kanidm-setup: become the gitea user as root; README: postfix relays from the containers

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
This commit is contained in:
bl
2026-09-30 08:04:16 +02:00
co-authored by Claude Fable 5.1
parent ba2da8f3b6
commit 88c16d0fc1
2 changed files with 16 additions and 2 deletions
+10
View File
@@ -206,3 +206,13 @@ when an `admin` session exists and says so when it does not.
The host's CLI comes from pacman and moves on its own, so the image is The host's CLI comes from pacman and moves on its own, so the image is
what to bump: `image: kanidm/server:<version>` in `compose.yml`, then what to bump: `image: kanidm/server:<version>` in `compose.yml`, then
`podman compose up -d kanidm`. `podman compose up -d kanidm`.
## Mail leaving the host
gdo hands the vel's mail to kasse's own postfix over the container
network, so postfix has to be willing to relay from it: `mynetworks`
on kasse includes `172.16.0.0/12` and `10.88.0.0/16` (set 2026-09-30,
the original is in `/etc/postfix/main.cf.before-containers`). Without
it every address outside the host's own domains is refused with
"Relay access denied", and gdo retries a minute apart until it is.
+6 -2
View File
@@ -136,8 +136,12 @@ if [ -n "${GITEA_URL:-}" ] && [ -n "${RESPONSIBLE_GROUP:-}" ]; then
discover="https://$ID_HOST/oauth2/openid/$G/.well-known/openid-configuration" discover="https://$ID_HOST/oauth2/openid/$G/.well-known/openid-configuration"
# On the host that runs that Gitea, add or update its source here; # On the host that runs that Gitea, add or update its source here;
# anywhere else, leave the secret in a file only this user can read. # anywhere else, leave the secret in a file only this user can read.
if command -v gitea >/dev/null 2>&1 && sudo -n -u gitea true 2>/dev/null; then # As root (this script is usually run under sudo) become the gitea
GT="sudo -n -u gitea gitea --config ${GITEA_CONFIG:-/etc/gitea/app.ini} admin auth" # user directly: on kasse root is not in sudoers.
as_gitea=""
if [ "$(id -u)" = 0 ]; then as_gitea="runuser -u gitea --"; elif sudo -n -u gitea true 2>/dev/null; then as_gitea="sudo -n -u gitea"; fi
if command -v gitea >/dev/null 2>&1 && [ -n "$as_gitea" ]; then
GT="$as_gitea gitea --config ${GITEA_CONFIG:-/etc/gitea/app.ini} admin auth"
id=$($GT list 2>/dev/null | awk -v n="$N" '$2 == n { print $1 }') id=$($GT list 2>/dev/null | awk -v n="$N" '$2 == n { print $1 }')
if [ -n "$id" ]; then if [ -n "$id" ]; then
$GT update-oauth --id "$id" --key "$G" --secret "$gsecret" --auto-discover-url "$discover" \ $GT update-oauth --id "$id" --key "$G" --secret "$gsecret" --auto-discover-url "$discover" \