docs: rename to Alauda Application Services Identity Management E1, add the trademark notice, and document PSA restricted - #14
Merged
Conversation
…CO-958)
Replaces the retired display name `Alauda Build of Keycloak` and adds the
required trademark notice.
The name and the notice both come from ECO-958/960's `rename-dev-guide.html`,
which the ticket bodies defer to ("逐条明细见附件"). That attachment was
republished on 2026-09-23 (id 251532, 1 844 668 B), so it was re-downloaded and
re-counted rather than taken from the earlier copy:
Alauda Application Services Identity Management E1 2 hits
Alauda Identity Management E1 (the summary table) 0 hits
The guide's scope for this row covers the docs site explicitly — 「用户手册与
发布说明、KB 知识库、FAQ、故障排查文档——正文、标题…;文档站另有
doom.config.yml 的 title / logoText」. The "要修改的只有这 6 个字段" clause is
scoped to the Operator Bundle artifact and is not a cap on the rename.
The 281-character notice is never retyped: it is read out of the shipped
listing, which was itself asserted byte-identical against the guide, and all 15
copies here are verified to be a single variant (sha1 fce3a988...). Retyping is
how the ClickHouse notice lost its required URL.
Also:
- `Keycloak™`, never `Keycloak®`. The mark is registered to The Linux
Foundation — Red Hat is the original creator and steward, not the rights
holder — and TLF's policy forbids anyone but the owner promoting ™ to ®.
intro.mdx said the project is "led by Red Hat"; corrected to originated at
Red Hat, now a CNCF project, which is also why TLF holds the mark.
- The two version tables took neutral column headers (`Release`,
`Upstream Keycloak™`) rather than a 50-character product name, following
ck-docs.
No version string is touched. `artifacts@origin/main:keycloak-operator/versions.yaml`
is still `v26.4.7-20260121113811`, so 26.4 is what the docs correctly describe;
26.7 exists only as release candidates.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`llmstxt-config.yaml` described this repo as "the Alauda Keycloak (Alauda Container Security) product". Alauda Container Security is a different product with its own entry in acp-docs. That summary is the seed for the AI-generated `llms.txt`, so the error was being published at the top of the generated index. The cached per-file descriptions in `llmstxt-state.json` are published through `llms.txt` too, so the old name is replaced there as well — otherwise a partial regeneration would reprint it. The file is re-parsed as JSON after editing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Adds the Troubleshooting section (weight 100, between Integration and API Reference) with its first page: a `Keycloak` CR in a namespace labelled `pod-security.kubernetes.io/enforce=restricted` is accepted, the StatefulSet appears, and no pod is ever created. Measured, not inferred. On oss-lt-41 in namespace `kc-psa-probe`, a plain CR is rejected at admission — `allowPrivilegeEscalation != false · unrestricted capabilities · runAsNonRoot != true` — while the same CR plus the `spec.unsupported.podTemplate` stanza documented here is admitted and Running. That second arm ran with `runAsNonRoot: true` and no `runAsUser`, which the kubelet permits only when the image declares a non-root user, so it also establishes that the server image needs neither privilege escalation nor any Linux capability. The gap is in what the API lets you express, not in the server. It applies to every shipped release, not just the one measured: `securityContext` appears in 0 files under `operator/src/main` on both `alauda-release-26.4` and `alauda-release-26.6` (positive control: `podTemplate`, 4 files each). The YAML is the exact stanza from the probe, including the container entry with no `name` — the pod template is the seed the Operator builds on, and it fills in the name and image itself. `runAsUser` is deliberately absent: it collides with the per-namespace UID range OpenShift's SCC assigns. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Deploying alauda-keycloak with
|
| Latest commit: |
e8710c5
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://abc6b811.alauda-keycloak.pages.dev |
| Branch Preview URL: | https://chore-eco-958-rename-and-tra.alauda-keycloak.pages.dev |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Three separable commits:
Alauda Build of Keycloak→Alauda Application Services Identity Management E1, 48 occurrences across 17 files includingdoom.config.yml'stitle/logoText, plus the verbatim trademark notice.enforce=restricted.Where the name and the notice come from
Both are read out of ECO-958/960's
