Changelog¶
One line per change. Versions follow Semantic Versioning; the current version is in VERSION.
Unreleased¶
- Compose marks Keycloak healthy only on a
200readiness status, not on any"status": "UP"fragment; bootstrap's readiness wait grows from 30s to 90s, so a cold firstdocker compose up --waitno longer fails - Authz debug check answers an engine refusal as
422VALIDATION_FAILED(was theVALIDATION_ERRORshape code) - Quickstart "What to try first" points at the admin routes instead of a removed section
- The discovery document's
issuerequals theissevery token carries (<origin>/realms/<realm>) at both/auth/realms/…and/realms/…, so a standard OpenID Connect library accepts Kiban's tokens; the/realms/mount forwards Keycloak untouched, so a login started there completes - Zero-clone quickstart serves a real origin:
deploy/quickstart/compose.public.yaml(generated from the source overlay) sets the public issuer, Keycloak hostname,KIBAN_DOMAINandKIBAN_TRUSTED_PROXYfrom oneKIBAN_PUBLIC_HOST
0.1.0 — 2026-09-25¶
First public release, Apache-2.0. Kiban runs beside your app: the app registers its model and serves its own API; the sample modules are examples, off by default.
- Backend SDKs:
@rosschiu/kiban-sdk/server(Node),kiban-sdk(Python),github.com/rosschiu/kiban/sdk(Go): service token, user token verification, decisions, tuples, member lookup, app registration - Kiban repositioned as a service beside your app (OpenFGA-style): the app registers its model and serves its own API; the module runtime is the sample modules' in-tree path
KIBAN_EXTRA_ORIGINS: extra web origins and native (custom-scheme) redirect URIs forkiban-frontend, also on the gateway's CORS allow-list; a Flutter or second web app can log in- Apps register at runtime (
POST /api/platform/admin/apps, manifest with fragment, features and service client); an app's backend writes tuples on its own types and looks up members; a check names only a feature its module declares (one string, one feature) - Company, org-unit and member administration through the gateway (
/api/org/admin/units,/api/org/admin/members) - The four sample modules are optional:
COMPOSE_PROFILES=samplesandKIBAN_INSTALLED_MODULESbring them up; the default stack is the foundation only and the gateway no longer waits on them - Service credential:
KIBAN_SERVICE_CLIENTScreates confidential Keycloak clients whose client-credentials tokens the gateway accepts, for workers and connectors - Identity: embedded Keycloak, OpenID Connect with PKCE, MFA policy (authenticator app or passkey), bootstrap seeds the superadmin with a file-delivered password
- Organization: org-unit tree, members, positions and groups; company is the sole authorization anchor; cross-company facts are unrepresentable
- Authorization: Postgres-native Zanzibar-subset engine, differential-tested against OpenFGA; modules ship an authorization fragment
- Position- and group-based access: rights follow the position holder or group membership with zero permission edits
- Audit: every mutation writes an append-only audit row in the same transaction
- Module runtime: manifest, fragment, OpenAPI file, checksummed migrations; validated by
make validate-modules, routed by a version-blind gateway - Gateway: single origin, bearer-only
/api/*, CORS, security headers, request limits,/readyhealth - Sample modules: notification, docs (DocShare), helpdesk, timesheet
- SDK
@rosschiu/kiban-sdk: session with PKCE and refresh, API client, org and effective-access clients,canIand grant recipes - Sample shell: React, CSP enforced, company switcher, administration pages
- Platform role is one tuple (
system:platform#superadmin) with grant and revoke routes GET /api/platform/metricsaggregates every service's metrics for one scrape target- Postgres roles: non-superuser owner
kiban, per-service roles, secrets read from files - Containers run as uid 65532, read-only root, no capabilities; base images digest-pinned
- Compose is the supported deployment; Kubernetes manifests proven on kind only
- Coverage ratchet, OpenAPI response validation, licence and secret scans in
make check - Documentation site: quickstart, integrate, concepts, building, SDK guide, operating, security, limitations