Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260829-2051-passkey-migration-dev-ecs0-dataroo

rdmbair15m5-changelog-20260829-2051-passkey-migration-dev-ecs0-dataroo

Migrated web authentication on dev.ecs0.net and dev.dataroo.net from legacy Cloudflare email OTP and Nginx Basic Auth to Google Passkeys (WebAuthn / FIDO2) with 720-hour (30-day) extended sessions and updated the Cloudflare Zero Trust team auth domain to dataroo.cloudflareaccess.com.

Scope

Changes

  1. Cloudflare Zero Trust Team Domain Updated:

    • Renamed organization auth domain from legacy 18ashwoodc.cloudflareaccess.com to dataroo.cloudflareaccess.com.
    • Verified active endpoints: https://dataroo.cloudflareaccess.com/cdn-cgi/access/callback.
  2. Google Identity Provider Integration:

    • Created OAuth 2.0 Client in Google Cloud Console (Cloudflare Access Dev Docs).
    • Added authorized JavaScript origins and redirect URIs for both dataroo.cloudflareaccess.com and ecs0.cloudflareaccess.com.
    • Registered google IdP in Cloudflare Access account (a36b8599-1cf3-4816-a340-f9958697d95e).
  3. Cloudflare Access Applications & Policy Cutover:

    • dev.ecs0.net: Updated application to Google IdP only with auto_redirect_to_identity: true, session_duration: 720h (30 days), and exact-email owner allow policy.
    • dev.dataroo.net: Created application with Google IdP only with auto_redirect_to_identity: true, session_duration: 720h (30 days), and exact-email owner allow policy.
  4. Nginx Basic Auth Decommissioned on rdmsm4x:

    • Backed up /Users/richh/dataroo.net/nginx_auth.conf to /Users/richh/dataroo.net/nginx_auth.conf.bak-20260829-passkey-cutover.
    • Replaced auth_basic and IP allow/deny blocks with auth_basic off; in location / so all authenticated edge traffic flows cleanly to the origin container.
    • Tested configuration syntax (docker exec dataroo-auth_proxy-1 nginx -t) and reloaded (nginx -s reload).

Verification Evidence

Backup and Rollback

Outstanding Owner Actions