v0.11.0¶
Release Date: 2026-10-02
Finishes the CoreForge→SystemForge rename that v0.10.0's module-path move began: the Core-era names are retired. Hard cutover, no dual-name compatibility — no consumer app has shipped yet, so this is the cheapest it will ever be to do (see ADR-001).
Highlights¶
coreauth→systemauth— the identity/auth server package, binary, bootstrap user, JWKS key id, env var, and observability metric namespace all rename; the parallelCoreControlnaming (contract/,multiapp/,identity/oauthclient) is retired in favor of the same name.cf_table prefix →sf_— all 26 identity tables, via the Ent schema annotations;rls.SystemForgeTablesupdated to match.- API-key visible prefix
cf_→sf_— newly issued keys readsf_live_…/sf_test_…. - Unified cross-app principal-link field:
sf_principal_id—PrincipalMixin's field (consumed by every downstream app that embeds it) replaces the divergentcore_control_principal_id/core_auth_principal_idspelling.
Breaking Changes¶
Service renamed coreauth → systemauth¶
// Old
import "github.com/plexusone/systemforge/identity/coreauth"
// New
import "github.com/plexusone/systemforge/identity/systemauth"
The binary is now systemauth (was coreauth); the bootstrap user is system@systemauth.local; the JWKS key id is systemauth-1; the config env var is SYSTEMAUTH_SECRET; observability metrics/spans are under the systemauth.* namespace. CoreControlConfig and related types in identity/oauthclient are now SystemAuthConfig, etc.
Table prefix cf_ → sf_¶
Every identity table is renamed, e.g. cf_principals → sf_principals, cf_oauth_tokens → sf_oauth_tokens. No production data exists at the old prefix. An existing Postgres dev database with cf_* data can be migrated in place with migrations/0001_rename_cf_to_sf.sql; a fresh database needs no migration — just run systemauth migrate.
API-key prefix cf_ → sf_¶
identity/apikey.DefaultPrefix and the legacy identity/credential.APIKeyPrefix both move from cf_/cf_ to sf_/sf_. Newly issued keys carry the new prefix; any dev-issued cf_-prefixed key must be reissued.
Principal-link field renamed to sf_principal_id¶
PrincipalMixin's SSO-federation link field — embedded by every app that uses the Principal model — is now sf_principal_id. Consumers previously on core_control_principal_id or core_auth_principal_id rename their column and regenerate Ent.
Documentation¶
README.md's Database Tables and Migration Strategy sections updated tosf_*.- A CI grep gate blocks any new
cf_/coreauth/corecontrol/core_control/core_authoccurrence from landing again.
What's Next¶
Consumer convergence: systemforge-web, dashforge, academyos, and proofminds-web each adopt sf_/systemauth/sf_principal_id and bump to this release before any of them ships.