Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions. bootstrap.sh renders configs from .env and recovers the Kanidm admin; kanidm-setup.sh creates the portal client and the desk groups. An optional runner profile lets the content repo's reload reach this host. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
# Kanidm server configuration. bootstrap.sh renders this into
|
||||
# server.toml from .env; edit the template, not the rendered file.
|
||||
# Reference: https://kanidm.github.io/kanidm/stable/server_configuration.html
|
||||
version = "2"
|
||||
|
||||
bindaddress = "0.0.0.0:8443"
|
||||
|
||||
# Internal self-signed pair made by bootstrap.sh; Caddy terminates the
|
||||
# public certificate and proxies here with verification disabled.
|
||||
tls_chain = "/data/chain.pem"
|
||||
tls_key = "/data/key.pem"
|
||||
|
||||
db_path = "/data/kanidm.db"
|
||||
db_fs_type = "other"
|
||||
db_arc_size = 2048
|
||||
|
||||
log_level = "info"
|
||||
|
||||
# domain must equal the DNS name Kanidm is served at.
|
||||
domain = "${ID_HOST}"
|
||||
origin = "https://${ID_HOST}"
|
||||
|
||||
# Trust X-Forwarded-For from Caddy on the compose network.
|
||||
[http_client_address_info]
|
||||
x-forward-for = ["172.16.0.0/12"]
|
||||
|
||||
[online_backup]
|
||||
path = "/data/backups/"
|
||||
schedule = "00 22 * * *"
|
||||
versions = 7
|
||||
Reference in New Issue
Block a user