diff --git a/.env.example b/.env.example index 2173ff2..90e1a84 100644 --- a/.env.example +++ b/.env.example @@ -9,7 +9,7 @@ PORTAL_HOST=vel.klingenbergbygg.no ID_HOST=id.vel.klingenbergbygg.no # The portal version to run: a tag of https://project.uhhm.no/uhhm/portal -PORTAL_RELEASE=v0.5.8 +PORTAL_RELEASE=v0.5.10 # The content this instance serves, and reloads live on every push. CONTENT_REPO=https://prosjekt.klingenbergbygg.no/tomtervel/questions @@ -31,6 +31,12 @@ SEED_ADMIN_NAME= # and joins this group. Kanidm names are ASCII: redaktor, "Redaktør". RESPONSIBLE_GROUP=redaktor +# Where the groups live. `memberships`: portal keeps them itself, a person +# is their phone number first, and Kanidm only makes the account (until a +# sign-in everyone already has, like Vipps, takes over). Unset: Kanidm +# holds the groups too. +PEOPLE_BACKEND=memberships + # A project Gitea they may sign in to with the same account: kanidm-setup # makes its OAuth2 client (only RESPONSIBLE_GROUP may use it) and, on the # host that runs that Gitea, adds the sign-in source. Empty: no Gitea. diff --git a/kanidm-setup.sh b/kanidm-setup.sh index 1423cd2..d931fcc 100755 --- a/kanidm-setup.sh +++ b/kanidm-setup.sh @@ -181,6 +181,9 @@ fi if [ -n "${SEED_ADMIN_EMAIL:-}" ]; then setenv SEED_ADMIN_EMAIL "$SEED_ADMIN_EMAIL"; fi if [ -n "${SEED_ADMIN_NAME:-}" ]; then setenv SEED_ADMIN_NAME "$SEED_ADMIN_NAME"; fi if [ -n "${RESPONSIBLE_GROUP:-}" ]; then setenv RESPONSIBLE_GROUP "$RESPONSIBLE_GROUP"; fi +# Where the groups live: `memberships` keeps them in portal, and this +# Kanidm only makes the accounts (portal docs, Memberships). +if [ -n "${PEOPLE_BACKEND:-}" ]; then setenv PEOPLE_BACKEND "$PEOPLE_BACKEND"; fi podman compose up -d portal echo "portal restarted: signs in through $C, onboards through $SA, desks: $(echo $groups)"