Sign in

Florian

@rootd.ch
32 followers 10 following 93 posts

CEO & Co-Founder of @zitadel.com

PostsRepliesMedia
Florian @rootd.ch · 30/06/2026
I’ll leave it here. This is not accountability; it penalizes maintainers who disclose and fix issues by presenting registry lag as “unpatched.” That is misleading. Have a good day
000
Florian @rootd.ch · 30/06/2026
NVD’s CVE status model is an enrichment/analysis, not a global patched/unpatched truth state. The upstream advisories list patched versions. Your dashboard terminology turns registry lag into a damaging claim about maintainers. That is misleading.
100
Florian @rootd.ch · 30/06/2026
This is the conflation. “NVD/CPE remediation mapping pending” is not the same claim as “unpatched.”
100
Florian @rootd.ch · 30/06/2026
Do not turn “my compliance ingestion has not accepted remediation metadata yet” into “the maintainer has not patched.” That is the damaging part.
100
Florian @rootd.ch · 30/06/2026
I think this is damaging to multiple projects even if you do not realize it.
100
Florian @rootd.ch · 30/06/2026
A "compliance tool" can say “we only mark remediation as NVD-validated after NIST enrichment.” Fine. But publicly labeling the project “97% unpatched” when official advisories and NVD descriptions list fixed versions is misleading. That is not strict data integrity; it is a modeling/wording error.
100
Florian @rootd.ch · 30/06/2026
Honestly I disagree. You’re conflating three different states: NVD enrichment status, upstream patch availability, and whether a specific customer asset has been upgraded.
100
Florian @rootd.ch · 30/06/2026
Whatever, it’s misleading. You make projects look like having a bad security posture even though the have fixed things.
100
Florian @rootd.ch · 30/06/2026
I find this really weird and potentially damaging to multiple good and secure projects. Also it sound like I am chatting to Claude 🤣
100
Florian @rootd.ch · 30/06/2026
I leave this here because I still disagree with the wording These issues have been patched but you decided to not consume the data bsky.app/profile/root...
200
Florian @rootd.ch · 22/06/2026
Fair enough as an ingestion choice, but then labeling it “unpatched” is misleading. A patch is available from a trusted source and has been published. I leave it to you how to handle that, but the current wording gives people the wrong impression.
100
Florian @rootd.ch · 22/06/2026
The pending NVD assessment appears to be the NIST scoring/enrichment, not patch availability. If your product shows ‘unpatched’ until a separate NVD enrichment field exists, that seems like an ingestion limitation rather than the official status of the advisory.
100
Florian @rootd.ch · 22/06/2026
GitHub is the CNA/source here, not an unverified source 😆. The GitHub-reviewed advisory lists patched version 4.12.0. NVD also references that advisory as Patch/Vendor Advisory, states the issue is patched in 4.12.0, and has a CPE range up to but excluding 4.12.0.
100
Florian @rootd.ch · 22/06/2026
This is the NVD nvd.nist.gov/vuln/detail/...
nvd.nist.gov
NVD - CVE-2026-29191
100
Florian @rootd.ch · 22/06/2026
Which exact upstream field are you missing? GitHub advisory shows patched version 4.12.0, NVD says patched in 4.12.0, and the CVE List affected range is >=4.0.0, <4.12.0. Are you not parsing the bounded affected range, or is the GitHub Advisory API not returning patched_versions for this advisory?
100
Florian @rootd.ch · 22/06/2026
Your scoring looks weird how can something be not patched that was literally patched?😅 For example www.valtersit.com/cve/CVE-2026... This clearly was patched github.com/advisories/G... 😂
github.com
CVE-2026-29191 - GitHub Advisory Database
ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint
100
Florian @rootd.ch · 19/06/2026
I love to hear that you like @zitadel.com
000
Florian @rootd.ch · 10/03/2026
I am not sure I follow, what did we do wrong?
000
Florian @rootd.ch · 09/03/2026
Ubuntu just added a generic OIDC broker to AuthD. We can finally stop fighting SSSD and LDAP bridges for Linux machine auth. - Bypasses legacy PAM module complexity - Authenticate Ubuntu desktops/servers directly against @zitadel.com via standard OIDC ubuntu.com/blog/more-id...
ubuntu.com
Supporting more identity providers on Ubuntu with the new Authd OIDC broker | Ubuntu
Today we are announcing the general availability of the new generic OpenID Connect (OIDC) broker for Authd. With enterprises needing to centralise access management controls, the ability to choose you...
