Files
infrastructure/.env.example
T
blandClaude Opus 5 d482ac43c2
deploy / deploy (push) Failing after 2s
gdo in the vel's own stack, and portal v0.5.2
The mailer moves in. Portal decides what to send and publishes it on
this NATS; gdo is what hands it to a mail server, and it belongs here
rather than shared, so the vel's mail leaves on the vel's own terms. It
has no mail server of its own and relays through the host's - on kasse,
Klingenberg Bygg's postfix - which is the one thing this stack borrows
and the one line that changes if the vel ever gets a host of its own.

Also:

- portal v0.5.2, four releases on from the v0.3.36 this pinned.
- The Kanidm setup makes the onboarding service account and its token.
  The vel's desks invite neighbours, and portal needs a token to do it;
  without one every invite fails closed. It goes in
  idm_people_on_boarding, which may create a person and issue a first
  credential reset and nothing else, plus idm_people_pii_read so an
  invite finds someone who already has an account instead of making
  them a second one.
- The deploy workflow runs. It was pointed at a `tomtervel` runner
  label that has never existed, so every push queued and did nothing.
  It now runs on kasse's host runner, which is not root and may run one
  argumentless script that pulls this repo and brings the stack up.
- The hosts default to vel.klingenbergbygg.no and
  id.vel.klingenbergbygg.no, which is where this actually runs. Both
  already resolve to kasse.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 20:37:07 +02:00

34 lines
1.3 KiB
Bash

# Copy to .env and fill in. Everything rendered from this (nats.conf,
# kanidm/server.toml, portal.env) is gitignored.
# Where the site and the identity provider are served. Both need an A
# record pointing at this host before the first start (Caddy gets the
# certificates over HTTP-01). tomtervel.no itself stays where it is
# until the vel decides to point the apex here.
PORTAL_HOST=vel.klingenbergbygg.no
ID_HOST=id.vel.klingenbergbygg.no
# The portal version to run: a tag of https://project.uhhm.no/uhhm/portal
PORTAL_RELEASE=v0.5.2
# The content this instance serves, and reloads live on every push.
CONTENT_REPO=https://prosjekt.klingenbergbygg.no/tomtervel/questions
CONTENT_BRANCH=main
SITE_NAME=Tomter Vel
# Generated once by bootstrap.sh if left empty.
NATS_PASSWORD=
# Filled in by bootstrap.sh after it creates the Kanidm client.
OAUTH2_CLIENT_ID=tomtervel-portal
OAUTH2_CLIENT_SECRET=
# Only for the optional runner profile: a registration token from
# prosjekt.klingenbergbygg.no -> tomtervel org -> Settings -> Actions -> Runners.
RUNNER_REGISTRATION_TOKEN=
# The gdo version to run: a tag of https://project.uhhm.no/uhhm/gdo,
# installed from the [uhhm] Arch registry. gdo hands the vel's mail to
# the host's mail server; on kasse that is Klingenberg Bygg's postfix.
GDO_RELEASE=v0.2.0