Skip to content

v0.11.0

Release Date: 2026-10-02

Finishes the CoreForge→SystemForge rename that v0.10.0's module-path move began: the Core-era names are retired. Hard cutover, no dual-name compatibility — no consumer app has shipped yet, so this is the cheapest it will ever be to do (see ADR-001).

Highlights

  • coreauth → systemauth — the identity/auth server package, binary, bootstrap user, JWKS key id, env var, and observability metric namespace all rename; the parallel CoreControl naming (contract/, multiapp/, identity/oauthclient) is retired in favor of the same name.
  • cf_ table prefix → sf_ — all 26 identity tables, via the Ent schema annotations; rls.SystemForgeTables updated to match.
  • API-key visible prefix cf_ → sf_ — newly issued keys read sf_live_…/sf_test_….
  • Unified cross-app principal-link field: sf_principal_id — PrincipalMixin's field (consumed by every downstream app that embeds it) replaces the divergent core_control_principal_id / core_auth_principal_id spelling.

Breaking Changes

Service renamed coreauth → systemauth

// Old
import "github.com/plexusone/systemforge/identity/coreauth"

// New
import "github.com/plexusone/systemforge/identity/systemauth"

The binary is now systemauth (was coreauth); the bootstrap user is system@systemauth.local; the JWKS key id is systemauth-1; the config env var is SYSTEMAUTH_SECRET; observability metrics/spans are under the systemauth.* namespace. CoreControlConfig and related types in identity/oauthclient are now SystemAuthConfig, etc.

Table prefix cf_ → sf_

Every identity table is renamed, e.g. cf_principals → sf_principals, cf_oauth_tokens → sf_oauth_tokens. No production data exists at the old prefix. An existing Postgres dev database with cf_* data can be migrated in place with migrations/0001_rename_cf_to_sf.sql; a fresh database needs no migration — just run systemauth migrate.

API-key prefix cf_ → sf_

identity/apikey.DefaultPrefix and the legacy identity/credential.APIKeyPrefix both move from cf_/cf_ to sf_/sf_. Newly issued keys carry the new prefix; any dev-issued cf_-prefixed key must be reissued.

PrincipalMixin's SSO-federation link field — embedded by every app that uses the Principal model — is now sf_principal_id. Consumers previously on core_control_principal_id or core_auth_principal_id rename their column and regenerate Ent.

Documentation

  • README.md's Database Tables and Migration Strategy sections updated to sf_*.
  • A CI grep gate blocks any new cf_/coreauth/corecontrol/core_control/core_auth occurrence from landing again.

What's Next

Consumer convergence: systemforge-web, dashforge, academyos, and proofminds-web each adopt sf_/systemauth/sf_principal_id and bump to this release before any of them ships.