Commit Graph
10 Commits
Author SHA1 Message Date
blandClaude Opus 5 0967b9973b The login page says whose it is
Kanidm out of the box presents itself: its own name, its own mark. A
neighbour landing on a login page that belongs to nobody in particular
is right to hesitate about typing a password into it.

The setup script now sets the vel's display name and logo on both the
instance and the portal client. The logo comes from the content repo -
the same images/logo.svg site.yaml already uses as the favicon - so
the login page and the site are branded from one place, and the
branding follows the content rather than this repo.

Left alone deliberately: account recovery by email, and easter eggs.
Both are decisions, not decoration, and the README says so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 21:43:17 +02:00
bl 81233498d3 kanidm-setup: do not ask to log in when already signed in 2026-09-28 21:01:12 +02:00
bl ea82e83d1f portal image: a base at least as new as the builder's glibc
deploy / deploy (push) Failing after 1m0s
2026-09-28 20:56:58 +02:00
bl 3222892605 gdo image: trust the registry's key instead of skipping the check
deploy / deploy (push) Failing after 3s
2026-09-28 20:53:41 +02:00
blandClaude Opus 5 d482ac43c2 gdo in the vel's own stack, and portal v0.5.2
deploy / deploy (push) Failing after 2s
The mailer moves in. Portal decides what to send and publishes it on
this NATS; gdo is what hands it to a mail server, and it belongs here
rather than shared, so the vel's mail leaves on the vel's own terms. It
has no mail server of its own and relays through the host's - on kasse,
Klingenberg Bygg's postfix - which is the one thing this stack borrows
and the one line that changes if the vel ever gets a host of its own.

Also:

- portal v0.5.2, four releases on from the v0.3.36 this pinned.
- The Kanidm setup makes the onboarding service account and its token.
  The vel's desks invite neighbours, and portal needs a token to do it;
  without one every invite fails closed. It goes in
  idm_people_on_boarding, which may create a person and issue a first
  credential reset and nothing else, plus idm_people_pii_read so an
  invite finds someone who already has an account instead of making
  them a second one.
- The deploy workflow runs. It was pointed at a `tomtervel` runner
  label that has never existed, so every push queued and did nothing.
  It now runs on kasse's host runner, which is not root and may run one
  argumentless script that pulls this repo and brings the stack up.
- The hosts default to vel.klingenbergbygg.no and
  id.vel.klingenbergbygg.no, which is where this actually runs. Both
  already resolve to kasse.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 20:37:07 +02:00
blandClaude Opus 4.8 debc0c9149 vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy
deploy / deploy (push) Canceled after 0s
The vel keeps its own identity+bus so it can later lift onto a host of its own
unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm
publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes
127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the
two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with
tls_insecure_skip_verify), the reload port, and the app@ handoff.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:31:14 +02:00
blandClaude Opus 4.8 74c120dc30 podman/caddy: fit kasse's single-front-Caddy model
deploy / deploy (push) Canceled after 0s
- caddy -> profiles: [edge]: on kasse the host Caddy already owns 80/443 and
  reverse-proxies vel.klingenbergbygg.no -> 127.0.0.1:3050, so the bundled
  Caddy is off by default (use `--profile edge` only on a standalone host)
- portal publishes 127.0.0.1:3050 so the host Caddy reaches it; the existing
  conf.d/vel.klingenbergbygg.no target is unchanged

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:15:30 +02:00
blandClaude Opus 4.8 de93e108ad podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful
  (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP
- compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the
  host gitea-runner already covers it; pin the project network to 172.18.0.0/16
  so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose
  default pool hands out unmatched 10.89.x addresses
- README / deploy.yml: podman + host-runner notes

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 11:15:29 +02:00
blandClaude Fable 5.1 506cb84e82 Desk groups are the committees
One Kanidm group per committee, named as the content names them, plus
kasserer, styret, komiteer and nabohjelp.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-23 06:48:31 +02:00
blandClaude Fable 5.1 29f2b9daec Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 19:06:31 +02:00