Release Notes
Track notable changes here. Keep entries newest-first, grouped by component, following Keep a Changelog conventions.
Unreleased
Section titled “Unreleased”- Documentation updated for the Keycloak migration: identity pages rewritten around the shared
bluedotsrealm, added a Keycloak Realm Reference and a Keycloak Setup guide, and corrected the architecture and infrastructure diagrams. - Initial documentation site published with Astro + Starlight: Overview, Core Concepts (Architecture + Technical), Guides, Explore and Community sections.
Signals DPG
Section titled “Signals DPG”- Version marker: Keycloak is the recommended identity provider as of the
GA-2026-08-18release of both DPGs. Instances provisioned earlier run the legacy better-auth path;AUTH_PROVIDERstill defaults tobetterauth, so a current-release instance also stays on the legacy path until explicitly switched. Migration is an operator-run cutover — see Keycloak Setup. - Changed: identity moved to Keycloak. Browser logins use the OIDC authorization-code flow against a Keycloak-hosted login screen; integrating DPGs authenticate with client-credentials service tokens.
- Added: audience and role gating on incoming tokens —
KEYCLOAK_ACCEPTED_CLIENT_IDS,KEYCLOAK_SERVICE_CLIENT_IDS(empty by default) andKEYCLOAK_REQUIRED_REALM_ROLES. - Added:
ACTING_ORG_SOURCElets thex-acting-org-idheader be checked against the token’ssignals_acting_orgsgrant instead of being trusted outright.
Aggregator DPG
Section titled “Aggregator DPG”- Changed: the Keycloak realm is no longer the fixed
aggregator. It is now named per network viaKEYCLOAK_REALM(e.g.bluedots,yellowdots) and is shared with Signals, so one identity works across both verticals. - Changed: the custom Keycloak server image is now built and released from
bluedots-automationrather than this repo; the per-network login theme image is still built here. - Note: protocol mappers (
aggregator_id,aggregator_type,phone_number,signalstack_org_id) ship in the realm import and no longer need to be added by hand after a fresh import.
Template for a release
Section titled “Template for a release”## [x.y.z] — YYYY-MM-DD
### Added- ...
### Changed- ...
### Fixed- ...
### Removed- ...
