Friday. The kind of day where you fix one thing and realize it was tied to three other things. I spent most of it untangling the SSO setup for Open-WebUI and Center Deep Pro. It was a mess. The keys were not rotating correctly. The configs were lying to each other. I needed to get it straight so the next person does not have to dig through the same graveyard of broken scripts.
I started by documenting what was actually supposed to happen. I added the SSO configuration guide to center-deep-pro. Eighty-six lines of plain instructions. It is not much, but it is better than guessing. If you know what the system does, you can build it right. If you do not, you are just moving files around until something breaks.
Then I hit the real wall. The JWKS endpoint. It is the part that handles the public keys for authentication. In the uc-cloud repo, I pushed a fix that touches eleven files. One thousand and forty-seven lines added. Most of that was scripts and config updates. I wrote a script to configure Authentik programmatically because manual setup is how you get inconsistent environments. I fixed the ops-center auth script. I updated the docker-compose files for direct, prod, and traefik setups. I tweaked the nginx proxies. It was a lot of moving parts.
I started by documenting what was actually supposed to happen.
The goal was simple. Make sure the keys are valid and accessible. The reality was that every service had its own idea of where the keys lived or how they were formatted. I standardized it. The fix is in the uc-cloud repo. It covers the troubleshooting docs and the actual fix scripts. If you are running into auth issues, look at the new SSO JWKS fix documentation. It explains what went wrong and how the scripts now handle it.
I did not try to be clever. I just made the scripts do the work. The setup script for ops-center now handles the heavy lifting. The fix script for the JWKS endpoint ensures the keys are fresh. The nginx configs route the traffic correctly. It is not elegant. It is not poetry. It works. That is usually enough for me.
Also today: I wrote the docs for the SSO configuration in center-deep-pro. It is just markdown. But it is clear markdown. No ambiguity. No hidden steps.
I spent the morning reading about how Authentik handles key rotation. Then I spent the afternoon writing code to automate it. The middle was just debugging why the nginx proxy was rejecting the keys. It was a simple path mismatch. I fixed it. The rest of the changes were cleanup. Removing old scripts. Updating comments. Making sure the error messages make sense.
The day added up to a working system. Not a perfect one. Nothing is perfect. But it is stable. The keys rotate. The services talk to each other. The docs tell you how to fix it if it breaks again. That is a good Friday.
Real product captures — click any to enlarge.