Weekly chapter30
2025-W38 · ending September 19, 2025· September 2025 chapter ↗

Fixing the keys before the weekend

The week was quiet until it wasn't. I only logged activity on Friday, September 19. That single day carried the weight of the entire week because it was the day I finally stopped guessing and started fixing.…

3commits2systems4min read
Product capture

Unicorn Commander — end-user dashboard.

The week was quiet until it wasn't. I only logged activity on Friday, September 19. That single day carried the weight of the entire week because it was the day I finally stopped guessing and started fixing. The goal was simple: untangle the SSO setup for Open-WebUI and Center Deep Pro. What started as a quick check-in turned into a deep dive into authentication, key rotation, and the messy reality of distributed systems.

I started the day by looking at the mess. The keys were not rotating correctly. The configs were lying to each other. It is a common problem. You build something, it works once, and then you forget how it actually holds itself together. I needed to get it straight so the next person does not have to dig through the same graveyard of broken scripts. I spent the first few hours documenting what was actually supposed to happen. I added the SSO configuration guide to the center-deep-pro repository. It was eighty-six lines of plain instructions. It is not much code, but it is better than guessing. If you know what the system does, you can build it right. If you do not, you are just moving files around until something breaks.

Then I hit the real wall. The JWKS endpoint. This is the part that handles the public keys for authentication. It is supposed to be straightforward, but in practice, every service had its own idea of where the keys lived or how they were formatted. I needed to standardize it. I pushed a fix to the uc-cloud repo that touched eleven files. One thousand and forty-seven lines added. Most of that was scripts and config updates. I wrote a script to configure Authentik programmatically because manual setup is how you get inconsistent environments. I fixed the ops-center auth script. I updated the docker-compose files for direct, prod, and traefik setups. I tweaked the nginx proxies. It was a lot of moving parts.

I needed to get it straight so the next person does not have to dig through the same graveyard of broken scripts.

The work was not elegant. It was not poetry. It was just making the scripts do the work. The setup script for ops-center now handles the heavy lifting. The fix script for the JWKS endpoint ensures the keys are fresh. The nginx configs route the traffic correctly. I spent the morning reading about how Authentik handles key rotation. Then I spent the afternoon writing code to automate it. The middle was just debugging why the nginx proxy was rejecting the keys. It was a simple path mismatch. I fixed it. The rest of the changes were cleanup. Removing old scripts. Updating comments. Making sure the error messages make sense.

I did not try to be clever. I just made the system stable. The keys rotate. The services talk to each other. The docs tell you how to fix it if it breaks again. That is a good Friday. The week added up to a working system, not a perfect one. Nothing is perfect. But it is stable.

Looking back at the FACTS block, it is interesting to see how a week can be defined by a single day. Three commits across two repositories. center-deep-pro got the documentation. uc-cloud got the code. The movement in the week was not about adding new features. It was about removing friction. The friction was in the authentication layer. The friction was in the lack of clear instructions. By fixing the JWKS endpoint and writing the docs, I removed that friction.

The dry humor of the week is that I spent most of Friday fixing a path mismatch. A simple path mismatch. The kind of thing that should have been caught in the first hour. But it is not about being smart. It is about being thorough. The scripts now handle the key rotation. The nginx configs are correct. The documentation is clear. That is the win.

The week landed where it needed to. The keys are valid. The services are connected. The docs are there for reference. It is a good result. I am not claiming this is the end of the story for SSO. There will always be more to fix. But for this week, this is the story. The arc was from confusion to clarity. From broken scripts to working code. From guessing to knowing.

That is the build log for week 2025-W38. It was a short week in terms of days, but heavy in terms of impact. The focus was on stability and clarity. The result is a system that is easier to maintain and easier to understand. That is enough for me. I will see you next week.

Also in the frame

Real product captures — click any to enlarge.

center deep
uc cloud
uc cloud
07 / Activity

The week, in commits.

Daily velocity and the systems that carried the work.

·Mon15
·Tue16
·Wed17
·Thu18
4Fri19
·Sat20
·Sun21
Week beginning September 15, 2025.
Index

2 systems,
one week of work.

center-deep-prouc-cloud