01 / The lock you inherit
You do not choose your auth. You inherit everyone else’s.
This week I deployed a piece of open-source software onto a server I run. It went well, in the way these things go well. The container came up, the health check passed, the certificate issued, the reverse proxy took traffic on the first reload. Everything I could point at was green.
Then I read the front end, and found that every page in the product is gated behind one identity provider. Not configurably. One import, at the top of one file, and a middleware that redirects anything without a session. There was no username-and-password option, no trusted-header bypass, no flag to turn it off for a private network. I checked for all three, because I did not believe it the first time.
That is not a bug and nobody did anything wrong. It is a decision somebody made in the first week of the project, when it was the smallest decision on the board, and it quietly became the shape of the product. My options were to adopt their choice or to fork the thing and own the fork forever.
This is the part people get wrong about identity. You do not choose your auth once, at the start, on your own terms. You inherit somebody else’s choice every time you adopt anything — and each one of those inherited choices has to be reconciled with the ones you already live with.
03 / The one nobody expects
Being locked out is loud. Being let in is quiet.
The failure everyone plans for is being locked out. It is loud, it is immediate, and somebody complains within a minute. In practice it is the cheap one.
The expensive failure is being let in. A missing secret usually fails hard and gets fixed the same hour. A permissive default fails silently, and from the outside it looks exactly like everything working — which it is, for the wrong people.
The hardest incident I have had to explain to a room was not a service that was down. It was a service that was up, healthy, fast, and answering honestly to anyone who found it. Every dashboard was green. Every dashboard was measuring the wrong thing.
You cannot get to confidence here by clicking around your own product, because you are always allowed. Your session is warm, your email is on the list, your browser has the cookie. The only test that means anything is the one you run as a stranger.