Files
homelab-frontend/tasks/3.4-flag-gated-rollout.md
T
Story Crater BotandClaude Opus 5 058f11cf2b
CI / Test (push) Canceled after 0s
CI / Vet (push) Canceled after 0s
CI / Build (push) Canceled after 0s
CI / Security (govulncheck) (push) Canceled after 0s
chore: initial commit of Go API gateway
Baseline for the Kong replacement on api.riotpiao.com. Brings the working
tree under version control for the first time: gateway source, the task
board that drives the agent runs, test fixtures, and K8s manifests.

Anchor the gateway ignore rule to the repo root. Unanchored, "gateway"
also matched the cmd/gateway/ source directory, so the program entrypoint
was excluded from every commit.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-19 20:54:34 -07:00

1.8 KiB

3.4 — Flag-gated auth rollout (GREEN)

Phase: 3 — Authentication Stage: GREEN Depends on: 3.2

  • Authentication is controlled by an explicit flag in configuration, and its default is OFF
  • With the flag off, every route answers exactly as it did before Phase 3 existed — no 401s, no WWW-Authenticate, no behaviour change
  • With the flag on, protected routes require Authorization: Bearer and reject anything else with 401
  • GET /healthz and GET /readyz never require authentication in either state
  • Which routes are protected is per-route configuration, so auth can be turned on for one surface at a time
  • Turning the flag on is a git change synced by Argo; it is never toggled by hand against the cluster
  • The flag's current state is visible in logs at startup and in metrics, so nobody has to guess whether auth is on
  • Turning the flag off again fully restores unauthenticated access, making the rollout reversible

The model API is unauthenticated today — verified live, a request with no credentials returns 200. Enabling this flag breaks every current caller until they hold a token, pi included. That is why it defaults off and is enabled deliberately, after 3.6.

Verify

# flag off
curl -s -o /dev/null -w '%{http_code}\n' localhost:8080/v1/models              # expected: 200
curl -s -o /dev/null -w '%{http_code}\n' localhost:8080/v1/chat/completions \
  -H 'content-type: application/json' -d '{"model":"reasoning","messages":[]}' # expected: 200

# flag on, no credentials
curl -s -o /dev/null -w '%{http_code}\n' localhost:8080/v1/chat/completions \
  -H 'content-type: application/json' -d '{"model":"reasoning","messages":[]}' # expected: 401
curl -s -o /dev/null -w '%{http_code}\n' localhost:8080/healthz                # expected: 200