Commit Graph
16 Commits
Author SHA1 Message Date
blandClaude Fable 5.1 88c16d0fc1 kanidm-setup: become the gitea user as root; README: postfix relays from the containers
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-30 08:04:16 +02:00
blandClaude Fable 5.1 ba2da8f3b6 portal v0.5.5: a record answered from a list; no fixed arrow
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-30 07:52:39 +02:00
blandClaude Fable 5.1 c4b3cc86d5 portal v0.5.4: accounts from the content, invites that can be sent again
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-29 21:39:25 +02:00
blandClaude Opus 5.5 b653536391 kanidm-setup, all the way: desk groups from the content, no prefix, onboarding that works, the first person, redaktør, and Gitea sign-in
The desk groups are read from the content's qualifies: and named as it
names them - this Kanidm is the vel's own - with the old tomtervel_*
groups renamed in place. The onboarding account manages every desk
group, since adding a member takes that right (measured: 404 without).
Sign-in scopes to idm_all_persons. SEED_ADMIN_EMAIL and
RESPONSIBLE_GROUP (redaktor) reach portal.env, and bootstrap no longer
drops the onboarding token when it rewrites portal.env. A second OAuth2
client lets redaktor sign in to prosjekt.klingenbergbygg.no; on the
Gitea host the script adds that sign-in source itself.

The login page's own name and logo need the admin account; the script
now says so rather than failing with 'Item not found'. .env.example
quotes SITE_NAME, which has a space and broke sourcing it.

Tested end to end against a local Kanidm 1.11.2, including a rerun and
a legacy tomtervel_kasserer with a member.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-29 15:45:41 +02:00
blandClaude Opus 5.5 415dea7230 portal v0.5.3: a way down the tree from every page
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-29 13:36:24 +02:00
blandClaude Opus 5 b7e8e0313e Match the Kanidm server to the CLI, and say why a token failed
deploy / deploy (push) Successful in 33s
Three things in one setup run, two of them mine.

The server image was 1.11.1 while the host's CLI is 1.11.2, and a
1.11.2 client looks up the domain entry at a UUID 1.11.1 does not
have. So `system domain set-displayname` and `set-image` both failed
with "Item not found", which says nothing about versions. The CLI had
been warning about the mismatch on every single call. Image bumped to
1.11.2; the README says to keep them together and which one to move.

The onboarding token asked for `--rw`, and the flag is spelled
`--readwrite`. The script swallowed stderr and reported a bare warning,
so a step that leaves every invite failing closed said nothing about
why. It now passes the right flag, and if it still fails it says what
the CLI said and prints the command to retry by hand.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 22:24:08 +02:00
blandClaude Opus 5 0967b9973b The login page says whose it is
Kanidm out of the box presents itself: its own name, its own mark. A
neighbour landing on a login page that belongs to nobody in particular
is right to hesitate about typing a password into it.

The setup script now sets the vel's display name and logo on both the
instance and the portal client. The logo comes from the content repo -
the same images/logo.svg site.yaml already uses as the favicon - so
the login page and the site are branded from one place, and the
branding follows the content rather than this repo.

Left alone deliberately: account recovery by email, and easter eggs.
Both are decisions, not decoration, and the README says so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 21:43:17 +02:00
bl 81233498d3 kanidm-setup: do not ask to log in when already signed in 2026-09-28 21:01:12 +02:00
bl ea82e83d1f portal image: a base at least as new as the builder's glibc
deploy / deploy (push) Failing after 1m0s
2026-09-28 20:56:58 +02:00
bl 3222892605 gdo image: trust the registry's key instead of skipping the check
deploy / deploy (push) Failing after 3s
2026-09-28 20:53:41 +02:00
blandClaude Opus 5 d482ac43c2 gdo in the vel's own stack, and portal v0.5.2
deploy / deploy (push) Failing after 2s
The mailer moves in. Portal decides what to send and publishes it on
this NATS; gdo is what hands it to a mail server, and it belongs here
rather than shared, so the vel's mail leaves on the vel's own terms. It
has no mail server of its own and relays through the host's - on kasse,
Klingenberg Bygg's postfix - which is the one thing this stack borrows
and the one line that changes if the vel ever gets a host of its own.

Also:

- portal v0.5.2, four releases on from the v0.3.36 this pinned.
- The Kanidm setup makes the onboarding service account and its token.
  The vel's desks invite neighbours, and portal needs a token to do it;
  without one every invite fails closed. It goes in
  idm_people_on_boarding, which may create a person and issue a first
  credential reset and nothing else, plus idm_people_pii_read so an
  invite finds someone who already has an account instead of making
  them a second one.
- The deploy workflow runs. It was pointed at a `tomtervel` runner
  label that has never existed, so every push queued and did nothing.
  It now runs on kasse's host runner, which is not root and may run one
  argumentless script that pulls this repo and brings the stack up.
- The hosts default to vel.klingenbergbygg.no and
  id.vel.klingenbergbygg.no, which is where this actually runs. Both
  already resolve to kasse.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 20:37:07 +02:00
blandClaude Opus 4.8 debc0c9149 vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy
deploy / deploy (push) Canceled after 0s
The vel keeps its own identity+bus so it can later lift onto a host of its own
unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm
publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes
127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the
two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with
tls_insecure_skip_verify), the reload port, and the app@ handoff.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:31:14 +02:00
blandClaude Opus 4.8 74c120dc30 podman/caddy: fit kasse's single-front-Caddy model
deploy / deploy (push) Canceled after 0s
- caddy -> profiles: [edge]: on kasse the host Caddy already owns 80/443 and
  reverse-proxies vel.klingenbergbygg.no -> 127.0.0.1:3050, so the bundled
  Caddy is off by default (use `--profile edge` only on a standalone host)
- portal publishes 127.0.0.1:3050 so the host Caddy reaches it; the existing
  conf.d/vel.klingenbergbygg.no target is unchanged

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:15:30 +02:00
blandClaude Opus 4.8 de93e108ad podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful
  (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP
- compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the
  host gitea-runner already covers it; pin the project network to 172.18.0.0/16
  so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose
  default pool hands out unmatched 10.89.x addresses
- README / deploy.yml: podman + host-runner notes

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 11:15:29 +02:00
blandClaude Fable 5.1 506cb84e82 Desk groups are the committees
One Kanidm group per committee, named as the content names them, plus
kasserer, styret, komiteer and nabohjelp.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-23 06:48:31 +02:00
blandClaude Fable 5.1 29f2b9daec Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 19:06:31 +02:00