rename-dev-guide.html, which the ticket bodies defer to (「逐条明细见附件」). The attachment was republished on 2026-09-23 (id251532, 1 844 668 B, vs the 1 841 555 B copy validated on 09-20), so it was re-downloaded and re-counted rather than trusted from cache:Alauda Application Services Identity Management E1Alauda Identity Management E1(ECO-960's summary table)The guide's scope for this row names the docs site explicitly: 「用户手册与发布说明、KB 知识库、FAQ、故障排查文档——正文、标题…;文档站另有
doom.config.yml的title/logoText」. The 「要修改的只有这 6 个字段」 clause is scoped to the Operator Bundle artifact and is not a cap on the rename.The 281-character notice is never retyped — it is read out of the shipped listing, which was itself asserted byte-identical against the guide. All 15 copies in this branch are verified to be a single variant (
sha1 fce3a988…). Retyping is how the ClickHouse notice silently lost its required URL.Keycloak™, neverKeycloak®: the mark is registered to The Linux Foundation — Red Hat is the original creator and steward, not the rights holder — and TLF policy forbids anyone but the owner promoting ™ to ®.intro.mdxclaimed the project is "led by Red Hat"; corrected to originated at Red Hat, now a CNCF project, which is also why TLF holds the mark.⛔ Merge ordering — the one thing to decide
install.mdxandupgrade.mdxtell the reader to find the entry by name in the Marketplace. The GA listing (artifacts@origin/main:keycloak-operator/metadata.yaml) still readsAlauda Build of Keycloak, so merging this first leaves two install steps naming a console label that does not exist yet.Correction to an earlier revision of this description: it said that rename was "blocked on BJLYQ-4742". That is false, and re-verified live — ECO-986 has exactly one issue link (
is contained by ← ECO-960) and its description never mentions BJLYQ; BJLYQ-4742 blocks ECO-958, which is ECO-960's sibling, not its parent. The sibling rename ECO-1057 is alreadyDone. BJLYQ-4742 does gate the marketplace icon and the UI carrier slot for the disclaimer — neither of which is a display-name string.So the listing rename is ECO-986: Open, assigned, and actionable now, and the remedy is to do it rather than to wait. ECO-986's own description in fact puts this repo in scope — 「另需扫产品 UI、用户手册与 KB、文档站 doom.config.yml 的 title 与 logoText、官网与宣传材料」 — so this PR is part of ECO-986, not a precursor to it. Land it together with the listing half.
No version string is touched
artifacts@origin/main:keycloak-operator/versions.yaml→v26.4.7-20260121113811. That is the GA version and it is exactly what these docs describe. The 26.7 line exists only as release candidates (origin/rc→v26.7.4-rc.5.gaab0aa20), so documenting it would describe something no customer can install. Arelease-26.7docs branch belongs at GA, following the per-branch pattern mgr-docs already uses.Evidence for the troubleshooting page
Measured on oss-lt-41, namespace
kc-psa-probe(enforce=restricted): a plain CR is rejected at admission (allowPrivilegeEscalation != false · unrestricted capabilities · runAsNonRoot != true); the same CR plus the documentedspec.unsupported.podTemplatestanza is admitted and Running. Arm B ran withrunAsNonRoot: trueand norunAsUser, which the kubelet permits only when the image declares a non-root user — so the image needs neither privilege escalation nor any capability. An API gap, not a capability gap.It applies to every shipped release, not only the one measured:
securityContextappears in 0 files underoperator/src/mainon bothalauda-release-26.4andalauda-release-26.6(positive controlpodTemplate: 4 files each).Verification
yarn lint→ 0 errors, 0 warnings, and proven falsifiable: a deliberate dead link makes it fail, then passes again once reverted.yarn build→ succeeds; the built site has 0 occurrences of the old name and 332 of the new one, and both new troubleshooting pages render.yarn buildfails on pristinemastertoo, identically, on Node 25:@alauda/doom/lib/login/store.js:5guards withtypeof localStorage === 'undefined', but Node ≥22 defines that global while leavinggetItemundefined, so the guard passes and line 8 throws. Pre-existing and not from this branch — worked around locally withNODE_OPTIONS=--localstorage-file=…. This repo is on doom^1.21.5; ck-docs is on^2.2.0.Not in this branch, deliberately
acp-docs/sites.yaml:92-98also carriesAlauda Build of Keycloak, and itsversion: "26.4". That file carries pre-rename names for the entire fleet — Kafka, Redis, PXC, MGR, RabbitMQ, PostgreSQL, CNPG — so it is a central, fleet-wide change, not a Keycloak one. Flagged rather than edited.🤖 Generated with Claude Code