portainer: Portainer CE on rootful podman (Portainer drives the Docker-compatible API, and rootless is not supported upstream), published via network:proxy with proxyAllowedZones left unset so members reach it from a client zone but the internet does not. Login is OIDC: identity:identity writes the client credentials, update.sh resolves the endpoints from the discovery document and PUTs them into /api/settings. A break-glass local admin stays for when Authentik is down. Multi-host is the agent on :9001 per host. komodo: scaffold only — komodo.json plus a README that specifies what install.sh and update.sh must do. GPL, no edition split, but it needs a database and models builds and stacks, so it is the alternative rather than the teaching example. Neither has been run on a live TAPPaaS yet; both are catalogued as incomplete. |
||
|---|---|---|
| src | ||
| .gitignore | ||
| README.md | ||
makerfloss
The MakerFLOSS DevOps repository for experimental TAPPaaS modules.
Modules are developed and tried out here, on the TAPPaaS system at makerfloss.eu, before they are proposed upstream to TAPPaaS or Community. Expect things to be half-built, renamed, or removed.
Layout
src/module-catalog.json # the registry a TAPPaaS instance reads
src/containers/podman/ # one directory per module
Using it from a TAPPaaS instance
Register the repository on the tappaas-cicd mothership, then install a module
from it:
site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main
module-manager module add podman --environment <env>
--branch main is not optional: repository add defaults to stable, and this
repo has no such branch. The repository name (makerfloss) is derived from the
URL, and the clone is made over HTTPS.
Modules
Three parallel takes on the same job — run containers on a lab host, let registered people manage them, reach the other hosts in the zone. They exist side by side on purpose.
| Module | What it is | Status |
|---|---|---|
| portainer | Portainer CE on rootful Podman; OIDC login, agents on other hosts | incomplete — the one the session uses |
| komodo | GPL Core + Periphery alternative; scaffold, scripts specified but not written | scaffold |
| podman | Plain Podman host with the Cockpit console; single host, local login | incomplete |
Why three: Cockpit turned out to fit neither requirement — it is not an OIDC client and cannot be made one, and its multi-host switcher is deprecated and disabled by default because it "cannot be secure". The reasoning is written up in podman/DESIGN.md.