rdmbair15m5-changelog-20260829-0426-dev-docs-passkey-migration-checkpoint
dev documentation passkey migration checkpoint
Prepared a rollback-safe Cloudflare Access migration for the locally
hosted dev.ecs0.net and dev.dataroo.net
documentation sites; no live authentication provider or Access
application has yet been changed because Google is waiting for owner
passkey verification.
Scope
- Execution host:
rdmbair15m5 - Provider and handoff target:
rdmsm4x - Services: Cloudflare Access inventory for
dev.ecs0.netanddev.dataroo.net - Content, DNS, tunnels, TLS, origins, and nginx runtime: unchanged
Files created or updated
/Users/richh/Documents/Codex/2026-08-29/can-you-scan-my-folder-and/work/cloudflare_access_inventory.zsh/Users/richh/Documents/Codex/2026-08-29/can-you-scan-my-folder-and/work/manage_dev_docs_access.zsh/Users/richh/Documents/Codex/2026-08-29/can-you-scan-my-folder-and/work/codex-rdmbair15m5-passkey-access-20260829.jsonrdmsm4x:/Users/richh/dev/_handoff/codex-out/dev-auth-passkeys-20260829/cloudflare_access_inventory.zshrdmsm4x:/Users/richh/dev/_handoff/codex-out/dev-auth-passkeys-20260829/manage_dev_docs_access.zshrdmsm4x:/Users/richh/.agent-coordination/checkins/codex-rdmbair15m5-passkey-access-20260829.json- Fleet message
20260829-042200-89E742AEsent toclaude@rdmsm4x; no secret values included
Commands and actions
- Inspected the existing ECS0 Cloudflare provisioner and Production project boundaries.
- Ran the existing ECS0 provider
planaction read-only. - Ran the redacted Access inventory helper on
rdmsm4x. - Ran the new migration helper in read-only
planmode. - Opened Google Cloud credentials in the in-app browser and selected the Google account that locally matched the existing Cloudflare owner-email policy.
- Requested release of the prior task's stale ownership claim on
/Users/richh/dataroo.net/nginx_auth.conf.
Verification evidence
- Both helper scripts pass
zsh -nlocally and onrdmsm4x;shellcheckis not installed on either checked host. ecs0.netanddataroo.netwere verified to share one Cloudflare account.- Current Access inventory: one OTP IdP, zero Google IdPs, one
dev.ecs0.netapp at 24 hours, and nodev.dataroo.netAccess app. - The migration plan projects Google plus OTP and 720-hour sessions without touching DNS, tunnels, TLS, nginx, content, or deleting the account-level OTP provider.
- Google Cloud is blocked only on the visible owner passkey/user-presence prompt.
Backup and undo
- No live provider resource or existing project file was changed, so no pre-change backup was required.
- The newly created handoff scripts and check-in are additive and can be removed if the migration is abandoned; the fleet message is immutable by design.
- The migration helper includes a non-destructive
rollbackaction that restores OTP-only 24-hour Access login while retaining both Access app shells.
Outstanding owner action
- Complete the visible Google passkey verification prompt. After that, create the OAuth client, stage Google plus OTP on both Access apps, validate authenticated access, obtain nginx-auth ownership release, test all requested passkey stores, and only then perform Google-only cutover and retire Basic Auth.