portainer: Portainer CE on rootful podman (Portainer drives the Docker-compatible API, and rootless is not supported upstream), published via network:proxy with proxyAllowedZones left unset so members reach it from a client zone but the internet does not. Login is OIDC: identity:identity writes the client credentials, update.sh resolves the endpoints from the discovery document and PUTs them into /api/settings. A break-glass local admin stays for when Authentik is down. Multi-host is the agent on :9001 per host. komodo: scaffold only — komodo.json plus a README that specifies what install.sh and update.sh must do. GPL, no edition split, but it needs a database and models builds and stacks, so it is the alternative rather than the teaching example. Neither has been run on a live TAPPaaS yet; both are catalogued as incomplete.
47 lines
1.9 KiB
Markdown
47 lines
1.9 KiB
Markdown
# makerfloss
|
|
|
|
The MakerFLOSS **DevOps repository** for experimental TAPPaaS modules.
|
|
|
|
Modules are developed and tried out here, on the TAPPaaS system at
|
|
[makerfloss.eu](https://makerfloss.eu), before they are proposed upstream to
|
|
[TAPPaaS](https://codeberg.org/TAPPaaS/TAPPaaS) or
|
|
[Community](https://codeberg.org/TAPPaaS/Community). Expect things to be
|
|
half-built, renamed, or removed.
|
|
|
|
## Layout
|
|
|
|
```text
|
|
src/module-catalog.json # the registry a TAPPaaS instance reads
|
|
src/containers/podman/ # one directory per module
|
|
```
|
|
|
|
## Using it from a TAPPaaS instance
|
|
|
|
Register the repository on the `tappaas-cicd` mothership, then install a module
|
|
from it:
|
|
|
|
```bash
|
|
site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main
|
|
|
|
module-manager module add podman --environment <env>
|
|
```
|
|
|
|
`--branch main` is not optional: `repository add` defaults to `stable`, and this
|
|
repo has no such branch. The repository name (`makerfloss`) is derived from the
|
|
URL, and the clone is made over HTTPS.
|
|
|
|
## Modules
|
|
|
|
Three parallel takes on the same job — run containers on a lab host, let registered people
|
|
manage them, reach the other hosts in the zone. They exist side by side on purpose.
|
|
|
|
| Module | What it is | Status |
|
|
| --- | --- | --- |
|
|
| [portainer](src/containers/portainer) | Portainer CE on rootful Podman; OIDC login, agents on other hosts | incomplete — **the one the session uses** |
|
|
| [komodo](src/containers/komodo) | GPL Core + Periphery alternative; scaffold, scripts specified but not written | scaffold |
|
|
| [podman](src/containers/podman) | Plain Podman host with the Cockpit console; single host, local login | incomplete |
|
|
|
|
Why three: Cockpit turned out to fit neither requirement — it is not an OIDC client and
|
|
cannot be made one, and its multi-host switcher is deprecated and disabled by default because
|
|
it "cannot be secure". The reasoning is written up in
|
|
[podman/DESIGN.md](src/containers/podman/DESIGN.md#identity-integration--the-analysis).
|