infra/stacks/authentik/modules/authentik
Viktor Barzin a1cf7ccaf6
All checks were successful
ci/woodpecker/push/default Pipeline was successful
authentik: repoint to the SLOW-1a overlay image + un-enroll Keel
GHA built ghcr.io/viktorbarzin/authentik-server:2026.2.4-patch1 (public, verified
anonymously pullable). Point global.image at it (repository + tag pinned
explicitly so neither helm's appVersion default nor Keel can downgrade it — the
2026-06-10 boot-storm class) and remove keel.sh/enrolled from the namespace so
Keel won't auto-bump the custom tag. authentik is now manual-upgrade: bump the
Dockerfile FROM + this tag together on each authentik version bump.

Net effect once rolled: the identification-stage query drops ~1.4s -> ~14ms, so
the cold login-flow first-load stops being slow. (Does NOT affect old-browser
clients — iPadOS<=15/Safari<=15.6 still can't run the SPA; that's unfixable
server-side.) Docs: .claude/CLAUDE.md Authentik row.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 10:46:21 +00:00
..
main.tf authentik: repoint to the SLOW-1a overlay image + un-enroll Keel 2026-06-28 10:46:21 +00:00
pgbouncer.ini authentik: incident hardening after the signin-speedup rollout storm 2026-06-11 00:26:52 +00:00
pgbouncer.tf authentik: ignore Keel-managed image_pull_policy on pgbouncer 2026-06-11 00:34:44 +00:00
userlist.txt fix: restore tree dropped by 6d224861; land stem95su gdrive-sync (10m) [ci skip] 2026-06-09 08:45:33 +00:00
values.yaml authentik: repoint to the SLOW-1a overlay image + un-enroll Keel 2026-06-28 10:46:21 +00:00