podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP - compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the host gitea-runner already covers it; pin the project network to 172.18.0.0/16 so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose default pool hands out unmatched 10.89.x addresses - README / deploy.yml: podman + host-runner notes Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -1,12 +1,10 @@
|
||||
# Deploy from this repo: on the vel's own host, a runner registered
|
||||
# against prosjekt.klingenbergbygg.no with the label `tomtervel`
|
||||
# (the `runner` profile in compose.yml) checks out this repo and
|
||||
# brings the stack up. Rolling out a new portal version is a commit
|
||||
# that bumps PORTAL_RELEASE in .env.example and, on the host, in .env.
|
||||
#
|
||||
# Until that runner exists, this workflow queues and does nothing;
|
||||
# deploy by hand with `git pull && docker compose up -d --build` on
|
||||
# the host.
|
||||
# Deploy from this repo onto the vel's own host (kasse). There is no
|
||||
# `tomtervel`-labelled runner, so this workflow queues and does nothing;
|
||||
# deploy by hand on the host with:
|
||||
# cd /srv/tomtervel/infrastructure && git pull --ff-only && sudo sh bootstrap.sh
|
||||
# (bootstrap.sh runs `podman compose up -d --build`, rootful). Rolling out
|
||||
# a new portal version is a commit that bumps PORTAL_RELEASE in .env.example
|
||||
# and, on the host, in .env.
|
||||
name: deploy
|
||||
on:
|
||||
push:
|
||||
|
||||
Reference in New Issue
Block a user