vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy
deploy / deploy (push) Canceled after 0s

The vel keeps its own identity+bus so it can later lift onto a host of its own
unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm
publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes
127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the
two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with
tls_insecure_skip_verify), the reload port, and the app@ handoff.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
bl
2026-09-28 12:31:14 +02:00
co-authored by Claude Opus 4.8
parent 74c120dc30
commit debc0c9149
2 changed files with 44 additions and 4 deletions
+14 -4
View File
@@ -45,10 +45,13 @@ services:
volumes:
- ./nats/nats.conf:/etc/nats/nats.conf:ro
- nats_data:/data
# Published so a runner or a person on the host can `nats pub
# portal.content.reload ""`; password-protected (see nats.conf).
# Published on the host so the reload job (`nats pub portal.content.reload ""`)
# can reach it; password-protected (see nats.conf). Host port 4223, not 4222:
# on kasse the shared platform NATS already owns 127.0.0.1:4222 and the vel
# runs its own NATS in isolation, so the reload workflow targets 4223 there.
# (Standalone, nothing else owns 4222, but 4223 is harmless.)
ports:
- "127.0.0.1:4222:4222"
- "127.0.0.1:4223:4222"
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://localhost:8222/healthz"]
interval: 10s
@@ -67,7 +70,14 @@ services:
# certificate and proxies here without verification.
- ./certs/kanidm-chain.pem:/data/chain.pem:ro
- ./certs/kanidm-key.pem:/data/key.pem:ro
# No published ports: only Caddy talks to it.
# Standalone (--profile edge): only the bundled Caddy talks to Kanidm.
# On kasse the host Caddy fronts it, so publish loopback-only for a conf.d
# entry: id.<vel> { reverse_proxy https://localhost:8443 {
# transport http { tls_insecure_skip_verify } } }
# (Kanidm's internal self-signed cert; 8443 is free on kasse — its shared
# Kanidm is on 8310.)
ports:
- "127.0.0.1:8443:8443"
portal:
build: