From debc0c914941d7aa1c664dababe2ad01c2748d70 Mon Sep 17 00:00:00 2001 From: Bendik Aagaard Lynghaug Date: Mon, 28 Sep 2026 12:31:14 +0200 Subject: [PATCH] vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy The vel keeps its own identity+bus so it can later lift onto a host of its own unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes 127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with tls_insecure_skip_verify), the reload port, and the app@ handoff. Co-Authored-By: Claude Opus 4.8 --- README.md | 30 ++++++++++++++++++++++++++++++ compose.yml | 18 ++++++++++++++---- 2 files changed, 44 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 4cebcbc..fda565f 100644 --- a/README.md +++ b/README.md @@ -34,6 +34,36 @@ sh kanidm-setup.sh # logs in, creates the portal client and desk groups, write them down. After `kanidm-setup.sh`, https://PORTAL_HOST serves the site and https://ID_HOST is the login. +## Running on kasse (behind the host Caddy) + +The vel keeps its **own** Kanidm and NATS here so it can later lift onto a host +of its own unchanged — on kasse it just runs in isolation, fronted by kasse's +existing host Caddy (which owns 80/443). So the bundled Caddy stays off (it's +behind `profiles: [edge]`); run the default `podman compose up -d --build`. +The services publish loopback-only ports for the host Caddy to reach: + +- portal → `127.0.0.1:3050` +- kanidm → `127.0.0.1:8443` (internal self-signed TLS) +- nats → `127.0.0.1:4223` (kasse's shared platform NATS owns 4222) + +Add two host-Caddy site blocks in `/etc/caddy/conf.d/`, using the vel's `.env` +hosts (`vel.klingenbergbygg.no → :3050` already exists): + +``` + { + reverse_proxy localhost:3050 +} + { + reverse_proxy https://localhost:8443 { + transport http { tls_insecure_skip_verify } + } +} +``` + +Then `sudo systemctl reload caddy`, point the content repo's `lint-and-reload` +reload step at `nats://127.0.0.1:4223`, and retire the old systemd portal: +`sudo systemctl disable --now app@tomtervel-portal`. + ## People and desks Each group in the content (`qualifies:` under `questions/`) is a diff --git a/compose.yml b/compose.yml index 8752cc7..ba10441 100644 --- a/compose.yml +++ b/compose.yml @@ -45,10 +45,13 @@ services: volumes: - ./nats/nats.conf:/etc/nats/nats.conf:ro - nats_data:/data - # Published so a runner or a person on the host can `nats pub - # portal.content.reload ""`; password-protected (see nats.conf). + # Published on the host so the reload job (`nats pub portal.content.reload ""`) + # can reach it; password-protected (see nats.conf). Host port 4223, not 4222: + # on kasse the shared platform NATS already owns 127.0.0.1:4222 and the vel + # runs its own NATS in isolation, so the reload workflow targets 4223 there. + # (Standalone, nothing else owns 4222, but 4223 is harmless.) ports: - - "127.0.0.1:4222:4222" + - "127.0.0.1:4223:4222" healthcheck: test: ["CMD", "wget", "--spider", "-q", "http://localhost:8222/healthz"] interval: 10s @@ -67,7 +70,14 @@ services: # certificate and proxies here without verification. - ./certs/kanidm-chain.pem:/data/chain.pem:ro - ./certs/kanidm-key.pem:/data/key.pem:ro - # No published ports: only Caddy talks to it. + # Standalone (--profile edge): only the bundled Caddy talks to Kanidm. + # On kasse the host Caddy fronts it, so publish loopback-only for a conf.d + # entry: id. { reverse_proxy https://localhost:8443 { + # transport http { tls_insecure_skip_verify } } } + # (Kanidm's internal self-signed cert; 8443 is free on kasse — its shared + # Kanidm is on 8310.) + ports: + - "127.0.0.1:8443:8443" portal: build: