Files
infrastructure/.gitea/workflows/deploy.yml
T
blandClaude Opus 4.8 de93e108ad
deploy / deploy (push) Canceled after 0s
podman: make the stack podman-friendly (drop docker.sock runner, pin XFF subnet)
- bootstrap.sh / kanidm-setup.sh: docker compose -> podman compose; run rootful
  (as root) so Caddy can bind 80/443 and Kanidm sees a stable source IP
- compose.yml: remove the in-compose act_runner (it mounted docker.sock) — the
  host gitea-runner already covers it; pin the project network to 172.18.0.0/16
  so Kanidm's X-Forwarded-For trust (172.16/12) stays valid under Podman, whose
  default pool hands out unmatched 10.89.x addresses
- README / deploy.yml: podman + host-runner notes

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 11:15:29 +02:00

31 lines
882 B
YAML

# Deploy from this repo onto the vel's own host (kasse). There is no
# `tomtervel`-labelled runner, so this workflow queues and does nothing;
# deploy by hand on the host with:
# cd /srv/tomtervel/infrastructure && git pull --ff-only && sudo sh bootstrap.sh
# (bootstrap.sh runs `podman compose up -d --build`, rootful). Rolling out
# a new portal version is a commit that bumps PORTAL_RELEASE in .env.example
# and, on the host, in .env.
name: deploy
on:
push:
branches: [main]
paths:
- compose.yml
- Caddyfile
- portal/**
- kanidm/server.toml.tpl
- nats/nats.conf.tpl
- .gitea/workflows/deploy.yml
workflow_dispatch:
jobs:
deploy:
runs-on: tomtervel
steps:
- name: Pull and restart
run: |
set -eu
cd /srv/tomtervel/infrastructure
git pull --ff-only
sh bootstrap.sh