.md
|
|
- "ADR-0022: Quartz scheduler": architecture/adr-0022-quartz-scheduler.md
|
|
- "ADR-0023: Observability stack": architecture/adr-0023-observability-stack.md
|
|
- "ADR-0024: Prometheus AspNetCore exporter": architecture/adr-0024-prometheus-aspnetcore-exporter.md
|
|
- "ADR-0025: BFF reads catalogus via the ACL": architecture/adr-0025-bff-reads-catalogus-via-acl.md
|
|
- "ADR-0026: Mutable default-fill store": architecture/adr-0026-mutable-default-fill-store.md
|
|
- "ADR-0027: RegisterRecord objecttype": architecture/adr-0027-registerrecord-objecttype-schema.md
|
|
- "ADR-0028: Objecten holds the register": architecture/adr-0028-objecten-holds-the-register.md
|
|
- "ADR-0029: Objecten publishes to NRC": architecture/adr-0029-objecten-publishes-to-nrc.md
|
|
- "ADR-0030: Projection sourced from the register": architecture/adr-0030-projection-sourced-from-the-register.md
|
|
- "ADR-0031: MFA on the medewerker realm": architecture/adr-0031-mfa-on-the-medewerker-realm.md
|
|
- "ADR-0032: Werkbak live refresh": architecture/adr-0032-werkbak-live-refresh.md
|
|
- "ADR-0033: Kubernetes via one Helm chart": architecture/adr-0033-kubernetes-via-one-helm-chart.md
|
|
- "ADR-0034: Caddy serves the portals": architecture/adr-0034-caddy-serves-the-portals.md
|
|
- "ADR-0035: Public access through the labs Caddy": architecture/adr-0035-public-access-through-the-labs-caddy.md
|
|
- FDS-architectuur:
|
|
- Overzicht: architecture/fds/README.md
|
|
- Componentview (L3): architecture/fds/c4-component-view.md
|
|
- "Slice 1: walking skeleton": architecture/fds/slice-1-proposal.md
|
|
- "FDS ADR-0001: ACL op elke registergrens": architecture/fds/adr/0001-acl-at-every-register-boundary.md
|
|
- "FDS ADR-0002: FSC voor connectiviteit": architecture/fds/adr/0002-fsc-for-connectivity.md
|
|
- "FDS ADR-0003: PBAC via OPA": architecture/fds/adr/0003-pbac-via-opa.md
|
|
- "FDS ADR-0004: Begrensde cache": architecture/fds/adr/0004-bounded-cache.md
|
|
- "FDS ADR-0005: Verwerkingenlog via events": architecture/fds/adr/0005-ldv-verwerkingenlog.md
|
|
- "FDS ADR-0006: Modulegrens en hergebruik": architecture/fds/adr/0006-module-boundary-and-reuse.md
|
|
- "FDS ADR-template": architecture/fds/adr/template.md
|
|
- Working in Gitea: gitea-workflow.md
|
|
- Frontend decisions: frontend-decisions.md
|
|
- Demo script: demo-script.md
|
|
- Synthetic data: synthetic-data.md
|
|
- Runbooks:
|
|
- CI: runbooks/ci.md
|
|
- OpenZaak: runbooks/openzaak.md
|
|
- Open Notificaties (NRC): runbooks/opennotificaties.md
|
|
- Keycloak: runbooks/keycloak.md
|
|
- Flowable: runbooks/flowable.md
|
|
- Kubernetes on Talos: runbooks/kubernetes-talos.md
|
|
- Gitea Actions gotchas: runbooks/gitea-actions-gotchas.md
|
|
|
|
markdown_extensions:
|
|
- admonition
|
|
- toc:
|
|
permalink: true
|
|
- pymdownx.superfences:
|
|
custom_fences:
|
|
- name: mermaid
|
|
class: mermaid
|
|
format: !!python/name:pymdownx.superfences.fence_code_format
|
|
|
|
# Many docs referenced by PRD.md land in later slices; don't fail the build on them.
|
|
validation:
|
|
nav:
|
|
omitted_files: warn
|
|
links:
|
|
not_found: warn
|