Files
infrastructure/kanidm-setup.sh
T
blandClaude Fable 5.1 29f2b9daec
deploy / deploy (push) Canceled after 0s
Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 19:06:31 +02:00

47 lines
2.1 KiB
Bash
Executable File

#!/bin/sh
# The portal's OAuth2 client and one Kanidm group per desk, mapped into
# the `groups` claim under the names the pages use in `qualifies`.
# Portal reads that claim at login (portal src/auth.rs). Rerunnable.
#
# Logs in first (interactive, idm_admin's password from bootstrap.sh),
# then writes the client secret into .env and portal.env and restarts
# the portal. Needs the kanidm CLI on this machine.
set -eu
cd "$(dirname "$0")"
. ./.env
K="kanidm -D idm_admin -H https://$ID_HOST"
C=$OAUTH2_CLIENT_ID
$K login
has_client() { $K system oauth2 get "$1" 2>/dev/null | grep -q '^name:'; }
has_group() { $K group get "$1" 2>/dev/null | grep -q '^name:'; }
has_client $C || $K system oauth2 create $C "$SITE_NAME" "https://$PORTAL_HOST"
$K system oauth2 add-redirect-url $C "https://$PORTAL_HOST/auth/callback" || true
# The desk groups: every group the content gates a directory on. Keep
# this list equal to the `qualifies` values under questions/.
has_group tomtervel_members || $K group create tomtervel_members
for g in kasserer styret trafikkomite lekeplasskomite arrangementskomite nabohjelp komiteer; do
has_group tomtervel_$g || $K group create tomtervel_$g
$K group add-members tomtervel_members tomtervel_$g
done
# Portal asks for openid, profile and email; groups arrive as a claim.
$K system oauth2 update-scope-map $C tomtervel_members openid profile email
for g in kasserer styret trafikkomite lekeplasskomite arrangementskomite nabohjelp komiteer; do
$K system oauth2 update-claim-map $C groups tomtervel_$g $g
done
$K system oauth2 update-claim-map-join $C groups array
secret=$($K system oauth2 show-basic-secret $C 2>/dev/null | tail -1)
sed -i "s|^OAUTH2_CLIENT_SECRET=.*|OAUTH2_CLIENT_SECRET=$secret|" .env portal.env
docker compose restart portal
echo "client $C configured; portal restarted with its secret"
echo
echo "Give people their desk (membership is read at login):"
echo " $K group add-members tomtervel_styret <person>"
echo "Create a person:"
echo " $K person create <name> '<Display Name>' && $K person update <name> --mail <email>"
echo " $K person credential create-reset-token <name>"