Phase 05 Plan S30: Isolated Synthetic Rehearsal Summary¶
The isolated rehearsal passed its full Task 2 verify command on 2026-10-03. Ordinary staging stayed on Auth0 throughout. The rehearsal was then removed through a two-stage GitOps teardown.
Live run (Task 2), 2026-10-03¶
Chris ran the operator wrapper. It runs live-smoke.sh --environment staging --expected-provider
openiddict --isolated-rehearsal --require-two-replicas --require-forwarded-header-matrix from the
approved worktree agents/s30-live, which was at origin/main.
The evidence file was redaction-checked and is kept private (mode 0600). Its results:
| Assertion | Result |
|---|---|
live-smoke.sh exit code |
0 (result: pass) |
| Password sign-in through the BFF | pass |
/api/auth/me |
pass |
| Account and admin pages, with the admin API | pass |
| Representative protected API | pass |
| Refresh and logout | pass |
| SignalR negotiate and reconnect | pass |
Password reset journey (Mailpit tag:rehearsal) |
pass |
| Replicas / shared-session replicas | 2 / 2 |
| Forwarded-header matrix | 5 of 5 rows: discovery and the BFF callback, trusted and untrusted, plus an emailed link requested under untrusted headers |
operator-attested (google: false, googleJourney: "operator-attested"). Chris signed in with Google in a desktop browser at 2026-10-03T01:46Z. He landed signed in, /api/auth/me returned 200, and Google was listed under ExternalLogins |
|
| Old-cookie rejection after a generation change | not checked (old_cookie_unauthorized_checked: false) |
Account set-up on 2026-10-02, done through the UI only:
- registration with the Mailpit verification link;
- the Identity
/Account/Admissionprofile step; - an admin grant on the synthetic account (
SyrfGroups: "administrator"); - the Google link, with its emailed step-up.
Not exercised live: passkeys, optional MFA, Google unlink, token-claim inspection, Swagger, confirmation resend and forced-reset admission. They stay open in the M005-VALIDATION full-matrix box.
Fixes needed on the way:
- camaradesuk/syrf#3940 bounds and resumes dropped post-login navigations. It also adds the operator-attested Google mode.
- camaradesuk/syrf#3951 renames the reset test, whose title tripped redaction rule 8.
- The run must come from an approved
agents/orpr/worktree:assert-worktree.shrejectsmain. - On this CI host, Playwright ran inside
mcr.microsoft.com/playwright:v1.58.2-nobleto avoidERR_NETWORK_CHANGED.
These lessons are recorded in Send non-production email to Mailpit.
Known issue found: camaradesuk/syrf#3935. Opening the verification link before the Register POST returns rolls the new account back.
Provision (Task 1 refresh)¶
camaradesuk/cluster-gitops#1508 (merge f86176a2, 2026-10-02) re-applied #1188 and #1265 on current
main. It pinned the four services to staging's then-current validated artifacts and replaced the
ignored Atlas annotation with mongodb.com/atlas-resource-policy: delete (camaradesuk/syrf#3834).
Teardown (Task 3)¶
See S30-PLAN, "Teardown evidence (2026-10-03)".
Kept for S09/S27-style runs¶
- the GCP secret
camarades-google-oauth-rehearsaland its non-production Google OAuth client; - the operator's run wrapper and its containerised Playwright wrapper;
- the
agents/s30-liveworktree; - the S08A
valkey-nonprodrehearsalACL user.
Next¶
S09: the ordinary staging switch and its Auth0 rollback. Its prerequisite is still the staging
API's ProxySettings/forwarded-header trust before bffAuth is enabled.