/ test (pull_request) Successful in 7s
Add a shared public client `forte-cli` to the `forte` realm so downloaded skills (forte-drop first) can do RFC 8628 device-code login through the Auth Sidecar. Today no client in the realm has the device grant enabled, so the flow cannot start. Client (inline in forte-realm.json, imported verbatim by keycloak-config-cli): - publicClient: true, standardFlowEnabled: false, directAccessGrantsEnabled: false - attributes: oauth2.device.authorization.grant.enabled=true - no secret, no redirectUris/webOrigins, no k8s.secret.sync It has to go in the realm JSON because the self-service registrar hardcodes publicClient:false/standardFlowEnabled:true and drops attributes. Also add forte-cli to the cleanup CronJob's protected list (belt-and-braces; it does not match the UUID pattern anyway). Additive only: gitea/grafana/argocd and all other realm settings are unchanged. Keycloak is deployed only via the upc-dev overlay, which inherits base values, so this lands on id.forteapps.net. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QciXev3MtCxo3eomcfrDRW