Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions. bootstrap.sh renders configs from .env and recovers the Kanidm admin; kanidm-setup.sh creates the portal client and the desk groups. An optional runner profile lets the content repo's reload reach this host. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Public TLS for both hosts, real certificates from Let's Encrypt over
|
||||
# HTTP-01: the DNS A records for ${PORTAL_HOST} and ${ID_HOST} must
|
||||
# point at this host before the first start.
|
||||
|
||||
{$ID_HOST} {
|
||||
# Kanidm serves its own (internal, self-signed) TLS; verification is
|
||||
# skipped on the inside hop only.
|
||||
reverse_proxy kanidm:8443 {
|
||||
transport http {
|
||||
tls_insecure_skip_verify
|
||||
}
|
||||
}
|
||||
log {
|
||||
output file /data/id.log
|
||||
}
|
||||
}
|
||||
|
||||
{$PORTAL_HOST} {
|
||||
reverse_proxy portal:3000
|
||||
log {
|
||||
output file /data/portal.log
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user