Nobody should log in manually. The job disables the local strategy as its final step (with a still-valid JWT), so the login page offers only Authentik OIDC. Re-runs without a DB reset find local disabled -> login returns None -> the job exits cleanly (already configured). Break-glass = DB reset (finalize re-enables local). Verified live: local login is BLOCKED after the run.