No description
Find a file
Lars Rossen 828b2c3f1b podman: document internet exposure and what identity does not gate
lab1 is now published with proxyAllowedZones: [internet]. Enabling OAuth does
not disable Portainer's internal login — POST /api/auth stays live and still
accepts the break-glass admin, confirmed against the public endpoint (422
Invalid credentials, not a refused path). So publishing the console publishes a
password path too; the remedy, if that is unacceptable, is to promote an OIDC
user to administrator and delete the local admin, at the cost of break-glass.

Also records that the operator's admin-VPN overlay (admin, 10.255.1.0/24) is
not in the internal default allow-set, which is why a remote admin on the
WireGuard tunnel also gets 403.
2026-08-25 09:56:01 +02:00
src podman: document internet exposure and what identity does not gate 2026-08-25 09:56:01 +02:00
.gitignore Seed the MakerFLOSS devops repo with the podman module 2026-08-22 18:46:24 +02:00
README.md Merge portainer into podman: engine plus GUI in one module 2026-08-25 09:30:11 +02:00

makerfloss

The MakerFLOSS DevOps repository for experimental TAPPaaS modules.

Modules are developed and tried out here, on the TAPPaaS system at makerfloss.eu, before they are proposed upstream to TAPPaaS or Community. Expect things to be half-built, renamed, or removed.

Layout

src/module-catalog.json      # the registry a TAPPaaS instance reads
src/containers/podman/       # one directory per module

Using it from a TAPPaaS instance

Register the repository on the tappaas-cicd mothership, then install a module from it:

site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main

module-manager module add podman --environment <env>

--branch main is not optional: repository add defaults to stable, and this repo has no such branch. The repository name (makerfloss) is derived from the URL, and the clone is made over HTTPS.

Modules

Two takes on the same job — run containers on a lab host, let registered people manage them, reach the other hosts in the zone.

Module What it is Status
podman Podman engine + Portainer CE console; OIDC login, agents on other hosts incomplete — the one the session uses
komodo GPL Core + Periphery alternative; scaffold, scripts specified but not written scaffold

podman absorbed the former standalone portainer module: Podman is the container foundation, Portainer is the GUI onto it, one VM. Cockpit was dropped because it fits neither requirement — it is not an OIDC client and cannot be made one, and its multi-host switcher is deprecated and disabled by default because it "cannot be secure". The reasoning is in podman/DESIGN.md.