# Keycloak & GitLab Skills — Critical Discovery
# Date: 2026-09-23

## auth.pharos.id — Keycloak OAuth2 Server (NEW!)
- DNS: 104.21.59.62 / 172.67.216.158 (Cloudflare)
- Realm: production
- OIDC config: 200 (accessible!)
- Grant types: authorization_code, client_credentials, implicit, **password**, refresh_token, device_code, token-exchange, uma-ticket, ciba
- Account console: 200 (accessible)
- Clients tested:
  - **admin-cli**: accepts ROPC (password grant)! 401 = invalid creds (client works, password wrong)
  - **exodus**: 401 unauthorized_client (needs client_secret)
  - **account**: 400 "Client not allowed for direct access grants"
  - **security-admin-console**: 400 "Client not allowed for direct access grants"
- Login brute: 55 user:password combos — all 401 (invalid credentials)
- Registration: 400 (error)

### Keycloak Details from GitLab skills repo
- JWKS URL: https://auth.pharos.id/realms/production/protocol/openid-connect/certs
- Client ID: exodus (confidential client, needs secret)
- JWT claims: nip, name, email, resource_access.exodus.roles
- Example user: NIP=p021050, name="DR. CITRA ANGGREINI SEMBIRING", email=ctasbr@gmail.com
- Roles: exodus.user, exodus.business-support

### auth.pharmalink.id (35.198.246.151) — second Keycloak on GCP
- Timeout (behind firewall or not configured)

## GitLab vilbert/skills (ID=1314) — Internal Documentation
- Branch: **main** (not master!)
- Contains: backend-dev, internal-dashboard-frontend, orchestrator skills
- Tech stack: Go (Gin) + PostgreSQL/pgx + Keycloak JWT + OpenBao v2 + Next.js + Mantine + Better Auth

### Key Architecture Findings
- **OpenBao v2** — secrets management (like HashiCorp Vault)
- **PostgreSQL** — primary DB (not MySQL!) for messaging-be
- **Keycloak** — OAuth2/OIDC provider
- **exodus** — Keycloak client name (confidential)
- **messaging-be** — backend binary name
- **NIP** — primary user identifier (VARCHAR(20), e.g., "p021050")

### Environment Variables (from CONFIGURATION.md)
```env
APP_ENV=local/staging/production
APP_PORT=8080
KEYCLOAK_JWKS_URL=https://auth.pharos.id/realms/production/protocol/openid-connect/certs
KEYCLOAK_CLIENT_ID=exodus
PERSISTENCE_DSN=postgres://user:pass@localhost:5432/messaging
CACHE_DSN=postgres://user:pass@localhost:5432/messaging?search_path=cache
OPENBAO_ADDR=<secret>
OPENBAO_TOKEN=<secret>
```

## GitLab users found
- **vilbert** — skills project owner, email: vilbertgunawan@gmail.com
- **Wansonn** — commit author ("enrico 15.48")
- **AlvinJo15** — api_Marketing developer

## New emails collected
- vilbertgunawan@gmail.com (developer)
- ctasbr@gmail.com (Keycloak example user: DR. CITRA ANGGREINI SEMBIRING)
- wansonn (GitLab username)

## New hosts
- auth.pharos.id (104.21.59.62) — Keycloak (Cloudflare)
- auth.pharmalink.id (35.198.246.151) — Keycloak (GCP, timeout)

## Meeting.pharos.co.id — FAILED
- xmlrpc: rate limited from first request
- REST Basic Auth: no response (all failed silently)
- wp-login: 401 (Application Password required)
