No description
Find a file
Lars Rossen 77f361120a portainer: fix admin bootstrap and the published-domain derivation
First live install on lab1 surfaced two bugs.

Portainer 2.39.6 refuses POST /api/users/admin/init with 403 unless the
X-Setup-Token header carries the token it prints once at startup; update.sh now
reads it out of podman logs, matching the 64-hex value because the log line puts
ANSI colour codes between the key and the token.

The domain fallback asked get_variant_config for the DEFAULT environment, so a
module installed into lab1 advertised portainer-lab1.makerfloss.eu while Caddy
actually publishes portainer-lab1.lab1.makerfloss.eu — which would also have put
a mismatched RedirectURI into Portainer's OAuth settings. It now derives from the
module's own environment, as identity/install-service.sh does.

Confirmed on the live system: identity:identity works — the OIDC application is
created and /etc/secrets/portainer.env is written before install.sh runs.
2026-08-24 20:55:26 +02:00
src portainer: fix admin bootstrap and the published-domain derivation 2026-08-24 20:55:26 +02:00
.gitignore Seed the MakerFLOSS devops repo with the podman module 2026-08-22 18:46:24 +02:00
README.md Add portainer and komodo as parallel container-management modules 2026-08-23 09:45:01 +02:00

makerfloss

The MakerFLOSS DevOps repository for experimental TAPPaaS modules.

Modules are developed and tried out here, on the TAPPaaS system at makerfloss.eu, before they are proposed upstream to TAPPaaS or Community. Expect things to be half-built, renamed, or removed.

Layout

src/module-catalog.json      # the registry a TAPPaaS instance reads
src/containers/podman/       # one directory per module

Using it from a TAPPaaS instance

Register the repository on the tappaas-cicd mothership, then install a module from it:

site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main

module-manager module add podman --environment <env>

--branch main is not optional: repository add defaults to stable, and this repo has no such branch. The repository name (makerfloss) is derived from the URL, and the clone is made over HTTPS.

Modules

Three parallel takes on the same job — run containers on a lab host, let registered people manage them, reach the other hosts in the zone. They exist side by side on purpose.

Module What it is Status
portainer Portainer CE on rootful Podman; OIDC login, agents on other hosts incomplete — the one the session uses
komodo GPL Core + Periphery alternative; scaffold, scripts specified but not written scaffold
podman Plain Podman host with the Cockpit console; single host, local login incomplete

Why three: Cockpit turned out to fit neither requirement — it is not an OIDC client and cannot be made one, and its multi-host switcher is deprecated and disabled by default because it "cannot be secure". The reasoning is written up in podman/DESIGN.md.