rdmbair15m5-changelog-20260830-1703-dev-docs-passkey-accepted-skill
rdmbair15m5-changelog-20260830-1703-dev-docs-passkey-accepted-skill
Accepted the owner-validated Google-passkey migration for
dev.ecs0.net and dev.dataroo.net, applied and
verified the guarded Google-only cutover, and saved the reusable
operational workflow as a canonical Codex skill.
Scope
- Coordination host:
rdmbair15m5 - Provider/runtime host:
rdmsm4x - Production services:
dev.ecs0.netanddev.dataroo.net - Provider: Cloudflare Access with Google as the application IdP
Owner acceptance
- Rich explicitly reported on 2026-08-30 that he had signed in with his Google passkeys and that access was working.
- This statement closes the real browser/passkey validation gate that API configuration checks cannot satisfy.
Live provider changes
- Ran the guarded
cutover --allow-cutoveraction for both separate Access applications. - Re-applied and verified each exact-owner Allow policy.
- Final application contract:
- Google is the sole application IdP.
- Session duration is
720h. auto_redirect_to_identityis enabled.- The account-level OTP IdP remains present for rollback.
- No Google OAuth client, OAuth secret, team domain, DNS, Tunnel, TLS, origin binding, or documentation content was changed.
- Nginx Basic Auth remains off. Its historical backup is retained as reference only and must not overwrite newer routing.
Saved skill
- Canonical skill name:
dev-docs-passkey-access - Local path:
/Users/richh/.codex/skills/dev-docs-passkey-access - Canonical rdmsm4x path:
/Users/richh/.codex/skills/dev-docs-passkey-access - Files:
SKILL.mdagents/openai.yamlreferences/site-profile.mdscripts/cloudflare_access_inventory.zshscripts/manage_dev_docs_access.zsh
- The skill preserves the configured/verified/owner-validated/accepted lifecycle boundary, separate app identities, OTP rollback resource, browser owner-presence gates, targeted nginx rollback rule, and no-secret handling.
Documentation changes
- Updated
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.mdfor both site records. - Updated
/Users/richh/.agent-coordination/checkins/codex-rdmbair15m5-passkey-access-20260829.jsontocomplete_owner_validated_google_passkey_access. - Sent final acceptance message
20260830-170410-93231598toclaude@rdmsm4x.
Verification evidence
verify-cutoverpassed for both applications after the final mutation.- Redacted inventory observed exactly one Access app per hostname, one
Google IdP, one retained OTP IdP, one allowed IdP per application,
720hsessions, and automatic redirect enabled. - Both public hostnames returned HTTP 302 through the Cloudflare Access team domain; signed redirect query strings were not retained in documentation.
- Dataroo loopback origin remained HTTP 200.
- Skill validation passed with the bundled
quick_validate.pyin an isolateduvenvironment. - Both bundled scripts passed
zsh -nlocally and onrdmsm4x. - The saved skill's live
plan,verify-cutover, and redacted inventory commands passed onrdmsm4x. - Local and rdmsm4x skill file hashes match:
SKILL.md:225b1510a1a60bc9e547e0c057b11d0100f125b453c347b2d424c927bbb47032agents/openai.yaml:0e1218342a01fbde847336d123158bbb158a8896567c37652400db012914eafcreferences/site-profile.md:da2e405de9cbcb6b5f3526c9293967faeac82d86ddff5b8882f0d770acbba161- inventory script:
6bf2cc7374dd9f24e64ee56eebd4993228b9fe8840a4415c25fcdd31482b4c25 - management script:
9394817ed75fdf5b2b00db67146aa30a94b18185866c64ec8b868e9e09877012
- Final
PROJECTS.mdSHA-256 on both hosts:87d4b4070605c9337ace720bca6b946ec744c2c157ab894ef9bd87d621654bc1. - Final canonical check-in SHA-256:
53c25ab5376e5ee96c050b13e3b5356d64fb26cbd8712caa360b86e56056ac4b.
Backups and rollback
- Pre-edit project index backup:
/Users/richh/Documents/Codex/2026-08-29/can-you-scan-my-folder-and/work/PROJECTS.md.pre-passkey-20260830, SHA-256ecd381a27d375b776117b2683d065f07eb3fa9bf441cbd9d5fdcb74df68e5cc9. - Historical nginx reference backup:
rdmsm4x:/Users/richh/dataroo.net/nginx_auth.conf.bak-20260829-passkey-cutover. - Provider rollback to OTP-only 24-hour applications while retaining
the app shells and Google IdP:
ssh [email protected] 'zsh /Users/richh/.codex/skills/dev-docs-passkey-access/scripts/manage_dev_docs_access.zsh rollback' - Nginx restoration requires a targeted edit to the current file plus credential rotation; never copy the historical backup wholesale.
Optional personal follow-up
- Expand the Google-account passkey portfolio to the desired four or five independent stores, such as Apple Passwords, 1Password, Bitwarden, Proton Pass, and a hardware key or Google Password Manager.
- No additional server-side action is required for those extra passkeys because both sites delegate authentication to the same Google identity.