Match the Kanidm server to the CLI, and say why a token failed
deploy / deploy (push) Successful in 33s

Three things in one setup run, two of them mine.

The server image was 1.11.1 while the host's CLI is 1.11.2, and a
1.11.2 client looks up the domain entry at a UUID 1.11.1 does not
have. So `system domain set-displayname` and `set-image` both failed
with "Item not found", which says nothing about versions. The CLI had
been warning about the mismatch on every single call. Image bumped to
1.11.2; the README says to keep them together and which one to move.

The onboarding token asked for `--rw`, and the flag is spelled
`--readwrite`. The script swallowed stderr and reported a bare warning,
so a step that leaves every invite failing closed said nothing about
why. It now passes the right flag, and if it still fails it says what
the CLI said and prints the command to retry by hand.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-28 22:24:08 +02:00
co-authored by Claude Opus 5
parent 0967b9973b
commit b7e8e0313e
3 changed files with 23 additions and 3 deletions
+14
View File
@@ -157,3 +157,17 @@ decisions rather than branding:
it is still a door, so it is turned on knowingly or not at all.
- `system domain set-allow-easter-eggs` - seasonal icons and birthday
surprises. Off in production builds, and this is somebody's vel.
## Keep the CLI and the server on the same version
The `kanidm` CLI on the host and the `kanidm/server` image in
`compose.yml` must match. They are not merely fussy about it: a 1.11.2
client against a 1.11.1 server looks up the domain entry at a UUID the
older server does not have, so `system domain set-displayname` and
`set-image` fail with "Item not found" - a message that says nothing
about versions. The CLI warns on every call; the warning is worth
reading.
The host's CLI comes from pacman and moves on its own, so the image is
what to bump: `image: kanidm/server:<version>` in `compose.yml`, then
`podman compose up -d kanidm`.