Files
infrastructure/.env.example
T
blandClaude Opus 5.5 b653536391 kanidm-setup, all the way: desk groups from the content, no prefix, onboarding that works, the first person, redaktør, and Gitea sign-in
The desk groups are read from the content's qualifies: and named as it
names them - this Kanidm is the vel's own - with the old tomtervel_*
groups renamed in place. The onboarding account manages every desk
group, since adding a member takes that right (measured: 404 without).
Sign-in scopes to idm_all_persons. SEED_ADMIN_EMAIL and
RESPONSIBLE_GROUP (redaktor) reach portal.env, and bootstrap no longer
drops the onboarding token when it rewrites portal.env. A second OAuth2
client lets redaktor sign in to prosjekt.klingenbergbygg.no; on the
Gitea host the script adds that sign-in source itself.

The login page's own name and logo need the admin account; the script
now says so rather than failing with 'Item not found'. .env.example
quotes SITE_NAME, which has a space and broke sourcing it.

Tested end to end against a local Kanidm 1.11.2, including a rerun and
a legacy tomtervel_kasserer with a member.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-29 15:45:41 +02:00

52 lines
2.1 KiB
Bash

# Copy to .env and fill in. Everything rendered from this (nats.conf,
# kanidm/server.toml, portal.env) is gitignored.
# Where the site and the identity provider are served. Both need an A
# record pointing at this host before the first start (Caddy gets the
# certificates over HTTP-01). tomtervel.no itself stays where it is
# until the vel decides to point the apex here.
PORTAL_HOST=vel.klingenbergbygg.no
ID_HOST=id.vel.klingenbergbygg.no
# The portal version to run: a tag of https://project.uhhm.no/uhhm/portal
PORTAL_RELEASE=v0.5.3
# The content this instance serves, and reloads live on every push.
CONTENT_REPO=https://prosjekt.klingenbergbygg.no/tomtervel/questions
CONTENT_BRANCH=main
SITE_NAME="Tomter Vel"
# Generated once by bootstrap.sh if left empty.
NATS_PASSWORD=
# The first person in: portal invites this address into the site's most
# privileged group (the board, on the vel - the group whose desk may
# invite into the most groups) and mails them the one-time link, once.
# Everyone else they invite themselves, from their desk.
SEED_ADMIN_EMAIL=
SEED_ADMIN_NAME=
# The people who ask the questions: everyone a page names as
# responsible gets an account (portal makes it at start and mails them)
# and joins this group. Kanidm names are ASCII: redaktor, "Redaktør".
RESPONSIBLE_GROUP=redaktor
# A project Gitea they may sign in to with the same account: kanidm-setup
# makes its OAuth2 client (only RESPONSIBLE_GROUP may use it) and, on the
# host that runs that Gitea, adds the sign-in source. Empty: no Gitea.
GITEA_URL=https://prosjekt.klingenbergbygg.no
GITEA_AUTH_NAME=tomtervel
# Filled in by bootstrap.sh after it creates the Kanidm client.
OAUTH2_CLIENT_ID=tomtervel-portal
OAUTH2_CLIENT_SECRET=
# Only for the optional runner profile: a registration token from
# prosjekt.klingenbergbygg.no -> tomtervel org -> Settings -> Actions -> Runners.
RUNNER_REGISTRATION_TOKEN=
# The gdo version to run: a tag of https://project.uhhm.no/uhhm/gdo,
# installed from the [uhhm] Arch registry. gdo hands the vel's mail to
# the host's mail server; on kasse that is Klingenberg Bygg's postfix.
GDO_RELEASE=v0.2.0