Files
infrastructure/kanidm/server.toml.tpl
T
blandClaude Fable 5.1 29f2b9daec
deploy / deploy (push) Canceled after 0s
Tomter Vel's own platform: Caddy, NATS, Kanidm and portal as containers
One host, four containers, content fetched from tomtervel/questions.
bootstrap.sh renders configs from .env and recovers the Kanidm admin;
kanidm-setup.sh creates the portal client and the desk groups. An
optional runner profile lets the content repo's reload reach this host.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 19:06:31 +02:00

31 lines
841 B
Smarty

# Kanidm server configuration. bootstrap.sh renders this into
# server.toml from .env; edit the template, not the rendered file.
# Reference: https://kanidm.github.io/kanidm/stable/server_configuration.html
version = "2"
bindaddress = "0.0.0.0:8443"
# Internal self-signed pair made by bootstrap.sh; Caddy terminates the
# public certificate and proxies here with verification disabled.
tls_chain = "/data/chain.pem"
tls_key = "/data/key.pem"
db_path = "/data/kanidm.db"
db_fs_type = "other"
db_arc_size = 2048
log_level = "info"
# domain must equal the DNS name Kanidm is served at.
domain = "${ID_HOST}"
origin = "https://${ID_HOST}"
# Trust X-Forwarded-For from Caddy on the compose network.
[http_client_address_info]
x-forward-for = ["172.16.0.0/12"]
[online_backup]
path = "/data/backups/"
schedule = "00 22 * * *"
versions = 7