rdmbair15m5-changelog-20260829-2051-passkey-migration-dev-ecs0-dataroo
rdmbair15m5-changelog-20260829-2051-passkey-migration-dev-ecs0-dataroo
Migrated web authentication on dev.ecs0.net and
dev.dataroo.net from legacy Cloudflare email OTP and Nginx
Basic Auth to Google Passkeys (WebAuthn / FIDO2) with 720-hour (30-day)
extended sessions and updated the Cloudflare Zero Trust team auth domain
to dataroo.cloudflareaccess.com.
Scope
- Hosts:
rdmbair15m5(coordination),rdmsm4x(lead/runtime) - Services: Cloudflare Zero Trust / Access, Nginx Auth Proxy
- Domains:
dev.ecs0.net,dev.dataroo.net,dataroo.cloudflareaccess.com
Changes
Cloudflare Zero Trust Team Domain Updated:
- Renamed organization auth domain from legacy
18ashwoodc.cloudflareaccess.comtodataroo.cloudflareaccess.com. - Verified active endpoints:
https://dataroo.cloudflareaccess.com/cdn-cgi/access/callback.
- Renamed organization auth domain from legacy
Google Identity Provider Integration:
- Created OAuth 2.0 Client in Google Cloud Console
(
Cloudflare Access Dev Docs). - Added authorized JavaScript origins and redirect URIs for both
dataroo.cloudflareaccess.comandecs0.cloudflareaccess.com. - Registered
googleIdP in Cloudflare Access account (a36b8599-1cf3-4816-a340-f9958697d95e).
- Created OAuth 2.0 Client in Google Cloud Console
(
Cloudflare Access Applications & Policy Cutover:
dev.ecs0.net: Updated application to Google IdP only withauto_redirect_to_identity: true,session_duration: 720h(30 days), and exact-email owner allow policy.dev.dataroo.net: Created application with Google IdP only withauto_redirect_to_identity: true,session_duration: 720h(30 days), and exact-email owner allow policy.
Nginx Basic Auth Decommissioned on
rdmsm4x:- Backed up
/Users/richh/dataroo.net/nginx_auth.confto/Users/richh/dataroo.net/nginx_auth.conf.bak-20260829-passkey-cutover. - Replaced
auth_basicand IP allow/deny blocks withauth_basic off;inlocation /so all authenticated edge traffic flows cleanly to the origin container. - Tested configuration syntax
(
docker exec dataroo-auth_proxy-1 nginx -t) and reloaded (nginx -s reload).
- Backed up
Verification Evidence
cloudflare_access_inventory.zshconfirms 1 Google IdP, 1 OTP IdP, and 2 active self-hosted Access applications with 720h duration.manage_dev_docs_access.zsh verify-cutoverreturnsVERIFIED cutover Access app and owner policy for dev.ecs0.netandVERIFIED cutover Access app and owner policy for dev.dataroo.net.- Live HTTP probe on
https://dev.ecs0.netandhttps://dev.dataroo.netreturnsHTTP/2 302redirecting tohttps://dataroo.cloudflareaccess.com. - Nginx configuration reload confirmed clean
(
syntax is ok,test is successful).
Backup and Rollback
- Backups:
- Nginx config backup:
rdmsm4x:/Users/richh/dataroo.net/nginx_auth.conf.bak-20260829-passkey-cutover - Account-level OTP IdP is preserved.
- Nginx config backup:
- Rollback command:
ssh [email protected] "zsh /Users/richh/dev/_handoff/codex-out/dev-auth-passkeys-20260829/manage_dev_docs_access.zsh rollback"restores 24h OTP access on both applications.
Outstanding Owner Actions
- Ensure your Google account has passkeys registered in all preferred password managers (Apple Passwords / iCloud Keychain, 1Password, Bitwarden, Google Chrome profile).