chore(iam): point IAM issuer to iam-serve.stuffle.io
All checks were successful
Stuffle/agos-client/pipeline/head This commit looks good

Switch VITE_IAM_ISSUER / prod issuer default from iam.armco.dev to the
firewall-friendly .io alias iam-serve.stuffle.io.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
2026-10-08 18:19:33 +05:30
parent e64f0b79fb
commit 2ed2524ccd
5 changed files with 7 additions and 7 deletions

View File

@@ -22,7 +22,7 @@ VITE_API_URL=http://localhost:2000 # local | prod: https://agos.armco.dev
# VITE_BACKEND_AI_MODE=true
# ── Armco IAM ─────────────────────────────────────────────────────────────────
# IAM is deployed at https://iam.armco.dev
# IAM is deployed at https://iam-serve.stuffle.io
# Issuer claim in JWTs: stuffle-iam | Audience for AGOS API: stuffle-api
#
# Client ID selection uses TWO axes (resolved automatically in iam.ts):
@@ -36,7 +36,7 @@ VITE_API_URL=http://localhost:2000 # local | prod: https://agos.armco.dev
#
# Set VITE_IAM_PROVIDER_ENV to select which IAM server to talk to:
# "local" → http://localhost:5000 (for local IAM dev)
# "prod" → https://iam.armco.dev (default when unset)
# "prod" → https://iam-serve.stuffle.io (default when unset)
VITE_IAM_PROVIDER_ENV=prod
VITE_IAM_AUDIENCE=stuffle-api
# Optional when IAM expects OAuth resource indicators in addition to audience.

View File

@@ -1,7 +1,7 @@
# ── Production environment ─────────────────────────────────────────────────────
VITE_PORT=3000
VITE_API_URL=https://agos.armco.dev
VITE_IAM_ISSUER=https://iam.armco.dev
VITE_IAM_ISSUER=https://iam-serve.stuffle.io
VITE_IAM_AUDIENCE=stuffle-api
VITE_IAM_DESKTOP_CLIENT_ID=client_6a243d0c127843ff8f2f2a28a486638f
VITE_IAM_DESKTOP_REDIRECT_URI=app://bundle/callback

View File

@@ -11,7 +11,7 @@ COPY . ./
ARG VITE_PORT=3000
ARG VITE_APP_ENV=production
ARG VITE_API_URL=https://agos.armco.dev
ARG VITE_IAM_ISSUER=https://iam.armco.dev
ARG VITE_IAM_ISSUER=https://iam-serve.stuffle.io
ARG VITE_IAM_CLIENT_ID=client_2dbeb454ddf14203b092eb4636a8e3d7
ARG VITE_IAM_AUDIENCE=stuffle-api
ARG VITE_IAM_RESOURCE=

View File

@@ -3,7 +3,7 @@
*
* Config env vars (set in .env.local for dev, .env.production for prod):
* VITE_IAM_PROVIDER_ENV — "local" → http://localhost:5000 (local IAM dev server)
* "prod" or unset → https://iam.armco.dev (default)
* "prod" or unset → https://iam-serve.stuffle.io (default)
* VITE_IAM_AUDIENCE — token audience (default: stuffle-api)
*
* Issuer and client_id are resolved from VITE_IAM_PROVIDER_ENV; no need to
@@ -23,7 +23,7 @@ import { recordAuthTelemetry } from './authTelemetry'
// ── IAM issuer lookup (which IAM server) ────────────────────────────────────
const _IAM_ISSUERS = {
local: 'http://localhost:5000',
prod: 'https://iam.armco.dev',
prod: 'https://iam-serve.stuffle.io',
} as const
// ── Client ID matrix: [iamEnv][agosEnv] ─────────────────────────────────────

View File

@@ -440,7 +440,7 @@ function AuthDocs() {
<div className="ne-DocSectionLabel">Enabling Armco IAM (built-in)</div>
<ul className="ne-DocList">
<li>Set <code>IAM_AUTH_ENABLED=true</code> in your environment.</li>
<li>Set <code>IAM_ISSUER</code> to your IAM base URL (e.g. <code>https://iam.armco.dev</code>).</li>
<li>Set <code>IAM_ISSUER</code> to your IAM base URL (e.g. <code>https://iam-serve.stuffle.io</code>).</li>
<li>Set <code>IAM_AUDIENCE</code> to the registered agOS client ID.</li>
<li>Optionally set <code>IAM_TOKEN_ISSUER</code> and <code>IAM_JWKS_CACHE_TTL</code>.</li>
<li>On the frontend set <code>VITE_IAM_ISSUER</code> and <code>VITE_IAM_CLIENT_ID</code>.</li>