Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions. bootstrap.sh renders configs from .env and recovers the Kanidm admin; kanidm-setup.sh creates the portal client and the desk groups. An optional runner profile lets the content repo's reload reach this host. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
# Portal, from the release tarball uhhm/portal publishes on
|
||||
# project.uhhm.no (the same artifact the bare-metal instances run).
|
||||
# PORTAL_RELEASE in .env pins the version; bumping it and rebuilding is
|
||||
# the whole upgrade.
|
||||
FROM debian:bookworm-slim
|
||||
ARG PORTAL_RELEASE
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends ca-certificates curl \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
WORKDIR /app
|
||||
RUN curl -sfL "https://project.uhhm.no/uhhm/portal/releases/download/${PORTAL_RELEASE}/portal-${PORTAL_RELEASE}.tar.gz" \
|
||||
| tar -xz -C /app \
|
||||
&& test -x /app/portal
|
||||
# A non-root user; the image ships nothing writable it needs.
|
||||
RUN useradd --system --no-create-home portal
|
||||
USER portal
|
||||
EXPOSE 3000
|
||||
CMD ["/app/portal"]
|
||||
Reference in New Issue
Block a user