podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP - compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the host gitea-runner already covers it; pin the project network to 172.18.0.0/16 so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose default pool hands out unmatched 10.89.x addresses - README / deploy.yml: podman + host-runner notes Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+14
-19
@@ -8,7 +8,7 @@
|
||||
# .env, makes Kanidm's internal cert, starts it all,
|
||||
# recovers the Kanidm admin, creates the portal client
|
||||
# and desk groups.
|
||||
# docker compose up -d --build every time after that.
|
||||
# podman compose up -d --build every time after that.
|
||||
|
||||
name: tomtervel
|
||||
|
||||
@@ -79,27 +79,22 @@ services:
|
||||
kanidm:
|
||||
condition: service_started
|
||||
|
||||
# Optional: a Gitea Actions runner on this host, so the content repo's
|
||||
# lint-and-reload can reach this NATS. Register it once against
|
||||
# prosjekt.klingenbergbygg.no with the label `tomtervel`, then give
|
||||
# the content repo a reload job with `runs-on: tomtervel`.
|
||||
# docker compose --profile runner up -d
|
||||
runner:
|
||||
profiles: ["runner"]
|
||||
image: gitea/act_runner:latest
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
GITEA_INSTANCE_URL: https://prosjekt.klingenbergbygg.no
|
||||
GITEA_RUNNER_REGISTRATION_TOKEN: ${RUNNER_REGISTRATION_TOKEN:-}
|
||||
GITEA_RUNNER_NAME: tomtervel
|
||||
GITEA_RUNNER_LABELS: tomtervel:host
|
||||
volumes:
|
||||
- runner_data:/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
# The Gitea Actions runner is a host service on kasse (pacman gitea-runner),
|
||||
# registered against prosjekt.klingenbergbygg.no. It reaches this NATS via the
|
||||
# published 127.0.0.1:4222 port above, so no in-compose runner — and no
|
||||
# docker.sock/podman.sock mount — is needed here.
|
||||
|
||||
volumes:
|
||||
caddy_data:
|
||||
caddy_config:
|
||||
nats_data:
|
||||
kanidm_data:
|
||||
runner_data:
|
||||
|
||||
# Pin the project network subnet inside 172.16/12 so Kanidm's X-Forwarded-For
|
||||
# trust (kanidm/server.toml.tpl) stays valid under Podman — its default pool
|
||||
# hands out 10.89.x addresses that Caddy's forwarded client IP can't match.
|
||||
networks:
|
||||
default:
|
||||
ipam:
|
||||
config:
|
||||
- subnet: 172.18.0.0/16
|
||||
|
||||
Reference in New Issue
Block a user