6479d35fb8
Rolls up sso-manager-node v1.29.0, theta-agent v1.4.0, proxy v1.34.0 and jump-host v1.19.0. Per-host SSO returned "400 redirect_uri is not registered for this client". The bootstrap registered only the proxy's own management callback, but per-host SSO calls back to https://<protected-host>/__proxy_auth/callback -- a different URL per proxied host, all against that one OAuth client. Now registers the wildcard + apex patterns, and backfills them onto existing clients so upgraded stacks are fixed too. theta-proxy and theta-jump were seeded as hosts and then left childless while their services hung off the stack host. Services now parent to the host that runs them; reparent() corrects existing installs, but only when the current parent is the one the old code set. The proxy gets a read-only SSO API token (minted before the OpenBao snapshot so the running proxy receives it) backing the per-host SSO group autocomplete, and the sso-broker policy grants secret/agent/* for the SSO's persistent theta-agent signing key. BREAKING: theta-agents must be re-enrolled, and ./setup.sh must be re-run for the new OpenBao grant. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>