011
Florian @rootd.ch · 07/03/2026
That’s a great idea! I think we could adopt that as well
000
Florian @rootd.ch · 06/03/2026
Check the details here github.com/zitadel/zita... #OpenTelemetry #Golang #Auth #Opensource #NextJs
github.com
feat(login): added support for otel push-based logs, metrics, and traces by mridang · Pull Request #11429 · zitadel/zitadel
Closes #11471 Closes #11470 Which Problems Are Solved The login application lacked observability infrastructure. There was no distributed tracing, structured logging, or custom metrics, making it d...
020
Florian @rootd.ch · 06/03/2026
We also moved the Login App to structured JSON logging, automatically injecting trace IDs to correlate your logs. If you're running Jaeger or Honeycomb, your dashboards will actually map the full request lifecycle now.
100
Florian @rootd.ch · 06/03/2026
Two unrelated traces. We built a custom gRPC interceptor to propagate W3C traceparent headers directly to the backend. One request = one trace.
100
Florian @rootd.ch · 06/03/2026
Before this, the backend had OTel, but the Login UI was an observability black box. Your ingress would start a trace, the UI would drop the headers, and the backend would start a new one.
100
Florian @rootd.ch · 06/03/2026
Disconnected traces make debugging auth latency impossible. We just merged PR #11429 to bring end-to-end distributed tracing to @zitadel.com (might land in v4.13.0). 🧵
200
Florian @rootd.ch · 05/03/2026
github.com/trending/go?...
github.com
Build software better, together
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
000
Florian @rootd.ch · 05/03/2026
Thanks to the community for all the help and input, this truly helps us grow. github.com/zitadel/zita... #go #golang #opensource #identity #iam
github.com
GitHub - zitadel/zitadel: ZITADEL - Identity infrastructure, simplified for you.
ZITADEL - Identity infrastructure, simplified for you. - zitadel/zitadel
110
Florian @rootd.ch · 05/03/2026
Building an open-source IdP means being buried in OIDC/SAML specs, dealing with multi-tenant data isolation, and optimizing for security, usability and reliability. It's plumbing that only gets noticed when it breaks😆
github.com
GitHub - zitadel/zitadel: ZITADEL - Identity infrastructure, simplified for you.
ZITADEL - Identity infrastructure, simplified for you. - zitadel/zitadel
120
Florian @rootd.ch · 05/03/2026
It has been a while since I checked the @github.com trending repos report, but out of sheer interest I took a look today and it brought me a lot of joy to see @zitadel.com back on the daily Go list.
121
Reposted by Florian
selfhosting.sh @selfhostingsh.bsky.social · 04/03/2026
Zitadel is a modern identity provider with OIDC, SAML, and passkey support. Built for developers who need more than basic auth but don't want Keycloak's complexity. selfhosting.sh/apps/zitadel
011
Florian @rootd.ch · 04/03/2026
Auth is critical infrastructure, but setting it up locally shouldn't be a multi-day engineering ticket. It should be boring, predictable, and lightning-fast. If you want to test this cold-start speed yourself, grab the compose file and time it -> zitadel.com/docs/self-ho...
zitadel.com
Set up ZITADEL with Docker Compose | ZITADEL Docs
Deploy ZITADEL with Docker Compose — from a 2-minute localhost quickstart to a hardened homelab setup with TLS, caching, and observability.
000
Florian @rootd.ch · 04/03/2026
No heavy runtime to boot. No undocumented config files to debug. No massive YAML mazes (no worries you can go there if you want). Just a raw docker compose up -d. In under a minute, images are pulled, the DB is initialized, the Go API & Next.js UI are served, and I'm in.
100
Florian @rootd.ch · 04/03/2026
A little while ago, I talked about our commitment to radically improve @zitadel.com's developer experience. Today, I’m just showing a first result -> 42 seconds. ⏱️ That is the exact time it takes to go from an empty terminal to a fully operational identity stack. 🧵👇
100
Florian @rootd.ch · 04/03/2026
Thank you!
000
Florian @rootd.ch · 04/03/2026
I think we are going to settle a debate soon... 😆 ZITADEL vs Zitadel What do you prefer
000
Florian @rootd.ch · 04/03/2026
@zitadel.com v4.12.0 got published recently and my small, but favorit change is that we now also support end to end TLS for the new Login UI! github.com/zitadel/zita...
github.com
Release v4.12.0 · zitadel/zitadel
4.12.0 (2026-03-02) Bug Fixes added login_hint to the idp intent (#11552) (273863f), closes #11392 allow creating new invite code before previous is invalid (#11649) (ec7f8da), closes #9962 #9962 ...
