Skip to content

Bind workspace access to user identity and harden lease lifecycle - #31

Merged
Paul Lizer (paullizer) merged 1 commit into
paullizer-frontend-tailwind-migrationfrom
paullizer-broker-authorization
Sep 23, 2026
Merged

Paul Lizer (paullizer) merged 1 commit into
paullizer-frontend-tailwind-migrationfrom
paullizer-broker-authorization

Conversation

@paullizer

Copy link
Copy Markdown
Collaborator

Workspace credentials must belong to the signed-in user, and administration must be separate from workspace access. This change enforces those boundaries while retaining local Linux accounts, persistent NFS profiles, and the reconnect workflow.

Approach

  • Replace interchangeable scope/role/group authorization with verified user and workload policies. Bind users to stable Linux usernames/UIDs and leases, and bind workload identities to trusted host inventory.
  • Add a per-user MSAL/WAM Windows launcher with silent authentication and interactive fallback. Preserve RDP and user-scoped Credential Manager integration without using the shared host identity for checkout.
  • Make the portal administrator-only and remove credential checkout/impersonation. Enforce capabilities in the BFF and broker, not just the UI.
  • Fence provisioning, reconnect, reclamation, and scaling with durable SQL operations and host-side guards. Preserve desktops during the grace period, retain NFS profiles, and make hosts available only after confirmed cleanup. Support both legacy and modern Linux reconnect gates.
  • Wire reviewed identity migration, trusted ARM re-enrollment, a dedicated least-privilege SQL runtime user, versioned launcher/runtime artifacts, and fail-closed rollout procedures.

Migration and rollout

This is a coordinated API, schema, launcher, and agent upgrade. Apply migrations 040 through 046, verify existing user/profile mappings, and re-import/re-enroll every intended host. Migration 046 deliberately invalidates older hostname-only trust. Old machine-token checkout and unguarded lifecycle callers are not retained as compatibility fallbacks.

Fresh deployment and migration finish with checkout paused. Existing unenrolled legacy XRDP services require a controlled drain before startup enrollment; active desktops are not forcibly restarted. See deploy/DEPLOYMENT.md for sequencing and recovery.

No Azure deployment or live acceptance pilot was performed. Actual WAM/AVD sign-in, native RHEL/XRDP behavior, NFS preservation, and workload managed-identity/SCM readiness must be validated in an authorized pilot before activation.

Validation

  • Python 3.13 with pinned dependencies: 551 API tests and 369 portal tests; real signed-JWT broker/BFF HTTP integration passed.
  • 183 React tests, TypeScript checks, and production build passed.
  • 175 Windows launcher tests, warning-free build, and self-contained package verification passed.
  • 100 safe Linux lifecycle tests and 84 Linux deployment fixtures passed; offline PowerShell deployment checks and Bicep compilation passed.
  • Real isolated SQL: 17 integration cases, 12 synchronized transaction races, and contained runtime-user creation, rotation, login, and permission checks passed. Disposable SQL resources were cleaned up.

Adds CI coverage for these offline checks without deploying infrastructure.

Separate workspace, administrator, and workload authorization; add per-user WAM authentication; fence lease provisioning and cleanup; and coordinate fail-closed deployment and profile-preserving migration.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paullizer
Paul Lizer (paullizer) merged commit 02a5297 into paullizer-frontend-tailwind-migration Sep 23, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant