2026-09-22 19:06:31 +02:00
|
|
|
# Copy to .env and fill in. Everything rendered from this (nats.conf,
|
|
|
|
|
# kanidm/server.toml, portal.env) is gitignored.
|
|
|
|
|
|
|
|
|
|
# Where the site and the identity provider are served. Both need an A
|
|
|
|
|
# record pointing at this host before the first start (Caddy gets the
|
|
|
|
|
# certificates over HTTP-01). tomtervel.no itself stays where it is
|
|
|
|
|
# until the vel decides to point the apex here.
|
2026-09-28 20:37:07 +02:00
|
|
|
PORTAL_HOST=vel.klingenbergbygg.no
|
|
|
|
|
ID_HOST=id.vel.klingenbergbygg.no
|
2026-09-22 19:06:31 +02:00
|
|
|
|
|
|
|
|
# The portal version to run: a tag of https://project.uhhm.no/uhhm/portal
|
2026-09-30 14:12:24 +02:00
|
|
|
PORTAL_RELEASE=v0.5.10
|
2026-09-22 19:06:31 +02:00
|
|
|
|
|
|
|
|
# The content this instance serves, and reloads live on every push.
|
|
|
|
|
CONTENT_REPO=https://prosjekt.klingenbergbygg.no/tomtervel/questions
|
|
|
|
|
CONTENT_BRANCH=main
|
2026-09-29 15:45:41 +02:00
|
|
|
SITE_NAME="Tomter Vel"
|
2026-09-22 19:06:31 +02:00
|
|
|
|
|
|
|
|
# Generated once by bootstrap.sh if left empty.
|
|
|
|
|
NATS_PASSWORD=
|
|
|
|
|
|
2026-09-29 15:45:41 +02:00
|
|
|
# The first person in: portal invites this address into the site's most
|
|
|
|
|
# privileged group (the board, on the vel - the group whose desk may
|
|
|
|
|
# invite into the most groups) and mails them the one-time link, once.
|
|
|
|
|
# Everyone else they invite themselves, from their desk.
|
|
|
|
|
SEED_ADMIN_EMAIL=
|
|
|
|
|
SEED_ADMIN_NAME=
|
|
|
|
|
|
|
|
|
|
# The people who ask the questions: everyone a page names as
|
|
|
|
|
# responsible gets an account (portal makes it at start and mails them)
|
|
|
|
|
# and joins this group. Kanidm names are ASCII: redaktor, "Redaktør".
|
|
|
|
|
RESPONSIBLE_GROUP=redaktor
|
|
|
|
|
|
2026-09-30 14:12:24 +02:00
|
|
|
# Where the groups live. `memberships`: portal keeps them itself, a person
|
|
|
|
|
# is their phone number first, and Kanidm only makes the account (until a
|
|
|
|
|
# sign-in everyone already has, like Vipps, takes over). Unset: Kanidm
|
|
|
|
|
# holds the groups too.
|
|
|
|
|
PEOPLE_BACKEND=memberships
|
|
|
|
|
|
2026-09-29 15:45:41 +02:00
|
|
|
# A project Gitea they may sign in to with the same account: kanidm-setup
|
|
|
|
|
# makes its OAuth2 client (only RESPONSIBLE_GROUP may use it) and, on the
|
|
|
|
|
# host that runs that Gitea, adds the sign-in source. Empty: no Gitea.
|
|
|
|
|
GITEA_URL=https://prosjekt.klingenbergbygg.no
|
|
|
|
|
GITEA_AUTH_NAME=tomtervel
|
|
|
|
|
|
2026-09-22 19:06:31 +02:00
|
|
|
# Filled in by bootstrap.sh after it creates the Kanidm client.
|
|
|
|
|
OAUTH2_CLIENT_ID=tomtervel-portal
|
|
|
|
|
OAUTH2_CLIENT_SECRET=
|
|
|
|
|
|
|
|
|
|
# Only for the optional runner profile: a registration token from
|
|
|
|
|
# prosjekt.klingenbergbygg.no -> tomtervel org -> Settings -> Actions -> Runners.
|
|
|
|
|
RUNNER_REGISTRATION_TOKEN=
|
2026-09-28 20:37:07 +02:00
|
|
|
|
|
|
|
|
# The gdo version to run: a tag of https://project.uhhm.no/uhhm/gdo,
|
|
|
|
|
# installed from the [uhhm] Arch registry. gdo hands the vel's mail to
|
|
|
|
|
# the host's mail server; on kasse that is Klingenberg Bygg's postfix.
|
|
|
|
|
GDO_RELEASE=v0.2.0
|