Habr•August 27, 2026•🇷🇺Translated from Russian

redb.Identity Adds gRPC Transport for OpenID Server Alongside Existing HTTP Facade

redb.Identity has added a gRPC facade to its OpenID server, placing it alongside the existing HTTP transport on the same core routes. The server remains transport-agnostic: all authorization logic resides behind direct-vm://identity-* addresses, and both HTTP and gRPC now act as interchangeable facades over this kernel.

The new surface implements the protocol operations required by relying parties: Token at /identity.v1.Identity/Token (RFC 6749 §3.2), Introspect (RFC 7662), Revoke (RFC 7009), UserInfo (OIDC Core §5.3), Discovery, and Jwks (RFC 7517). A gRPC health check is also exposed via grpc.health.v1.Health/Check. Forty administrative operations across five services (Users, Applications, Groups, Scopes, Tokens) are available on a dedicated management port.

Requests accept the same key-value pairs defined by the RFCs plus a map<string, string> for extensions. Responses type the fields fixed by the specifications and place open sets such as claims into google.protobuf.Struct. OAuth errors are returned as gRPC status codes (UNAUTHENTICATED, PERMISSION_DENIED, RESOURCE_EXHAUSTED, INVALID_ARGUMENT) with the original error code and correlation identifier carried in trailers.

The same token issued through dynamic client registration over HTTP is accepted by the gRPC endpoint and yields identical authorization decisions. Scope evaluation occurs once inside the kernel at direct-vm://identity-authz-check, eliminating the risk of divergent policy between transports.

Browser flows (authorize, login, consent, MFA), DPoP proofs (RFC 9449), and user self-service remain exclusively on HTTP. The gRPC listener uses its own port because it requires HTTP/2 while the HTTP facade supports both HTTP/1.1 and HTTP/2.

Configuration is placed in the shared context.json under the identity.grpc section, allowing independent host, port, TLS, and compression settings. The EmitHttpCompatHeaders flag is enabled by default to preserve IP-based rate limiting and device metadata collection.

Related articles

AntiMalware•Other

Bureau 1440 Unveils Satellite Internet Terminals Reaching 700 Mbps for Industrial and Rail Use

Bureau 1440 presented three satellite terminal models at the Digital Solutions forum in Russia. The 1440 ULTRA model supports data speeds up to 700 Mbps and is designed for remote industrial sites and infrastructure, operating both stationary and in motion. The company reduced the terminal's weight by 30 percent while maintaining 600 by 600 mm dimensions and adding IP67 dust and water protection. The 1440 ZEMLYA variant is already undergoing tests on Russian Railways trains, including Lastochka and Sapsan services, and is rated for operation at speeds up to 400 km/h. A compact 1440 MINI concept aims for around 100 Mbps in a 300 by 300 mm portable form factor intended for rescue teams and expeditions. All models are being developed alongside the company's low-orbit satellite constellation, with test connections already active on rail lines and in remote settlements. Sales have not yet begun, and the company will announce availability separately while noting that maximum speeds are not guaranteed in every environment.

AntiMalware•Other

GTA V Unofficial Browser Port Runs Locally via WebAssembly Using Leaked Rockstar Sources

Enthusiasts created an unofficial port of GTA V that executes the game directly in the browser through WebAssembly without any cloud streaming. The project compiled the original RAGE engine to wasm64 and built a compatibility layer translating DirectX 11 calls to WebGPU. Game assets were served over HTTP while JavaScript handled input and saves, and AudioWorklet managed audio. The port retained Euphoria physics and Scaleform interfaces but removed Bink video playback. Requirements ranged from 3 to 16 GB of RAM, supporting both story mode and free roam. The site was taken offline shortly after launch, first displaying a thank-you message and later redirecting to adult content. Analysis of the build confirmed debug symbols and developer file paths consistent with leaked Rockstar source code.

Habr•Other

PKI Storm: Managing 100,000 Simultaneous Certificate Requests in Kubernetes Recovery Scenarios

A large organization's PKI infrastructure faced a critical bottleneck when a data center outage triggered simultaneous startup of tens of thousands of Kubernetes pods, each requiring mTLS certificates. The existing setup using ESAUS and Citadel routed all requests through external certificate authorities that could only sustain 50-70 RPS against an incoming burst of 100,000 requests. Average daily load of 10-11 RPS had masked the thundering herd risk during mass recovery. Scaling the CA 15x was rejected due to cost and the fundamental dependency on real-time signing. The team introduced pre-issuance of certificates stored in a dedicated Unified Secret Storage (ЕХС) layer that supports 14,000 RPS reads while the CA continues normal operation. This architectural separation of issuance and consumption reduced recovery time from nearly 24 minutes to seconds while shifting focus to secure secret lifecycle management including KRA key protection.

AntiMalware•Other

MinTsifry Considers Annual 10 Billion Rubles Support Package for Russian AI Development

Russia's Ministry of Digital Development is discussing a state support package worth up to 10 billion rubles per year aimed at local AI developers. The proposed funding would cover technology development, pilot launches, and compensation for computing resources. According to Kommersant, 8 billion rubles are planned for development and implementation while 2 billion would offset computational costs. Mechanisms under consideration include subsidized loans through authorized banks and grants covering up to 80 percent of pilot project costs in priority sectors. The initiative remains in discussion with no final parameters or launch timelines confirmed yet. Industry experts note that clear selection criteria and transparent reporting will be essential to prevent intermediaries and ensure fair access for independent teams.