podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP - compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the host gitea-runner already covers it; pin the project network to 172.18.0.0/16 so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose default pool hands out unmatched 10.89.x addresses - README / deploy.yml: podman + host-runner notes Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -19,13 +19,14 @@ so nothing about the vel's members or records depends on anyone else.
|
||||
|
||||
## First start
|
||||
|
||||
On a fresh Linux host with docker (compose plugin) and openssl:
|
||||
On a fresh Linux host with podman + podman-compose and openssl (run rootful,
|
||||
i.e. as root, so Caddy can bind 80/443 and Kanidm sees a stable source IP):
|
||||
|
||||
```sh
|
||||
git clone https://prosjekt.klingenbergbygg.no/tomtervel/infrastructure /srv/tomtervel/infrastructure
|
||||
cd /srv/tomtervel/infrastructure
|
||||
cp .env.example .env # set PORTAL_HOST and ID_HOST; DNS must point here
|
||||
sh bootstrap.sh # renders configs, makes the internal cert, starts, recovers Kanidm admin
|
||||
sudo sh bootstrap.sh # renders configs, makes the internal cert, starts, recovers Kanidm admin
|
||||
sh kanidm-setup.sh # logs in, creates the portal client and desk groups, restarts portal
|
||||
```
|
||||
|
||||
@@ -53,22 +54,18 @@ and in again.
|
||||
|
||||
A push to tomtervel/questions is linted on push and tells the portal
|
||||
to reload over NATS. That reload reaches the host it runs on: today
|
||||
Klingenberg Bygg's. For this host, start the runner profile once with
|
||||
a registration token from the tomtervel org's Actions settings:
|
||||
|
||||
```sh
|
||||
docker compose --profile runner up -d
|
||||
```
|
||||
|
||||
and give the content repo's `lint-and-reload.yml` a reload job with
|
||||
`runs-on: tomtervel` that runs
|
||||
Klingenberg Bygg's. On this host the runner is a **host service**
|
||||
(`pacman -S gitea-runner`, registered against prosjekt.klingenbergbygg.no) —
|
||||
not an in-compose container — so it reaches NATS on the published
|
||||
`127.0.0.1:4222`. Give the content repo's `lint-and-reload.yml` a reload job
|
||||
whose `runs-on` matches that runner's host label, running
|
||||
`nats --server nats://portal:$NATS_PASSWORD@127.0.0.1:4222 pub portal.content.reload ""`.
|
||||
Until then, `docker compose restart portal` picks up new content.
|
||||
Until then, `podman compose restart portal` picks up new content.
|
||||
|
||||
## Upgrading portal
|
||||
|
||||
Bump `PORTAL_RELEASE` in `.env` (a tag of uhhm/portal) and
|
||||
`docker compose up -d --build portal`. Keep `IRIS_RELEASE` in the
|
||||
`podman compose up -d --build portal`. Keep `IRIS_RELEASE` in the
|
||||
content repo's workflow matched to it.
|
||||
|
||||
## Backups
|
||||
|
||||
Reference in New Issue
Block a user