Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s

One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-22 19:06:31 +02:00
co-authored by Claude Fable 5.1
commit 29f2b9daec
11 changed files with 454 additions and 0 deletions
+30
View File
@@ -0,0 +1,30 @@
# Kanidm server configuration. bootstrap.sh renders this into
# server.toml from .env; edit the template, not the rendered file.
# Reference: https://kanidm.github.io/kanidm/stable/server_configuration.html
version = "2"
bindaddress = "0.0.0.0:8443"
# Internal self-signed pair made by bootstrap.sh; Caddy terminates the
# public certificate and proxies here with verification disabled.
tls_chain = "/data/chain.pem"
tls_key = "/data/key.pem"
db_path = "/data/kanidm.db"
db_fs_type = "other"
db_arc_size = 2048
log_level = "info"
# domain must equal the DNS name Kanidm is served at.
domain = "${ID_HOST}"
origin = "https://${ID_HOST}"
# Trust X-Forwarded-For from Caddy on the compose network.
[http_client_address_info]
x-forward-for = ["172.16.0.0/12"]
[online_backup]
path = "/data/backups/"
schedule = "00 22 * * *"
versions = 7