makerfloss/README.md
Lars Rossen 1ca204c405 podman: write up how (and whether) it can integrate with identity
Cockpit is not an OIDC client and cannot be configured into one, so
identity:identity is the wrong dependency. Records the three real options —
accessControl URL gating, an Authentik LDAP outpost with SSSD, and a custom
Cockpit auth command — with the recommendation to take the first, raise the
second upstream, and leave the third alone.

Also flags that accessControl's install-service requires proxyDomain in the
resolved config and, unlike identity's, does not derive it — to verify on a
live install before relying on it.
2026-08-22 20:40:25 +02:00

39 lines
1.3 KiB
Markdown

# makerfloss
The MakerFLOSS **DevOps repository** for experimental TAPPaaS modules.
Modules are developed and tried out here, on the TAPPaaS system at
[makerfloss.eu](https://makerfloss.eu), before they are proposed upstream to
[TAPPaaS](https://codeberg.org/TAPPaaS/TAPPaaS) or
[Community](https://codeberg.org/TAPPaaS/Community). Expect things to be
half-built, renamed, or removed.
## Layout
```text
src/module-catalog.json # the registry a TAPPaaS instance reads
src/containers/podman/ # one directory per module
```
## Using it from a TAPPaaS instance
Register the repository on the `tappaas-cicd` mothership, then install a module
from it:
```bash
site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main
module-manager module add podman --environment <env>
```
`--branch main` is not optional: `repository add` defaults to `stable`, and this
repo has no such branch. The repository name (`makerfloss`) is derived from the
URL, and the clone is made over HTTPS.
## Modules
| Module | What it is | Status |
| --- | --- | --- |
| [podman](src/containers/podman) | Debian 13 VM with rootless Podman + the Cockpit web console | incomplete |
Open work on `podman`: identity integration — see its [DESIGN.md](src/containers/podman/DESIGN.md#identity-integration--the-analysis).