podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s

- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful
  (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP
- compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the
  host gitea-runner already covers it; pin the project network to 172.18.0.0/16
  so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose
  default pool hands out unmatched 10.89.x addresses
- README / deploy.yml: podman + host-runner notes

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-28 11:15:29 +02:00
co-authored by Claude Opus 4.8
parent 506cb84e82
commit de93e108ad
5 changed files with 39 additions and 48 deletions
+10 -13
View File
@@ -19,13 +19,14 @@ so nothing about the vel's members or records depends on anyone else.
## First start
On a fresh Linux host with docker (compose plugin) and openssl:
On a fresh Linux host with podman + podman-compose and openssl (run rootful,
i.e. as root, so Caddy can bind 80/443 and Kanidm sees a stable source IP):
```sh
git clone https://prosjekt.klingenbergbygg.no/tomtervel/infrastructure /srv/tomtervel/infrastructure
cd /srv/tomtervel/infrastructure
cp .env.example .env # set PORTAL_HOST and ID_HOST; DNS must point here
sh bootstrap.sh # renders configs, makes the internal cert, starts, recovers Kanidm admin
sudo sh bootstrap.sh # renders configs, makes the internal cert, starts, recovers Kanidm admin
sh kanidm-setup.sh # logs in, creates the portal client and desk groups, restarts portal
```
@@ -53,22 +54,18 @@ and in again.
A push to tomtervel/questions is linted on push and tells the portal
to reload over NATS. That reload reaches the host it runs on: today
Klingenberg Bygg's. For this host, start the runner profile once with
a registration token from the tomtervel org's Actions settings:
```sh
docker compose --profile runner up -d
```
and give the content repo's `lint-and-reload.yml` a reload job with
`runs-on: tomtervel` that runs
Klingenberg Bygg's. On this host the runner is a **host service**
(`pacman -S gitea-runner`, registered against prosjekt.klingenbergbygg.no) —
not an in-compose container — so it reaches NATS on the published
`127.0.0.1:4222`. Give the content repo's `lint-and-reload.yml` a reload job
whose `runs-on` matches that runner's host label, running
`nats --server nats://portal:$NATS_PASSWORD@127.0.0.1:4222 pub portal.content.reload ""`.
Until then, `docker compose restart portal` picks up new content.
Until then, `podman compose restart portal` picks up new content.
## Upgrading portal
Bump `PORTAL_RELEASE` in `.env` (a tag of uhhm/portal) and
`docker compose up -d --build portal`. Keep `IRIS_RELEASE` in the
`podman compose up -d --build portal`. Keep `IRIS_RELEASE` in the
content repo's workflow matched to it.
## Backups