kanidm-setup, all the way: desk groups from the content, no prefix, onboarding that works, the first person, redaktør, and Gitea sign-in
The desk groups are read from the content's qualifies: and named as it names them - this Kanidm is the vel's own - with the old tomtervel_* groups renamed in place. The onboarding account manages every desk group, since adding a member takes that right (measured: 404 without). Sign-in scopes to idm_all_persons. SEED_ADMIN_EMAIL and RESPONSIBLE_GROUP (redaktor) reach portal.env, and bootstrap no longer drops the onboarding token when it rewrites portal.env. A second OAuth2 client lets redaktor sign in to prosjekt.klingenbergbygg.no; on the Gitea host the script adds that sign-in source itself. The login page's own name and logo need the admin account; the script now says so rather than failing with 'Item not found'. .env.example quotes SITE_NAME, which has a space and broke sourcing it. Tested end to end against a local Kanidm 1.11.2, including a rerun and a legacy tomtervel_kasserer with a member. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
This commit is contained in:
@@ -21,6 +21,9 @@ fi
|
||||
# Rendered configs (gitignored).
|
||||
sed "s|\${ID_HOST}|$ID_HOST|g" kanidm/server.toml.tpl > kanidm/server.toml
|
||||
sed "s|\${NATS_PASSWORD}|$NATS_PASSWORD|g" nats/nats.conf.tpl > nats/nats.conf
|
||||
# The onboarding token is written by kanidm-setup.sh, once; a rerun of
|
||||
# this script must not lose it, or every invite fails closed again.
|
||||
kept_token=$(grep '^KANIDM_API_TOKEN=' portal.env 2>/dev/null | head -1 || true)
|
||||
cat > portal.env <<EOF
|
||||
NATS_URL=nats://portal:$NATS_PASSWORD@nats:4222
|
||||
KANIDM_URL=https://$ID_HOST
|
||||
@@ -31,7 +34,11 @@ COOKIE_SECURE=true
|
||||
CONTENT_REPO=$CONTENT_REPO
|
||||
CONTENT_BRANCH=$CONTENT_BRANCH
|
||||
SITE_NAME=$SITE_NAME
|
||||
SEED_ADMIN_EMAIL=${SEED_ADMIN_EMAIL:-}
|
||||
SEED_ADMIN_NAME=${SEED_ADMIN_NAME:-}
|
||||
RESPONSIBLE_GROUP=${RESPONSIBLE_GROUP:-}
|
||||
EOF
|
||||
[ -n "$kept_token" ] && echo "$kept_token" >> portal.env
|
||||
chmod 600 portal.env
|
||||
|
||||
# Kanidm's internal certificate: Caddy holds the public one.
|
||||
|
||||
Reference in New Issue
Block a user