Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s

One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-22 19:06:31 +02:00
co-authored by Claude Fable 5.1
commit 29f2b9daec
11 changed files with 454 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
# Portal, from the release tarball uhhm/portal publishes on
# project.uhhm.no (the same artifact the bare-metal instances run).
# PORTAL_RELEASE in .env pins the version; bumping it and rebuilding is
# the whole upgrade.
FROM debian:bookworm-slim
ARG PORTAL_RELEASE
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates curl \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
RUN curl -sfL "https://project.uhhm.no/uhhm/portal/releases/download/${PORTAL_RELEASE}/portal-${PORTAL_RELEASE}.tar.gz" \
| tar -xz -C /app \
&& test -x /app/portal
# A non-root user; the image ships nothing writable it needs.
RUN useradd --system --no-create-home portal
USER portal
EXPOSE 3000
CMD ["/app/portal"]