gdo in the vel's own stack, and portal v0.5.2
deploy / deploy (push) Failing after 2s

The mailer moves in. Portal decides what to send and publishes it on
this NATS; gdo is what hands it to a mail server, and it belongs here
rather than shared, so the vel's mail leaves on the vel's own terms. It
has no mail server of its own and relays through the host's - on kasse,
Klingenberg Bygg's postfix - which is the one thing this stack borrows
and the one line that changes if the vel ever gets a host of its own.

Also:

- portal v0.5.2, four releases on from the v0.3.36 this pinned.
- The Kanidm setup makes the onboarding service account and its token.
  The vel's desks invite neighbours, and portal needs a token to do it;
  without one every invite fails closed. It goes in
  idm_people_on_boarding, which may create a person and issue a first
  credential reset and nothing else, plus idm_people_pii_read so an
  invite finds someone who already has an account instead of making
  them a second one.
- The deploy workflow runs. It was pointed at a `tomtervel` runner
  label that has never existed, so every push queued and did nothing.
  It now runs on kasse's host runner, which is not root and may run one
  argumentless script that pulls this repo and brings the stack up.
- The hosts default to vel.klingenbergbygg.no and
  id.vel.klingenbergbygg.no, which is where this actually runs. Both
  already resolve to kasse.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-28 20:37:07 +02:00
co-authored by Claude Opus 5
parent debc0c9149
commit d482ac43c2
6 changed files with 118 additions and 17 deletions
+14 -14
View File
@@ -1,10 +1,13 @@
# Deploy from this repo onto the vel's own host (kasse). There is no
# `tomtervel`-labelled runner, so this workflow queues and does nothing;
# deploy by hand on the host with:
# cd /srv/tomtervel/infrastructure && git pull --ff-only && sudo sh bootstrap.sh
# (bootstrap.sh runs `podman compose up -d --build`, rootful). Rolling out
# a new portal version is a commit that bumps PORTAL_RELEASE in .env.example
# and, on the host, in .env.
# Deploy this stack onto the host it runs on. A push that changes the
# compose file, a Dockerfile or a rendered config pulls and brings the
# stack up; a portal or gdo upgrade is a commit that bumps the version in
# .env.example and, on the host, in .env.
#
# Runs on kasse's host runner. It is not root: it may run one script,
# /usr/local/bin/deploy-tomtervel, which pulls this repo under
# /srv/tomtervel and runs `podman compose up -d --build` and nothing
# else. The .env on the host - the NATS password, the OAuth2 secret, the
# Kanidm token - is never in this repo and is not touched by a deploy.
name: deploy
on:
push:
@@ -13,6 +16,7 @@ on:
- compose.yml
- Caddyfile
- portal/**
- gdo/**
- kanidm/server.toml.tpl
- nats/nats.conf.tpl
- .gitea/workflows/deploy.yml
@@ -20,11 +24,7 @@ on:
jobs:
deploy:
runs-on: tomtervel
runs-on: fish
steps:
- name: Pull and restart
run: |
set -eu
cd /srv/tomtervel/infrastructure
git pull --ff-only
sh bootstrap.sh
- name: Pull and bring the stack up
run: sudo /usr/local/bin/deploy-tomtervel