#!/bin/sh # First start on a fresh host. Idempotent: rerunning renders configs # again and skips what exists. Needs docker with the compose plugin, # openssl, and DNS for PORTAL_HOST and ID_HOST already pointing here. # # cp .env.example .env # fill in the hosts # sh bootstrap.sh set -eu cd "$(dirname "$0")" [ -f .env ] || { echo "copy .env.example to .env and fill it in first"; exit 1; } . ./.env # A NATS password, once. if [ -z "${NATS_PASSWORD:-}" ]; then NATS_PASSWORD=$(openssl rand -base64 36 | tr -d '/+=' | cut -c1-40) sed -i "s|^NATS_PASSWORD=.*|NATS_PASSWORD=$NATS_PASSWORD|" .env echo "NATS_PASSWORD generated into .env" fi # Rendered configs (gitignored). sed "s|\${ID_HOST}|$ID_HOST|g" kanidm/server.toml.tpl > kanidm/server.toml sed "s|\${NATS_PASSWORD}|$NATS_PASSWORD|g" nats/nats.conf.tpl > nats/nats.conf cat > portal.env </dev/null 2>&1 chmod 600 certs/kanidm-key.pem echo "internal Kanidm certificate made" fi docker compose up -d --build echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOST" # The Kanidm admin accounts exist only after the first start; their # passwords are set by recovery. Do this once; the output is the # password, shown once. if [ ! -f .kanidm-recovered ]; then echo echo "=== Kanidm admin recovery (write these passwords down) ===" docker compose exec kanidm kanidmd recover-account admin docker compose exec kanidm kanidmd recover-account idm_admin touch .kanidm-recovered fi echo echo "Next: sh kanidm-setup.sh (log in as idm_admin, create the portal client and desk groups)"