From 88c16d0fc1f9f53ca4d18d0fe207e943e6caf4b1 Mon Sep 17 00:00:00 2001 From: Bendik Aagaard Lynghaug Date: Wed, 30 Sep 2026 08:04:16 +0200 Subject: [PATCH] kanidm-setup: become the gitea user as root; README: postfix relays from the containers Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt --- README.md | 10 ++++++++++ kanidm-setup.sh | 8 ++++++-- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index aee45a2..7aecb21 100644 --- a/README.md +++ b/README.md @@ -206,3 +206,13 @@ when an `admin` session exists and says so when it does not. The host's CLI comes from pacman and moves on its own, so the image is what to bump: `image: kanidm/server:` in `compose.yml`, then `podman compose up -d kanidm`. + +## Mail leaving the host + +gdo hands the vel's mail to kasse's own postfix over the container +network, so postfix has to be willing to relay from it: `mynetworks` +on kasse includes `172.16.0.0/12` and `10.88.0.0/16` (set 2026-09-30, +the original is in `/etc/postfix/main.cf.before-containers`). Without +it every address outside the host's own domains is refused with +"Relay access denied", and gdo retries a minute apart until it is. + diff --git a/kanidm-setup.sh b/kanidm-setup.sh index aa63782..1423cd2 100755 --- a/kanidm-setup.sh +++ b/kanidm-setup.sh @@ -136,8 +136,12 @@ if [ -n "${GITEA_URL:-}" ] && [ -n "${RESPONSIBLE_GROUP:-}" ]; then discover="https://$ID_HOST/oauth2/openid/$G/.well-known/openid-configuration" # On the host that runs that Gitea, add or update its source here; # anywhere else, leave the secret in a file only this user can read. - if command -v gitea >/dev/null 2>&1 && sudo -n -u gitea true 2>/dev/null; then - GT="sudo -n -u gitea gitea --config ${GITEA_CONFIG:-/etc/gitea/app.ini} admin auth" + # As root (this script is usually run under sudo) become the gitea + # user directly: on kasse root is not in sudoers. + as_gitea="" + if [ "$(id -u)" = 0 ]; then as_gitea="runuser -u gitea --"; elif sudo -n -u gitea true 2>/dev/null; then as_gitea="sudo -n -u gitea"; fi + if command -v gitea >/dev/null 2>&1 && [ -n "$as_gitea" ]; then + GT="$as_gitea gitea --config ${GITEA_CONFIG:-/etc/gitea/app.ini} admin auth" id=$($GT list 2>/dev/null | awk -v n="$N" '$2 == n { print $1 }') if [ -n "$id" ]; then $GT update-oauth --id "$id" --key "$G" --secret "$gsecret" --auto-discover-url "$discover" \