The mailer moves in. Portal decides what to send and publishes it on this NATS; gdo is what hands it to a mail server, and it belongs here rather than shared, so the vel's mail leaves on the vel's own terms. It has no mail server of its own and relays through the host's - on kasse, Klingenberg Bygg's postfix - which is the one thing this stack borrows and the one line that changes if the vel ever gets a host of its own. Also: - portal v0.5.2, four releases on from the v0.3.36 this pinned. - The Kanidm setup makes the onboarding service account and its token. The vel's desks invite neighbours, and portal needs a token to do it; without one every invite fails closed. It goes in idm_people_on_boarding, which may create a person and issue a first credential reset and nothing else, plus idm_people_pii_read so an invite finds someone who already has an account instead of making them a second one. - The deploy workflow runs. It was pointed at a `tomtervel` runner label that has never existed, so every push queued and did nothing. It now runs on kasse's host runner, which is not root and may run one argumentless script that pulls this repo and brings the stack up. - The hosts default to vel.klingenbergbygg.no and id.vel.klingenbergbygg.no, which is where this actually runs. Both already resolve to kasse. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+27
@@ -101,6 +101,33 @@ services:
|
||||
kanidm:
|
||||
condition: service_started
|
||||
|
||||
# The mailer. Portal decides what to send - a `mail:` on a state in the
|
||||
# content, or an invite - and publishes it on this NATS; gdo is what
|
||||
# actually hands it to a mail server. It is in the vel's own stack rather
|
||||
# than shared, so the vel's mail leaves on the vel's own terms, but it
|
||||
# has no mail server of its own: it relays through the host's, which on
|
||||
# kasse is Klingenberg Bygg's postfix on port 25. That is the one thing
|
||||
# here the vel borrows.
|
||||
gdo:
|
||||
build:
|
||||
context: ./gdo
|
||||
args:
|
||||
GDO_RELEASE: ${GDO_RELEASE}
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
NATS_URL: nats://portal:${NATS_PASSWORD}@nats:4222
|
||||
# The host, from inside the container. Podman resolves this to the
|
||||
# gateway; the host's postfix listens on 0.0.0.0:25.
|
||||
SMTP_HOST: host.containers.internal
|
||||
SMTP_PORT: "25"
|
||||
# A strict server refuses a bare container hostname in EHLO.
|
||||
SMTP_HELO: ${PORTAL_HOST}
|
||||
extra_hosts:
|
||||
- "host.containers.internal:host-gateway"
|
||||
depends_on:
|
||||
nats:
|
||||
condition: service_healthy
|
||||
|
||||
# The Gitea Actions runner is a host service on kasse (pacman gitea-runner),
|
||||
# registered against prosjekt.klingenbergbygg.no. It reaches this NATS via the
|
||||
# published 127.0.0.1:4222 port above, so no in-compose runner — and no
|
||||
|
||||
Reference in New Issue
Block a user