#!/bin/sh # First start on a fresh host. Idempotent: rerunning renders configs # again and skips what exists. Needs podman + podman-compose and openssl, # and DNS for PORTAL_HOST and ID_HOST already pointing here. Run rootful # (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP. # # cp .env.example .env # fill in the hosts # sudo sh bootstrap.sh set -eu cd "$(dirname "$0")" [ -f .env ] || { echo "copy .env.example to .env and fill it in first"; exit 1; } . ./.env # A NATS password, once. if [ -z "${NATS_PASSWORD:-}" ]; then NATS_PASSWORD=$(openssl rand -base64 36 | tr -d '/+=' | cut -c1-40) sed -i "s|^NATS_PASSWORD=.*|NATS_PASSWORD=$NATS_PASSWORD|" .env echo "NATS_PASSWORD generated into .env" fi # Rendered configs (gitignored). sed "s|\${ID_HOST}|$ID_HOST|g" kanidm/server.toml.tpl > kanidm/server.toml sed "s|\${NATS_PASSWORD}|$NATS_PASSWORD|g" nats/nats.conf.tpl > nats/nats.conf # The onboarding token is written by kanidm-setup.sh, once; a rerun of # this script must not lose it, or every invite fails closed again. kept_token=$(grep '^KANIDM_API_TOKEN=' portal.env 2>/dev/null | head -1 || true) cat > portal.env <> portal.env chmod 600 portal.env # Kanidm's internal certificate: Caddy holds the public one. mkdir -p certs if [ ! -f certs/kanidm-key.pem ]; then openssl req -x509 -newkey rsa:2048 -nodes -days 3650 \ -subj "/CN=kanidm" -addext "subjectAltName=DNS:kanidm,DNS:$ID_HOST" \ -keyout certs/kanidm-key.pem -out certs/kanidm-chain.pem >/dev/null 2>&1 chmod 600 certs/kanidm-key.pem echo "internal Kanidm certificate made" fi podman compose up -d --build echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOST" # The Kanidm admin accounts exist only after the first start; their # passwords are set by recovery. Do this once; the output is the # password, shown once. if [ ! -f .kanidm-recovered ]; then echo echo "=== Kanidm admin recovery (write these passwords down) ===" podman compose exec kanidm kanidmd recover-account admin podman compose exec kanidm kanidmd recover-account idm_admin touch .kanidm-recovered fi echo echo "Next: sh kanidm-setup.sh (log in as idm_admin, create the portal client and desk groups)"