podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP - compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the host gitea-runner already covers it; pin the project network to 172.18.0.0/16 so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose default pool hands out unmatched 10.89.x addresses - README / deploy.yml: podman + host-runner notes Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+7
-6
@@ -1,10 +1,11 @@
|
||||
#!/bin/sh
|
||||
# First start on a fresh host. Idempotent: rerunning renders configs
|
||||
# again and skips what exists. Needs docker with the compose plugin,
|
||||
# openssl, and DNS for PORTAL_HOST and ID_HOST already pointing here.
|
||||
# again and skips what exists. Needs podman + podman-compose and openssl,
|
||||
# and DNS for PORTAL_HOST and ID_HOST already pointing here. Run rootful
|
||||
# (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP.
|
||||
#
|
||||
# cp .env.example .env # fill in the hosts
|
||||
# sh bootstrap.sh
|
||||
# sudo sh bootstrap.sh
|
||||
set -eu
|
||||
cd "$(dirname "$0")"
|
||||
[ -f .env ] || { echo "copy .env.example to .env and fill it in first"; exit 1; }
|
||||
@@ -43,7 +44,7 @@ if [ ! -f certs/kanidm-key.pem ]; then
|
||||
echo "internal Kanidm certificate made"
|
||||
fi
|
||||
|
||||
docker compose up -d --build
|
||||
podman compose up -d --build
|
||||
echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOST"
|
||||
|
||||
# The Kanidm admin accounts exist only after the first start; their
|
||||
@@ -52,8 +53,8 @@ echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOS
|
||||
if [ ! -f .kanidm-recovered ]; then
|
||||
echo
|
||||
echo "=== Kanidm admin recovery (write these passwords down) ==="
|
||||
docker compose exec kanidm kanidmd recover-account admin
|
||||
docker compose exec kanidm kanidmd recover-account idm_admin
|
||||
podman compose exec kanidm kanidmd recover-account admin
|
||||
podman compose exec kanidm kanidmd recover-account idm_admin
|
||||
touch .kanidm-recovered
|
||||
fi
|
||||
|
||||
|
||||
Reference in New Issue
Block a user