vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy
deploy / deploy (push) Canceled after 0s

The vel keeps its own identity+bus so it can later lift onto a host of its own
unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm
publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes
127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the
two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with
tls_insecure_skip_verify), the reload port, and the app@ handoff.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-28 12:31:14 +02:00
co-authored by Claude Opus 4.8
parent 74c120dc30
commit debc0c9149
2 changed files with 44 additions and 4 deletions
+30
View File
@@ -34,6 +34,36 @@ sh kanidm-setup.sh # logs in, creates the portal client and desk groups,
write them down. After `kanidm-setup.sh`, https://PORTAL_HOST serves the
site and https://ID_HOST is the login.
## Running on kasse (behind the host Caddy)
The vel keeps its **own** Kanidm and NATS here so it can later lift onto a host
of its own unchanged — on kasse it just runs in isolation, fronted by kasse's
existing host Caddy (which owns 80/443). So the bundled Caddy stays off (it's
behind `profiles: [edge]`); run the default `podman compose up -d --build`.
The services publish loopback-only ports for the host Caddy to reach:
- portal → `127.0.0.1:3050`
- kanidm → `127.0.0.1:8443` (internal self-signed TLS)
- nats → `127.0.0.1:4223` (kasse's shared platform NATS owns 4222)
Add two host-Caddy site blocks in `/etc/caddy/conf.d/`, using the vel's `.env`
hosts (`vel.klingenbergbygg.no → :3050` already exists):
```
<PORTAL_HOST> {
reverse_proxy localhost:3050
}
<ID_HOST> {
reverse_proxy https://localhost:8443 {
transport http { tls_insecure_skip_verify }
}
}
```
Then `sudo systemctl reload caddy`, point the content repo's `lint-and-reload`
reload step at `nats://127.0.0.1:4223`, and retire the old systemd portal:
`sudo systemctl disable --now app@tomtervel-portal`.
## People and desks
Each group in the content (`qualifies:` under `questions/`) is a