Incident Management Platform · View 33 of 34 · 7 · Assurance
Decisions
- Keycloak brokers the corporate identity provider for normal logins and holds a small set of local break-glass accounts, each bound to a registered hardware key. Keycloak runs in the control plane, which is the only thing a console login needs (ADR-26).
- Break-glass sessions last four hours and carry a responder role: acknowledge, resolve, change severity, post updates. Schedule, policy and suppression edits are unavailable, because those can wait for the identity provider and are the most damaging in the wrong hands.
- Every break-glass login notifies the security rotation. It does not page them; the event is expected during an identity outage and suspicious outside one.
Accounts
- About a dozen, held by on-call leads across the three timezones, each with two registered keys. Accounts are reviewed quarterly and exercised in the same drill as the control-plane rebuild.
Not needed for paging
- Nothing on the paging path uses Keycloak or the corporate identity provider. Acknowledgement by keypress, SMS reply or app works throughout an identity outage.