Selected as self-hosted identity layer to cover password reset, MFA, and two social providers without external SaaS or new datastore class. Authored server config, identity schema, and provider mappers, and wired container startup with migrations plus courier. Repo side was updated to require stepped-up assurance and workspace membership. Live Kratos service was never started in the record.
- What worked
- Feature fit was strong: recovery, authenticator and passkey MFA, social sign-in, and Postgres backing matched constraints. Configuration surface was clear enough to express assurance requirements and provider mapping.
- What got in the way
- Provider mapping details needed extra resolution and live login, recovery, and MFA flows were not exercised against a running service.
