Repository navigation
feat(server-nestjs): add Sécurité Plateforme admin role - #2793
Merged
Merged
Conversation
5 tasks
shikanime
force-pushed
the
feat/security-admin-role
branch
from
September 29, 2026 13:51
f29f92f to
950d189
Compare
ADR-014 defines the only platform administration Keycloak groups as /console/admin, /console/readonly and /console/security. The console ships AdminRole rows for the first two only, while every plugin module (gitlab auditor, argocd platform security, nexus read, registry guest, sonarqube security) already targets '/console/security': the platform security group is therefore never created, synced or resolvable from the database. Add an idempotent migration inserting the 'Sécurité Plateforme' system:managed role (position 3, permissions 1 = ADMIN_PERMS.LIST for the *-RO scope of ADR-014, oidcGroup '/console/security'), mirroring the project-side Sécurité backfill (20260908155700_add_security_role). Refs #2792 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: Iac69ae508f7e6162d33c602aff4a1bfb6a6a6964
shikanime
force-pushed
the
feat/security-admin-role
branch
from
September 29, 2026 14:22
950d189 to
2f10b36
Compare
shikanime
marked this pull request as ready for review
September 29, 2026 14:40
|
StephaneTrebel
approved these changes
Sep 30, 2026
5 tasks
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

0 New Issues
0 Fixed Issues
0 Accepted Issues
No data about coverage (62.10% Estimated after merge)
Issues liées
Refs #2792
Quel est le comportement actuel ?
Le système de rôles admin ne comporte pas de rôle « Sécurité » adossé au groupe Keycloak
/console/security. L'ADR-014 définit pourtant/console/admin,/console/readonlyet/console/securitycomme les seuls groupes Keycloak d'administration plateforme, et tous les modules de la console (GitLab auditor, Argo CD security, Nexus read, Registry guest, SonarQube security) ciblent déjà/console/security: le groupe plateforme n'est donc jamais créé, synchronisé ni résolvable depuis la base.Quel est le nouveau comportement ?
Ajout d'une migration insérant le rôle admin système « Sécurité Plateforme » (type
system:managed, position 3, permissions 1 =ADMIN_PERMS.LIST, groupe OIDC/console/security), en miroir du backfill projet20260908155700_add_security_role.L'insertion est idempotente (anti-jointure sur
oidcGroup) : un rôle personnalisé déjà lié à/console/securityest préservé, aucune ligne dupliquée en cas de ré-exécution.Aucun autre changement de code dans cette PR : la réconciliation Keycloak crée le groupe de tout
AdminRoleporteur d'unoidcGroupnon vide. La projection GitLab (résolution multi-chemins admin/auditor) est traitée séparément dans #2795.Cette PR introduit-elle un breaking change ?
Non. La modification est purement additive (une ligne
AdminRoleen plus) ; les rôles existants conservent leurs permissions et leurs positions.Autres informations
Validation : migration exécutée sur PostgreSQL 16 : backfill sur un état standard (une seule ligne ajoutée, rôles existants intacts), ré-exécution sans effet, préservation d'un rôle personnalisé déjà lié à
/console/security. Aucun test unitaire impacté (migration de données seule).Issue : #2792