podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP - compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the host gitea-runner already covers it; pin the project network to 172.18.0.0/16 so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose default pool hands out unmatched 10.89.x addresses - README / deploy.yml: podman + host-runner notes Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -36,7 +36,7 @@ $K system oauth2 update-claim-map-join $C groups array
|
||||
|
||||
secret=$($K system oauth2 show-basic-secret $C 2>/dev/null | tail -1)
|
||||
sed -i "s|^OAUTH2_CLIENT_SECRET=.*|OAUTH2_CLIENT_SECRET=$secret|" .env portal.env
|
||||
docker compose restart portal
|
||||
podman compose restart portal
|
||||
echo "client $C configured; portal restarted with its secret"
|
||||
echo
|
||||
echo "Give people their desk (membership is read at login):"
|
||||
|
||||
Reference in New Issue
Block a user