Skip to content

docs: rename to Alauda Application Services Identity Management E1, add the trademark notice, and document PSA restricted - #14

Merged
SuJinpei merged 3 commits into
masterfrom
chore/eco-958-rename-and-trademark-notice
Sep 23, 2026
Merged

SuJinpei merged 3 commits into
masterfrom
chore/eco-958-rename-and-trademark-notice

Conversation

@SuJinpei

@SuJinpei SuJinpei commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

What

Three separable commits:

  1. Rename — Alauda Build of Keycloak → Alauda Application Services Identity Management E1, 48 occurrences across 17 files including doom.config.yml's title/logoText, plus the verbatim trademark notice.
  2. llms metadata — carries the rename, and fixes a summary that described this repo as a different product.
  3. Troubleshooting — new section, first page: the instance pod never created under enforce=restricted.

Where the name and the notice come from

Both are read out of ECO-958/960's rename-dev-guide.html, which the ticket bodies defer to (「逐条明细见附件」). The attachment was republished on 2026-09-23 (id 251532, 1 844 668 B, vs the 1 841 555 B copy validated on 09-20), so it was re-downloaded and re-counted rather than trusted from cache:

string hits in the guide
Alauda Application Services Identity Management E1 2
Alauda Identity Management E1 (ECO-960's summary table) 0

The guide's scope for this row names the docs site explicitly: 「用户手册与发布说明、KB 知识库、FAQ、故障排查文档——正文、标题…;文档站另有 doom.config.yml 的 title / logoText」. The 「要修改的只有这 6 个字段」 clause is scoped to the Operator Bundle artifact and is not a cap on the rename.

The 281-character notice is never retyped — it is read out of the shipped listing, which was itself asserted byte-identical against the guide. All 15 copies in this branch are verified to be a single variant (sha1 fce3a988…). Retyping is how the ClickHouse notice silently lost its required URL.

Keycloak™, never Keycloak®: the mark is registered to The Linux Foundation — Red Hat is the original creator and steward, not the rights holder — and TLF policy forbids anyone but the owner promoting ™ to ®. intro.mdx claimed the project is "led by Red Hat"; corrected to originated at Red Hat, now a CNCF project, which is also why TLF holds the mark.

⛔ Merge ordering — the one thing to decide

install.mdx and upgrade.mdx tell the reader to find the entry by name in the Marketplace. The GA listing (artifacts@origin/main:keycloak-operator/metadata.yaml) still reads Alauda Build of Keycloak, so merging this first leaves two install steps naming a console label that does not exist yet.

Correction to an earlier revision of this description: it said that rename was "blocked on BJLYQ-4742". That is false, and re-verified live — ECO-986 has exactly one issue link (is contained by ← ECO-960) and its description never mentions BJLYQ; BJLYQ-4742 blocks ECO-958, which is ECO-960's sibling, not its parent. The sibling rename ECO-1057 is already Done. BJLYQ-4742 does gate the marketplace icon and the UI carrier slot for the disclaimer — neither of which is a display-name string.

So the listing rename is ECO-986: Open, assigned, and actionable now, and the remedy is to do it rather than to wait. ECO-986's own description in fact puts this repo in scope — 「另需扫产品 UI、用户手册与 KB、文档站 doom.config.yml 的 title 与 logoText、官网与宣传材料」 — so this PR is part of ECO-986, not a precursor to it. Land it together with the listing half.

No version string is touched

artifacts@origin/main:keycloak-operator/versions.yaml → v26.4.7-20260121113811. That is the GA version and it is exactly what these docs describe. The 26.7 line exists only as release candidates (origin/rc → v26.7.4-rc.5.gaab0aa20), so documenting it would describe something no customer can install. A release-26.7 docs branch belongs at GA, following the per-branch pattern mgr-docs already uses.

Evidence for the troubleshooting page

Measured on oss-lt-41, namespace kc-psa-probe (enforce=restricted): a plain CR is rejected at admission (allowPrivilegeEscalation != false · unrestricted capabilities · runAsNonRoot != true); the same CR plus the documented spec.unsupported.podTemplate stanza is admitted and Running. Arm B ran with runAsNonRoot: true and no runAsUser, which the kubelet permits only when the image declares a non-root user — so the image needs neither privilege escalation nor any capability. An API gap, not a capability gap.

It applies to every shipped release, not only the one measured: securityContext appears in 0 files under operator/src/main on both alauda-release-26.4 and alauda-release-26.6 (positive control podTemplate: 4 files each).

Verification

  • yarn lint → 0 errors, 0 warnings, and proven falsifiable: a deliberate dead link makes it fail, then passes again once reverted.
  • yarn build → succeeds; the built site has 0 occurrences of the old name and 332 of the new one, and both new troubleshooting pages render.
  • ⚠ yarn build fails on pristine master too, identically, on Node 25: @alauda/doom/lib/login/store.js:5 guards with typeof localStorage === 'undefined', but Node ≥22 defines that global while leaving getItem undefined, so the guard passes and line 8 throws. Pre-existing and not from this branch — worked around locally with NODE_OPTIONS=--localstorage-file=…. This repo is on doom ^1.21.5; ck-docs is on ^2.2.0.

