verae-staff-iam/README.md

1.2 KiB

verae-staff-iam

Named internal staff accounts with roles and permissions. Source of truth for who may use CS, sales, accounting, the staff plane, the operator console, and the billing admin console.

Forgejo: https://git.georgelambert.org/marchon/verae-staff-iam

Port :3028. UI: sign-in, people, roles, audit.

Seed lab users

Username Password Roles
admin admin-dev-key owner (all)
cs cs-dev-key cs
sales sales-dev-key sales
accounting acct-dev-key accounting
operator fleet-dev-key operator

Override with IAM_OWNER_PASSWORD, IAM_CS_PASSWORD, etc. Persist: STAFF_IAM_PATH (users, audit, sessions). Login is rate-limited (8 failures / 10 minutes / IP+username). JSON APIs return 401/403; HTML doors 302 to /login.

Wire other doors

STAFF_IAM_URL=http://127.0.0.1:3028
STAFF_AUTH=1   # department HTML still redirects if check fails

GET /check?permission=cs.credit — cookie or Authorization: Bearer. Cookie name remains staff_session. Multi-host: STAFF_COOKIE_DOMAIN.

Roles

owner, iam-admin, billing-admin, cs, sales, accounting, operator, viewer. Permissions are listed on /roles.