Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s

One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-22 19:06:31 +02:00
co-authored by Claude Fable 5.1
commit 29f2b9daec
11 changed files with 454 additions and 0 deletions
+28
View File
@@ -0,0 +1,28 @@
# Copy to .env and fill in. Everything rendered from this (nats.conf,
# kanidm/server.toml, portal.env) is gitignored.
# Where the site and the identity provider are served. Both need an A
# record pointing at this host before the first start (Caddy gets the
# certificates over HTTP-01). tomtervel.no itself stays where it is
# until the vel decides to point the apex here.
PORTAL_HOST=portal.tomtervel.no
ID_HOST=id.tomtervel.no
# The portal version to run: a tag of https://project.uhhm.no/uhhm/portal
PORTAL_RELEASE=v0.3.36
# The content this instance serves, and reloads live on every push.
CONTENT_REPO=https://prosjekt.klingenbergbygg.no/tomtervel/questions
CONTENT_BRANCH=main
SITE_NAME=Tomter Vel
# Generated once by bootstrap.sh if left empty.
NATS_PASSWORD=
# Filled in by bootstrap.sh after it creates the Kanidm client.
OAUTH2_CLIENT_ID=tomtervel-portal
OAUTH2_CLIENT_SECRET=
# Only for the optional runner profile: a registration token from
# prosjekt.klingenbergbygg.no -> tomtervel org -> Settings -> Actions -> Runners.
RUNNER_REGISTRATION_TOKEN=