portainer: Portainer CE on rootful podman (Portainer drives the Docker-compatible API, and rootless is not supported upstream), published via network:proxy with proxyAllowedZones left unset so members reach it from a client zone but the internet does not. Login is OIDC: identity:identity writes the client credentials, update.sh resolves the endpoints from the discovery document and PUTs them into /api/settings. A break-glass local admin stays for when Authentik is down. Multi-host is the agent on :9001 per host. komodo: scaffold only — komodo.json plus a README that specifies what install.sh and update.sh must do. GPL, no edition split, but it needs a database and models builds and stacks, so it is the alternative rather than the teaching example. Neither has been run on a live TAPPaaS yet; both are catalogued as incomplete.
18 lines
634 B
Bash
Executable file
18 lines
634 B
Bash
Executable file
#!/usr/bin/env bash
|
|
#
|
|
# portainer module install — thin wrapper.
|
|
#
|
|
# The VM is created by the cluster:vm provider (Debian 13 cloud image) and
|
|
# OS-prepped by templates:debian. identity:identity has, by this point, created
|
|
# the OIDC application in Authentik and written OIDC_CLIENT_ID /
|
|
# OIDC_CLIENT_SECRET / OIDC_DISCOVERY_URI to the VM's secrets env file. This
|
|
# script applies the module-specific step; all real work lives in update.sh
|
|
# (install == update for this module).
|
|
#
|
|
# Usage: install.sh <module-name>
|
|
#
|
|
|
|
set -euo pipefail
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
exec "${SCRIPT_DIR}/update.sh" "$@"
|