podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP - compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the host gitea-runner already covers it; pin the project network to 172.18.0.0/16 so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose default pool hands out unmatched 10.89.x addresses - README / deploy.yml: podman + host-runner notes Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -1,12 +1,10 @@
|
|||||||
# Deploy from this repo: on the vel's own host, a runner registered
|
# Deploy from this repo onto the vel's own host (kasse). There is no
|
||||||
# against prosjekt.klingenbergbygg.no with the label `tomtervel`
|
# `tomtervel`-labelled runner, so this workflow queues and does nothing;
|
||||||
# (the `runner` profile in compose.yml) checks out this repo and
|
# deploy by hand on the host with:
|
||||||
# brings the stack up. Rolling out a new portal version is a commit
|
# cd /srv/tomtervel/infrastructure && git pull --ff-only && sudo sh bootstrap.sh
|
||||||
# that bumps PORTAL_RELEASE in .env.example and, on the host, in .env.
|
# (bootstrap.sh runs `podman compose up -d --build`, rootful). Rolling out
|
||||||
#
|
# a new portal version is a commit that bumps PORTAL_RELEASE in .env.example
|
||||||
# Until that runner exists, this workflow queues and does nothing;
|
# and, on the host, in .env.
|
||||||
# deploy by hand with `git pull && docker compose up -d --build` on
|
|
||||||
# the host.
|
|
||||||
name: deploy
|
name: deploy
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
|
|||||||
@@ -19,13 +19,14 @@ so nothing about the vel's members or records depends on anyone else.
|
|||||||
|
|
||||||
## First start
|
## First start
|
||||||
|
|
||||||
On a fresh Linux host with docker (compose plugin) and openssl:
|
On a fresh Linux host with podman + podman-compose and openssl (run rootful,
|
||||||
|
i.e. as root, so Caddy can bind 80/443 and Kanidm sees a stable source IP):
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
git clone https://prosjekt.klingenbergbygg.no/tomtervel/infrastructure /srv/tomtervel/infrastructure
|
git clone https://prosjekt.klingenbergbygg.no/tomtervel/infrastructure /srv/tomtervel/infrastructure
|
||||||
cd /srv/tomtervel/infrastructure
|
cd /srv/tomtervel/infrastructure
|
||||||
cp .env.example .env # set PORTAL_HOST and ID_HOST; DNS must point here
|
cp .env.example .env # set PORTAL_HOST and ID_HOST; DNS must point here
|
||||||
sh bootstrap.sh # renders configs, makes the internal cert, starts, recovers Kanidm admin
|
sudo sh bootstrap.sh # renders configs, makes the internal cert, starts, recovers Kanidm admin
|
||||||
sh kanidm-setup.sh # logs in, creates the portal client and desk groups, restarts portal
|
sh kanidm-setup.sh # logs in, creates the portal client and desk groups, restarts portal
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -53,22 +54,18 @@ and in again.
|
|||||||
|
|
||||||
A push to tomtervel/questions is linted on push and tells the portal
|
A push to tomtervel/questions is linted on push and tells the portal
|
||||||
to reload over NATS. That reload reaches the host it runs on: today
|
to reload over NATS. That reload reaches the host it runs on: today
|
||||||
Klingenberg Bygg's. For this host, start the runner profile once with
|
Klingenberg Bygg's. On this host the runner is a **host service**
|
||||||
a registration token from the tomtervel org's Actions settings:
|
(`pacman -S gitea-runner`, registered against prosjekt.klingenbergbygg.no) —
|
||||||
|
not an in-compose container — so it reaches NATS on the published
|
||||||
```sh
|
`127.0.0.1:4222`. Give the content repo's `lint-and-reload.yml` a reload job
|
||||||
docker compose --profile runner up -d
|
whose `runs-on` matches that runner's host label, running
|
||||||
```
|
|
||||||
|
|
||||||
and give the content repo's `lint-and-reload.yml` a reload job with
|
|
||||||
`runs-on: tomtervel` that runs
|
|
||||||
`nats --server nats://portal:$NATS_PASSWORD@127.0.0.1:4222 pub portal.content.reload ""`.
|
`nats --server nats://portal:$NATS_PASSWORD@127.0.0.1:4222 pub portal.content.reload ""`.
|
||||||
Until then, `docker compose restart portal` picks up new content.
|
Until then, `podman compose restart portal` picks up new content.
|
||||||
|
|
||||||
## Upgrading portal
|
## Upgrading portal
|
||||||
|
|
||||||
Bump `PORTAL_RELEASE` in `.env` (a tag of uhhm/portal) and
|
Bump `PORTAL_RELEASE` in `.env` (a tag of uhhm/portal) and
|
||||||
`docker compose up -d --build portal`. Keep `IRIS_RELEASE` in the
|
`podman compose up -d --build portal`. Keep `IRIS_RELEASE` in the
|
||||||
content repo's workflow matched to it.
|
content repo's workflow matched to it.
