vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy
deploy / deploy (push) Canceled after 0s
deploy / deploy (push) Canceled after 0s
The vel keeps its own identity+bus so it can later lift onto a host of its own unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes 127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with tls_insecure_skip_verify), the reload port, and the app@ handoff. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -34,6 +34,36 @@ sh kanidm-setup.sh # logs in, creates the portal client and desk groups,
|
|||||||
write them down. After `kanidm-setup.sh`, https://PORTAL_HOST serves the
|
write them down. After `kanidm-setup.sh`, https://PORTAL_HOST serves the
|
||||||
site and https://ID_HOST is the login.
|
site and https://ID_HOST is the login.
|
||||||
|
|
||||||
|
## Running on kasse (behind the host Caddy)
|
||||||
|
|
||||||
|
The vel keeps its **own** Kanidm and NATS here so it can later lift onto a host
|
||||||
|
of its own unchanged — on kasse it just runs in isolation, fronted by kasse's
|
||||||
|
existing host Caddy (which owns 80/443). So the bundled Caddy stays off (it's
|
||||||
|
behind `profiles: [edge]`); run the default `podman compose up -d --build`.
|
||||||
|
The services publish loopback-only ports for the host Caddy to reach:
|
||||||
|
|
||||||
|
- portal → `127.0.0.1:3050`
|
||||||
|
- kanidm → `127.0.0.1:8443` (internal self-signed TLS)
|
||||||
|
- nats → `127.0.0.1:4223` (kasse's shared platform NATS owns 4222)
|
||||||
|
|
||||||
|
Add two host-Caddy site blocks in `/etc/caddy/conf.d/`, using the vel's `.env`
|
||||||
|
hosts (`vel.klingenbergbygg.no → :3050` already exists):
|
||||||
|
|
||||||
|
```
|
||||||
|
<PORTAL_HOST> {
|
||||||
|
reverse_proxy localhost:3050
|
||||||
|
}
|
||||||
|
<ID_HOST> {
|
||||||
|
reverse_proxy https://localhost:8443 {
|
||||||
|
transport http { tls_insecure_skip_verify }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Then `sudo systemctl reload caddy`, point the content repo's `lint-and-reload`
|
||||||
|
reload step at `nats://127.0.0.1:4223`, and retire the old systemd portal:
|
||||||
|
`sudo systemctl disable --now app@tomtervel-portal`.
|
||||||
|
|
||||||
## People and desks
|
## People and desks
|
||||||
|
|
||||||
Each group in the content (`qualifies:` under `questions/`) is a
|
Each group in the content (`qualifies:` under `questions/`) is a
|
||||||
|
|||||||
+14
-4
@@ -45,10 +45,13 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- ./nats/nats.conf:/etc/nats/nats.conf:ro
|
- ./nats/nats.conf:/etc/nats/nats.conf:ro
|
||||||
- nats_data:/data
|
- nats_data:/data
|
||||||
# Published so a runner or a person on the host can `nats pub
|
# Published on the host so the reload job (`nats pub portal.content.reload ""`)
|
||||||
# portal.content.reload ""`; password-protected (see nats.conf).
|
# can reach it; password-protected (see nats.conf). Host port 4223, not 4222:
|
||||||
|
# on kasse the shared platform NATS already owns 127.0.0.1:4222 and the vel
|
||||||
|
# runs its own NATS in isolation, so the reload workflow targets 4223 there.
|
||||||
|
# (Standalone, nothing else owns 4222, but 4223 is harmless.)
|
||||||
ports:
|
ports:
|
||||||
- "127.0.0.1:4222:4222"
|
- "127.0.0.1:4223:4222"
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "wget", "--spider", "-q", "http://localhost:8222/healthz"]
|
test: ["CMD", "wget", "--spider", "-q", "http://localhost:8222/healthz"]
|
||||||
interval: 10s
|
interval: 10s
|
||||||
@@ -67,7 +70,14 @@ services:
|
|||||||
# certificate and proxies here without verification.
|
# certificate and proxies here without verification.
|
||||||
- ./certs/kanidm-chain.pem:/data/chain.pem:ro
|
- ./certs/kanidm-chain.pem:/data/chain.pem:ro
|
||||||
- ./certs/kanidm-key.pem:/data/key.pem:ro
|
- ./certs/kanidm-key.pem:/data/key.pem:ro
|
||||||
# No published ports: only Caddy talks to it.
|
# Standalone (--profile edge): only the bundled Caddy talks to Kanidm.
|
||||||
|
# On kasse the host Caddy fronts it, so publish loopback-only for a conf.d
|
||||||
|
# entry: id.<vel> { reverse_proxy https://localhost:8443 {
|
||||||
|
# transport http { tls_insecure_skip_verify } } }
|
||||||
|
# (Kanidm's internal self-signed cert; 8443 is free on kasse — its shared
|
||||||
|
# Kanidm is on 8310.)
|
||||||
|
ports:
|
||||||
|
- "127.0.0.1:8443:8443"
|
||||||
|
|
||||||
portal:
|
portal:
|
||||||
build:
|
build:
|
||||||
|
|||||||
Reference in New Issue
Block a user