Commit graph

4 commits

Author SHA1 Message Date
8b981ecdea feat(signage): scaffold bare Debian VM module
New src/apps/signage: Debian 13 VM, 1 core / 1G / 16G (vmid 816), deps cluster:vm + templates:debian + backup:vm. update.sh confirms the VM is up and records a version marker; signage software layered on in a later pass. Registered in module-catalog.json.
2026-09-01 22:14:54 +02:00
Lars Rossen
04b4437c95 Merge portainer into podman: engine plus GUI in one module
Podman is the container foundation, Portainer CE is the web interface onto it,
running as a container on the very engine it manages. This is what the separate
portainer module already did, so it is retired rather than duplicated.

Two sockets on purpose: the rootful one is the Docker-compatible API Portainer
drives (it does not support rootless), the rootless user socket is for people
who ssh in and run containers by hand — which was the original podman module's
point and is worth keeping.

An explicit proxyDomain lets the module publish at the environment's own domain
instead of <module>.<environment-domain>, making it that environment's gateway.

DESIGN.md keeps the Cockpit identity analysis: it is the reason for the change,
and anyone proposing 'just put Cockpit behind forward-auth' should read it.
2026-08-25 09:30:11 +02:00
Lars Rossen
bca395d7f9 Add portainer and komodo as parallel container-management modules
portainer: Portainer CE on rootful podman (Portainer drives the
Docker-compatible API, and rootless is not supported upstream), published via
network:proxy with proxyAllowedZones left unset so members reach it from a
client zone but the internet does not. Login is OIDC: identity:identity writes
the client credentials, update.sh resolves the endpoints from the discovery
document and PUTs them into /api/settings. A break-glass local admin stays for
when Authentik is down. Multi-host is the agent on :9001 per host.

komodo: scaffold only — komodo.json plus a README that specifies what
install.sh and update.sh must do. GPL, no edition split, but it needs a
database and models builds and stacks, so it is the alternative rather than
the teaching example.

Neither has been run on a live TAPPaaS yet; both are catalogued as incomplete.
2026-08-23 09:45:01 +02:00
Lars Rossen
1dba304085 Seed the MakerFLOSS devops repo with the podman module
README, a module-catalog.json validated against TAPPaaS's
module-catalog-fields.json, and the podman module copied verbatim from
Community/src/larsrossen/containers/podman into a flat src/containers/ layout
(the catalog carries the explicit moduleJson path, so layout is free).
2026-08-22 18:46:24 +02:00