|
||||||
|
|
||||||
## Backups
|
## Backups
|
||||||
|
|||||||
+7
-6
@@ -1,10 +1,11 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# First start on a fresh host. Idempotent: rerunning renders configs
|
# First start on a fresh host. Idempotent: rerunning renders configs
|
||||||
# again and skips what exists. Needs docker with the compose plugin,
|
# again and skips what exists. Needs podman + podman-compose and openssl,
|
||||||
# openssl, and DNS for PORTAL_HOST and ID_HOST already pointing here.
|
# and DNS for PORTAL_HOST and ID_HOST already pointing here. Run rootful
|
||||||
|
# (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP.
|
||||||
#
|
#
|
||||||
# cp .env.example .env # fill in the hosts
|
# cp .env.example .env # fill in the hosts
|
||||||
# sh bootstrap.sh
|
# sudo sh bootstrap.sh
|
||||||
set -eu
|
set -eu
|
||||||
cd "$(dirname "$0")"
|
cd "$(dirname "$0")"
|
||||||
[ -f .env ] || { echo "copy .env.example to .env and fill it in first"; exit 1; }
|
[ -f .env ] || { echo "copy .env.example to .env and fill it in first"; exit 1; }
|
||||||
@@ -43,7 +44,7 @@ if [ ! -f certs/kanidm-key.pem ]; then
|
|||||||
echo "internal Kanidm certificate made"
|
echo "internal Kanidm certificate made"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
docker compose up -d --build
|
podman compose up -d --build
|
||||||
echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOST"
|
echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOST"
|
||||||
|
|
||||||
# The Kanidm admin accounts exist only after the first start; their
|
# The Kanidm admin accounts exist only after the first start; their
|
||||||
@@ -52,8 +53,8 @@ echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOS
|
|||||||
if [ ! -f .kanidm-recovered ]; then
|
if [ ! -f .kanidm-recovered ]; then
|
||||||
echo
|
echo
|
||||||
echo "=== Kanidm admin recovery (write these passwords down) ==="
|
echo "=== Kanidm admin recovery (write these passwords down) ==="
|
||||||
docker compose exec kanidm kanidmd recover-account admin
|
podman compose exec kanidm kanidmd recover-account admin
|
||||||
docker compose exec kanidm kanidmd recover-account idm_admin
|
podman compose exec kanidm kanidmd recover-account idm_admin
|
||||||
touch .kanidm-recovered
|
touch .kanidm-recovered
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
+14
-19
@@ -8,7 +8,7 @@
|
|||||||
# .env, makes Kanidm's internal cert, starts it all,
|
# .env, makes Kanidm's internal cert, starts it all,
|
||||||
# recovers the Kanidm admin, creates the portal client
|
# recovers the Kanidm admin, creates the portal client
|
||||||
# and desk groups.
|
# and desk groups.
|
||||||
# docker compose up -d --build every time after that.
|
# podman compose up -d --build every time after that.
|
||||||
|
|
||||||
name: tomtervel
|
name: tomtervel
|
||||||
|
|
||||||
@@ -79,27 +79,22 @@ services:
|
|||||||
kanidm:
|
kanidm:
|
||||||
condition: service_started
|
condition: service_started
|
||||||
|
|
||||||
# Optional: a Gitea Actions runner on this host, so the content repo's
|
# The Gitea Actions runner is a host service on kasse (pacman gitea-runner),
|
||||||
# lint-and-reload can reach this NATS. Register it once against
|
# registered against prosjekt.klingenbergbygg.no. It reaches this NATS via the
|
||||||
# prosjekt.klingenbergbygg.no with the label `tomtervel`, then give
|
# published 127.0.0.1:4222 port above, so no in-compose runner — and no
|
||||||
# the content repo a reload job with `runs-on: tomtervel`.
|
# docker.sock/podman.sock mount — is needed here.
|
||||||
# docker compose --profile runner up -d
|
|
||||||
runner:
|
|
||||||
profiles: ["runner"]
|
|
||||||
image: gitea/act_runner:latest
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
GITEA_INSTANCE_URL: https://prosjekt.klingenbergbygg.no
|
|
||||||
GITEA_RUNNER_REGISTRATION_TOKEN: ${RUNNER_REGISTRATION_TOKEN:-}
|
|
||||||
GITEA_RUNNER_NAME: tomtervel
|
|
||||||
GITEA_RUNNER_LABELS: tomtervel:host
|
|
||||||
volumes:
|
|
||||||
- runner_data:/data
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
caddy_data:
|
caddy_data:
|
||||||
caddy_config:
|
caddy_config:
|
||||||
nats_data:
|
nats_data:
|
||||||
kanidm_data:
|
kanidm_data:
|
||||||
runner_data:
|
|
||||||
|
# Pin the project network subnet inside 172.16/12 so Kanidm's X-Forwarded-For
|
||||||
|
# trust (kanidm/server.toml.tpl) stays valid under Podman — its default pool
|
||||||
|
# hands out 10.89.x addresses that Caddy's forwarded client IP can't match.
|
||||||
|
networks:
|
||||||
|
default:
|
||||||
|
ipam:
|
||||||
|
config:
|
||||||
|
- subnet: 172.18.0.0/16
|
||||||
|
|||||||
+1
-1
@@ -36,7 +36,7 @@ $K system oauth2 update-claim-map-join $C groups array
|
|||||||
|
|
||||||
secret=$($K system oauth2 show-basic-secret $C 2>/dev/null | tail -1)
|
secret=$($K system oauth2 show-basic-secret $C 2>/dev/null | tail -1)
|
||||||
sed -i "s|^OAUTH2_CLIENT_SECRET=.*|OAUTH2_CLIENT_SECRET=$secret|" .env portal.env
|
sed -i "s|^OAUTH2_CLIENT_SECRET=.*|OAUTH2_CLIENT_SECRET=$secret|" .env portal.env
|
||||||
docker compose restart portal
|
podman compose restart portal
|
||||||
echo "client $C configured; portal restarted with its secret"
|
echo "client $C configured; portal restarted with its secret"
|
||||||
echo
|
echo
|
||||||
echo "Give people their desk (membership is read at login):"
|
echo "Give people their desk (membership is read at login):"
|
||||||
|
|||||||
Reference in New Issue
Block a user