# makerfloss The MakerFLOSS **DevOps repository** for experimental TAPPaaS modules. Modules are developed and tried out here, on the TAPPaaS system at [makerfloss.eu](https://makerfloss.eu), before they are proposed upstream to [TAPPaaS](https://codeberg.org/TAPPaaS/TAPPaaS) or [Community](https://codeberg.org/TAPPaaS/Community). Expect things to be half-built, renamed, or removed. ## Layout ```text src/module-catalog.json # the registry a TAPPaaS instance reads src/containers/podman/ # one directory per module ``` ## Using it from a TAPPaaS instance Register the repository on the `tappaas-cicd` mothership, then install a module from it: ```bash site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main module-manager module add podman --environment ``` `--branch main` is not optional: `repository add` defaults to `stable`, and this repo has no such branch. The repository name (`makerfloss`) is derived from the URL, and the clone is made over HTTPS. ## Modules Two takes on the same job — run containers on a lab host, let registered people manage them, reach the other hosts in the zone. | Module | What it is | Status | | --- | --- | --- | | [podman](src/containers/podman) | Podman engine + Portainer CE console; OIDC login, agents on other hosts | incomplete — **the one the session uses** | | [komodo](src/containers/komodo) | GPL Core + Periphery alternative; scaffold, scripts specified but not written | scaffold | `podman` absorbed the former standalone `portainer` module: Podman is the container foundation, Portainer is the GUI onto it, one VM. Cockpit was dropped because it fits neither requirement — it is not an OIDC client and cannot be made one, and its multi-host switcher is deprecated and disabled by default because it "cannot be secure". The reasoning is in [podman/DESIGN.md](src/containers/podman/DESIGN.md#identity-integration--the-analysis).