Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions. bootstrap.sh renders configs from .env and recovers the Kanidm admin; kanidm-setup.sh creates the portal client and the desk groups. An optional runner profile lets the content repo's reload reach this host. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
+105
@@ -0,0 +1,105 @@
|
||||
# Tomter Vel's own platform: one host, four containers, everything
|
||||
# behind Caddy. The content (pages, forms, desks) is not here: portal
|
||||
# fetches it from tomtervel/questions on prosjekt.klingenbergbygg.no
|
||||
# and hot-reloads it over NATS. This repo owns the host: identity,
|
||||
# the bus, TLS, and which portal version runs.
|
||||
#
|
||||
# bootstrap.sh first time on a fresh host: renders configs from
|
||||
# .env, makes Kanidm's internal cert, starts it all,
|
||||
# recovers the Kanidm admin, creates the portal client
|
||||
# and desk groups.
|
||||
# docker compose up -d --build every time after that.
|
||||
|
||||
name: tomtervel
|
||||
|
||||
services:
|
||||
caddy:
|
||||
image: caddy:2
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
- "443:443/udp"
|
||||
environment:
|
||||
PORTAL_HOST: ${PORTAL_HOST}
|
||||
ID_HOST: ${ID_HOST}
|
||||
volumes:
|
||||
- ./Caddyfile:/etc/caddy/Caddyfile:ro
|
||||
- caddy_data:/data
|
||||
- caddy_config:/config
|
||||
depends_on:
|
||||
- portal
|
||||
- kanidm
|
||||
|
||||
nats:
|
||||
image: nats:2.14.6-alpine
|
||||
restart: unless-stopped
|
||||
command: ["-c", "/etc/nats/nats.conf"]
|
||||
volumes:
|
||||
- ./nats/nats.conf:/etc/nats/nats.conf:ro
|
||||
- nats_data:/data
|
||||
# Published so a runner or a person on the host can `nats pub
|
||||
# portal.content.reload ""`; password-protected (see nats.conf).
|
||||
ports:
|
||||
- "127.0.0.1:4222:4222"
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "--spider", "-q", "http://localhost:8222/healthz"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
|
||||
kanidm:
|
||||
image: kanidm/server:1.11.1
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
KANIDM_CONFIG_PATH: /data/server.toml
|
||||
volumes:
|
||||
- kanidm_data:/data
|
||||
- ./kanidm/server.toml:/data/server.toml:ro
|
||||
# Internal self-signed TLS: Caddy terminates the public
|
||||
# certificate and proxies here without verification.
|
||||
- ./certs/kanidm-chain.pem:/data/chain.pem:ro
|
||||
- ./certs/kanidm-key.pem:/data/key.pem:ro
|
||||
# No published ports: only Caddy talks to it.
|
||||
|
||||
portal:
|
||||
build:
|
||||
context: ./portal
|
||||
args:
|
||||
PORTAL_RELEASE: ${PORTAL_RELEASE}
|
||||
restart: unless-stopped
|
||||
env_file: portal.env
|
||||
environment:
|
||||
LEPTOS_SITE_ADDR: 0.0.0.0:3000
|
||||
LEPTOS_SITE_ROOT: site
|
||||
LEPTOS_HASH_FILES: "true"
|
||||
depends_on:
|
||||
nats:
|
||||
condition: service_healthy
|
||||
kanidm:
|
||||
condition: service_started
|
||||
|
||||
# Optional: a Gitea Actions runner on this host, so the content repo's
|
||||
# lint-and-reload can reach this NATS. Register it once against
|
||||
# prosjekt.klingenbergbygg.no with the label `tomtervel`, then give
|
||||
# the content repo a reload job with `runs-on: tomtervel`.
|
||||
# docker compose --profile runner up -d
|
||||
runner:
|
||||
profiles: ["runner"]
|
||||
image: gitea/act_runner:latest
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
GITEA_INSTANCE_URL: https://prosjekt.klingenbergbygg.no
|
||||
GITEA_RUNNER_REGISTRATION_TOKEN: ${RUNNER_REGISTRATION_TOKEN:-}
|
||||
GITEA_RUNNER_NAME: tomtervel
|
||||
GITEA_RUNNER_LABELS: tomtervel:host
|
||||
volumes:
|
||||
- runner_data:/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
|
||||
volumes:
|
||||
caddy_data:
|
||||
caddy_config:
|
||||
nats_data:
|
||||
kanidm_data:
|
||||
runner_data:
|
||||
Reference in New Issue
Block a user