Not in this branch, deliberately

acp-docs/sites.yaml:92-98 also carries Alauda Build of Keycloak, and its version: "26.4". That file carries pre-rename names for the entire fleet — Kafka, Redis, PXC, MGR, RabbitMQ, PostgreSQL, CNPG — so it is a central, fleet-wide change, not a Keycloak one. Flagged rather than edited.

🤖 Generated with Claude Code

SuJinpei and others added 3 commits September 23, 2026 14:42
…CO-958)

Replaces the retired display name `Alauda Build of Keycloak` and adds the
required trademark notice.

The name and the notice both come from ECO-958/960's `rename-dev-guide.html`,
which the ticket bodies defer to ("逐条明细见附件"). That attachment was
republished on 2026-09-23 (id 251532, 1 844 668 B), so it was re-downloaded and
re-counted rather than taken from the earlier copy:

  Alauda Application Services Identity Management E1   2 hits
  Alauda Identity Management E1  (the summary table)   0 hits

The guide's scope for this row covers the docs site explicitly — 「用户手册与
发布说明、KB 知识库、FAQ、故障排查文档——正文、标题…;文档站另有
doom.config.yml 的 title / logoText」. The "要修改的只有这 6 个字段" clause is
scoped to the Operator Bundle artifact and is not a cap on the rename.

The 281-character notice is never retyped: it is read out of the shipped
listing, which was itself asserted byte-identical against the guide, and all 15
copies here are verified to be a single variant (sha1 fce3a988...). Retyping is
how the ClickHouse notice lost its required URL.

Also:
  - `Keycloak™`, never `Keycloak®`. The mark is registered to The Linux
    Foundation — Red Hat is the original creator and steward, not the rights
    holder — and TLF's policy forbids anyone but the owner promoting ™ to ®.
    intro.mdx said the project is "led by Red Hat"; corrected to originated at
    Red Hat, now a CNCF project, which is also why TLF holds the mark.
  - The two version tables took neutral column headers (`Release`,
    `Upstream Keycloak™`) rather than a 50-character product name, following
    ck-docs.

No version string is touched. `artifacts@origin/main:keycloak-operator/versions.yaml`
is still `v26.4.7-20260121113811`, so 26.4 is what the docs correctly describe;
26.7 exists only as release candidates.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`llmstxt-config.yaml` described this repo as "the Alauda Keycloak (Alauda
Container Security) product". Alauda Container Security is a different product
with its own entry in acp-docs. That summary is the seed for the AI-generated
`llms.txt`, so the error was being published at the top of the generated index.

The cached per-file descriptions in `llmstxt-state.json` are published through
`llms.txt` too, so the old name is replaced there as well — otherwise a partial
regeneration would reprint it. The file is re-parsed as JSON after editing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Adds the Troubleshooting section (weight 100, between Integration and API
Reference) with its first page: a `Keycloak` CR in a namespace labelled
`pod-security.kubernetes.io/enforce=restricted` is accepted, the StatefulSet
appears, and no pod is ever created.

Measured, not inferred. On oss-lt-41 in namespace `kc-psa-probe`, a plain CR is
rejected at admission — `allowPrivilegeEscalation != false · unrestricted
capabilities · runAsNonRoot != true` — while the same CR plus the
`spec.unsupported.podTemplate` stanza documented here is admitted and Running.
That second arm ran with `runAsNonRoot: true` and no `runAsUser`, which the
kubelet permits only when the image declares a non-root user, so it also
establishes that the server image needs neither privilege escalation nor any
Linux capability. The gap is in what the API lets you express, not in the
server.

It applies to every shipped release, not just the one measured: `securityContext`
appears in 0 files under `operator/src/main` on both `alauda-release-26.4` and
`alauda-release-26.6` (positive control: `podTemplate`, 4 files each).

The YAML is the exact stanza from the probe, including the container entry with
no `name` — the pod template is the seed the Operator builds on, and it fills in
the name and image itself. `runAsUser` is deliberately absent: it collides with
the per-namespace UID range OpenShift's SCC assigns.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying alauda-keycloak with  Cloudflare Pages  Cloudflare Pages

Latest commit: e8710c5
Status: ✅  Deploy successful!
Preview URL: https://abc6b811.alauda-keycloak.pages.dev
Branch Preview URL: https://chore-eco-958-rename-and-tra.alauda-keycloak.pages.dev

View logs

@SuJinpei
SuJinpei merged commit 5ef3d73 into master Sep 23, 2026
3 checks passed
@SuJinpei
SuJinpei deleted the chore/eco-958-rename-and-trademark-notice branch September 23, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant