Commit Graph
4 Commits
Author SHA1 Message Date
blandClaude Opus 4.8 debc0c9149 vel isolation on kasse: own Kanidm(:8443)+NATS(:4223) behind the host Caddy
deploy / deploy (push) Canceled after 0s
The vel keeps its own identity+bus so it can later lift onto a host of its own
unchanged. On kasse it runs in isolation fronted by kasse's host Caddy: kanidm
publishes 127.0.0.1:8443 (shared Kanidm is on 8310) and nats publishes
127.0.0.1:4223 (kasse's shared platform NATS owns 4222). README documents the
two conf.d site blocks (portal -> :3050, id -> https://localhost:8443 with
tls_insecure_skip_verify), the reload port, and the app@ handoff.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:31:14 +02:00
blandClaude Opus 4.8 74c120dc30 podman/caddy: fit kasse's single-front-Caddy model
deploy / deploy (push) Canceled after 0s
- caddy -> profiles: [edge]: on kasse the host Caddy already owns 80/443 and
  reverse-proxies vel.klingenbergbygg.no -> 127.0.0.1:3050, so the bundled
  Caddy is off by default (use `--profile edge` only on a standalone host)
- portal publishes 127.0.0.1:3050 so the host Caddy reaches it; the existing
  conf.d/vel.klingenbergbygg.no target is unchanged

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 12:15:30 +02:00
blandClaude Opus 4.8 de93e108ad podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
deploy / deploy (push) Canceled after 0s
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful
  (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP
- compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the
  host gitea-runner already covers it; pin the project network to 172.18.0.0/16
  so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose
  default pool hands out unmatched 10.89.x addresses
- README / deploy.yml: podman + host-runner notes

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 11:15:29 +02:00
blandClaude Fable 5.1 29f2b9daec Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
deploy / deploy (push) Canceled after 0s
One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 19:06:31 +02:00