000
Florian @rootd.ch · 03/03/2026
Great write up! Btw. we just improved our docker compose example to also include a traefik by default zitadel.com/docs/self-ho...
zitadel.com
Set up ZITADEL with Docker Compose | ZITADEL Docs
Deploy ZITADEL with Docker Compose — from a 2-minute localhost quickstart to a hardened homelab setup with TLS, caching, and observability.
100
Florian @rootd.ch · 03/03/2026
I love to read this! "Zitadel is the best modern alternative to Keycloak for self-hosted identity management..."
010
Florian @rootd.ch · 24/02/2026
We enable AI to understand our docs/data so it can handle the initial vetting, while we focus on the human parts: certified compliance, guaranteed SLAs, and CVE liability. Feed the AI the code. Pay the humans for the trust. 🐧🛡️ zitadel.com/blog/open-so...
zitadel.com
ZITADEL - Identity Infrastructure, Simplified
ZITADEL is the identity infrastructure platform that is built for developers and works for all users and applications.
000
Florian @rootd.ch · 24/02/2026
At @zitadel.com , we’re focusing on "Risk Transfer" as the product. The "Code or Contribution" model we started a year ago has only been confirmed by the rise of AI.
zitadel.com
ZITADEL - Identity Infrastructure, Simplified
ZITADEL is the identity infrastructure platform that is built for developers and works for all users and applications.
100
Florian @rootd.ch · 24/02/2026
The OSS funnel is evolving. 🏗️ AI is making architectural mapping and syntax a commodity. For infrastructure software, the real product is shifting from "how it works" to "who is responsible when it breaks."
zitadel.com
ZITADEL - Identity Infrastructure, Simplified
ZITADEL is the identity infrastructure platform that is built for developers and works for all users and applications.
110
Florian @rootd.ch · 16/02/2026
We need eyes on the spec. If you run a distributed setup, does this syntax make sense to you? github.com/zitadel/zita... #OpenTelemetry #DevOps #Golang #OpenSource
github.com
🛠 Beta: Better Error Logging & GCP Support · zitadel zitadel · Discussion #11598
We’ve all been there, debugging a generic 500 error is a nightmare. To fix this, we’ve updated how ZITADEL handles logging so you actually have the context to resolve the issue the moment it appear...
010
Florian @rootd.ch · 16/02/2026
Identity infrastructure shouldn't be a black box. 🔭 We're rolling out a new OpenTelemetry (OTel) configuration for the @zitadel.com API. The goal: cleaner traces, better propagation, and less friction for your collectors (Jaeger, Honeycomb, etc.).
111
Florian @rootd.ch · 13/02/2026
We love to hear this! We made a conscious choice to give everyone the option to own their login UI and not hide something like this behind the pricing 😎
010
Florian @rootd.ch · 13/02/2026
We now support 3 connectors for our Go-based API: - Redis (K8s standard) - Postgres (Simple & robust, 30k+ RPS) - In-Memory (Fast, but beware of sticky sessions!) Read the full blog: zitadel.com/blog/scaling... #golang #systemdesign #opensource #auth
020
Florian @rootd.ch · 13/02/2026
Identity in can be an "N-over-N" problem. Resolving Instance -> Org -> User for every request hits hard in B2B SaaS. 📉 We engineered a new caching strategy for @zitadel.com to flatten this hierarchy, decoupling read performance from DB complexity. ⚡
130
Florian @rootd.ch · 10/02/2026
Ah I see, we can not do that yet natively in the login UI, but you can add to your own UI a check for that by creating a session. So in essence your UI can ask the user for a OTP prompt. zitadel.com/docs/referen...
zitadel.com
CreateSession
110
Florian @rootd.ch · 09/02/2026
You can already configure a different lifetime for MFA if that helps zitadel.com/docs/guides/...
zitadel.com
ZITADEL Default Settings
000
Florian @rootd.ch · 09/02/2026
Can you give me a rinse down what you need? Happy to give pointers from there
100
Florian @rootd.ch · 09/02/2026
Right now our login ui does not provide step-up per se. But when you build your own login ui with the session api you are 100% capable to do that. Happy to elaborate more, if it helps
210