lab1 is now published with proxyAllowedZones: [internet]. Enabling OAuth does not disable Portainer's internal login — POST /api/auth stays live and still accepts the break-glass admin, confirmed against the public endpoint (422 Invalid credentials, not a refused path). So publishing the console publishes a password path too; the remedy, if that is unacceptable, is to promote an OIDC user to administrator and delete the local admin, at the cost of break-glass. Also records that the operator's admin-VPN overlay (admin, 10.255.1.0/24) is not in the internal default allow-set, which is why a remote admin on the WireGuard tunnel also gets 403. |
||
|---|---|---|
| src | ||
| .gitignore | ||
| README.md | ||
makerfloss
The MakerFLOSS DevOps repository for experimental TAPPaaS modules.
Modules are developed and tried out here, on the TAPPaaS system at makerfloss.eu, before they are proposed upstream to TAPPaaS or Community. Expect things to be half-built, renamed, or removed.
Layout
src/module-catalog.json # the registry a TAPPaaS instance reads
src/containers/podman/ # one directory per module
Using it from a TAPPaaS instance
Register the repository on the tappaas-cicd mothership, then install a module
from it:
site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main
module-manager module add podman --environment <env>
--branch main is not optional: repository add defaults to stable, and this
repo has no such branch. The repository name (makerfloss) is derived from the
URL, and the clone is made over HTTPS.
Modules
Two takes on the same job — run containers on a lab host, let registered people manage them, reach the other hosts in the zone.
| Module | What it is | Status |
|---|---|---|
| podman | Podman engine + Portainer CE console; OIDC login, agents on other hosts | incomplete — the one the session uses |
| komodo | GPL Core + Periphery alternative; scaffold, scripts specified but not written | scaffold |
podman absorbed the former standalone portainer module: Podman is the container
foundation, Portainer is the GUI onto it, one VM. Cockpit was dropped because it fits neither
requirement — it is not an OIDC client and cannot be made one, and its multi-host switcher is
deprecated and disabled by default because it "cannot be secure". The reasoning is in
podman/DESIGN.md.