Skip to content

Document Keycloak-only mode (ENABLE_LOCAL_USERS) - #96

Open
grzanka wants to merge 3 commits into
mainfrom
keycloak-only-mode
Open

grzanka wants to merge 3 commits into
mainfrom
keycloak-only-mode

Conversation

@grzanka

@grzanka grzanka commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

What

Documents the Keycloak-only mode added in yaptide/yaptide#1676 and yaptide/ui#2427: a single backend flag, ENABLE_LOCAL_USERS, which is off by default.

  • Architecture → Authentication Model: new Keycloak-Only Deployments section, covering the default, which values count as true, and how invalid values are handled (logged and treated as off). It also says that users created with db_manage.py add-user need the flag. The @requires_auth steps now mention that local users are rejected.
  • API Reference → Auth / Overview: the 403 responses on register, login and refresh, and the local_users_enabled field returned by GET /.
  • Backend → Overview / Docker Deployment / Testing: the variable added to the env-var tables, plus a note that pytest.ini turns it on for tests.
  • Local setup (Celery) and Docker setup (Celery): ENABLE_LOCAL_USERS=true added. Without it, the documented admin/password login now fails with 403.
  • Backend → Docker Deployment Quick Start: writes ENABLE_LOCAL_USERS=true to .env before docker compose up, and notes that a change to .env needs the container recreated (up -d, not restart).
  • Login troubleshooting: the local and Docker Celery guides get a tip quoting the exact 403 message (Local user login is disabled on this instance) and how to fix it.
  • Frontend → Auth Flows: how localUsersEnabled hides the "use password login" link.

Developer impact

Every developer who runs the backend locally and logs in with a local user (admin/password) now has to set ENABLE_LOCAL_USERS=true. Each guide that uses a local login now does so. The Slurm guides log in through the local Keycloak (devuser), so they need no change. The test suite is unaffected, because pytest.ini turns the flag on.

Testing

npm run build passes, and the #keycloak-only-deployments anchor resolves.

🤖 Generated with Claude Code

Describe the ENABLE_USER_REGISTRATION and ENABLE_LOCAL_USERS backend
flags, the new 403 responses on the auth endpoints, the flags reported
by GET /, and how the UI hides password login when local users are
disabled.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The backend merged ENABLE_USER_REGISTRATION into ENABLE_LOCAL_USERS,
and local users are now off unless the flag is true. Update the auth
reference and env-var tables, and add the flag to the local and Docker
setup guides so the admin/password login keeps working.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@grzanka
grzanka deployed to github-pages October 1, 2026 18:34 — with GitHub Actions Active
Local users are now off by default, so the Docker quick start must set
ENABLE_LOCAL_USERS=true before logging in with a db_manage user. Add a
troubleshooting tip with the exact 403 message to the local and Docker
Celery setup guides, and note that changing .env requires recreating
the Flask container.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@grzanka
grzanka deployed to github-pages October 1, 2026 18:47 — with GitHub Actions Active

@dazakdev dazakdev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

This branch was successfully deployed

1 active deployment
github-pages — da2c361b Deployed Oct 1, 2026 by grzanka via deploy #226
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants