Files
infrastructure/bootstrap.sh
T
blandClaude Opus 4.8 de93e108ad
deploy / deploy (push) Canceled after 0s
podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful
  (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP
- compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the
  host gitea-runner already covers it; pin the project network to 172.18.0.0/16
  so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose
  default pool hands out unmatched 10.89.x addresses
- README / deploy.yml: podman + host-runner notes

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 11:15:29 +02:00

63 lines
2.2 KiB
Bash
Executable File

#!/bin/sh
# First start on a fresh host. Idempotent: rerunning renders configs
# again and skips what exists. Needs podman + podman-compose and openssl,
# and DNS for PORTAL_HOST and ID_HOST already pointing here. Run rootful
# (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP.
#
# cp .env.example .env # fill in the hosts
# sudo sh bootstrap.sh
set -eu
cd "$(dirname "$0")"
[ -f .env ] || { echo "copy .env.example to .env and fill it in first"; exit 1; }
. ./.env
# A NATS password, once.
if [ -z "${NATS_PASSWORD:-}" ]; then
NATS_PASSWORD=$(openssl rand -base64 36 | tr -d '/+=' | cut -c1-40)
sed -i "s|^NATS_PASSWORD=.*|NATS_PASSWORD=$NATS_PASSWORD|" .env
echo "NATS_PASSWORD generated into .env"
fi
# Rendered configs (gitignored).
sed "s|\${ID_HOST}|$ID_HOST|g" kanidm/server.toml.tpl > kanidm/server.toml
sed "s|\${NATS_PASSWORD}|$NATS_PASSWORD|g" nats/nats.conf.tpl > nats/nats.conf
cat > portal.env <<EOF
NATS_URL=nats://portal:$NATS_PASSWORD@nats:4222
KANIDM_URL=https://$ID_HOST
OAUTH2_CLIENT_ID=$OAUTH2_CLIENT_ID
OAUTH2_CLIENT_SECRET=${OAUTH2_CLIENT_SECRET:-}
PUBLIC_URL=https://$PORTAL_HOST
COOKIE_SECURE=true
CONTENT_REPO=$CONTENT_REPO
CONTENT_BRANCH=$CONTENT_BRANCH
SITE_NAME=$SITE_NAME
EOF
chmod 600 portal.env
# Kanidm's internal certificate: Caddy holds the public one.
mkdir -p certs
if [ ! -f certs/kanidm-key.pem ]; then
openssl req -x509 -newkey rsa:2048 -nodes -days 3650 \
-subj "/CN=kanidm" -addext "subjectAltName=DNS:kanidm,DNS:$ID_HOST" \
-keyout certs/kanidm-key.pem -out certs/kanidm-chain.pem >/dev/null 2>&1
chmod 600 certs/kanidm-key.pem
echo "internal Kanidm certificate made"
fi
podman compose up -d --build
echo "containers up; Caddy is fetching certificates for $PORTAL_HOST and $ID_HOST"
# The Kanidm admin accounts exist only after the first start; their
# passwords are set by recovery. Do this once; the output is the
# password, shown once.
if [ ! -f .kanidm-recovered ]; then
echo
echo "=== Kanidm admin recovery (write these passwords down) ==="
podman compose exec kanidm kanidmd recover-account admin
podman compose exec kanidm kanidmd recover-account idm_admin
touch .kanidm-recovered
fi
echo
echo "Next: sh kanidm-setup.sh (log in as idm_admin, create the portal client and desk groups)"