From 2722c89dcba95d54816e0fc595d7a87f161633c4 Mon Sep 17 00:00:00 2001 From: Lars Rossen Date: Mon, 24 Aug 2026 21:03:01 +0200 Subject: [PATCH] slides(tappaas): correct the demo commands against a real run MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Installed portainer into lab1 on the live system; several slide commands were wrong. The verb is 'network-manager add', not 'network-manager zone add', and there is no 'srv' zone here — the live service zone is 'makerfloss'. Status verbs need the effective name 'portainer-lab1', while 'module add' takes the base name. The published host is portainer-lab1.lab1.makerfloss.eu, not portainer.lab1.makerfloss.eu. Adds the repository registration to Demo 2, which the deck had never shown. --- slides/tappaas/how-to/new-module/index.md | 28 ++++++++++++----------- 1 file changed, 15 insertions(+), 13 deletions(-) diff --git a/slides/tappaas/how-to/new-module/index.md b/slides/tappaas/how-to/new-module/index.md index f847d79..11dff43 100644 --- a/slides/tappaas/how-to/new-module/index.md +++ b/slides/tappaas/how-to/new-module/index.md @@ -250,7 +250,7 @@ unattended updates are safe — that is the entire deal. - A VM — `cluster:vm` built it from the Debian 13 cloud image - OS prep — `templates:debian` did apt + guest agent - A VLAN, an interface, DHCP, firewall rules — the zone came with the environment -- `https://portainer.lab1.makerfloss.eu` with a real certificate — `network:proxy` +- `https://portainer-lab1.lab1.makerfloss.eu`, valid cert — `network:proxy` - An OIDC application, a group binding and client credentials — `identity:identity` - Nightly backup to PBS, scheduled updates, health reporting @@ -261,19 +261,17 @@ A few lines of json bought all of it. ## Demo 1 — an environment of our own ```bash -network-manager zone add lab1 --from-zone srv -network-manager show lab1 # vlan tag, subnet, access-to +network-manager add lab1 --from-zone makerfloss # --check first for a dry run +network-manager show lab1 # vlan 299, 10.2.99.0/24, access-to network-manager reconcile # dry-run: drift on all 4 planes -network-manager reconcile --apply # converge OPNsense, Proxmox, switch, AP -environment-manager add lab1 --display "MakerFLOSS lab" \ +environment-manager add lab1 --display "MakerFLOSS lab" --owner makerfloss \ --zone lab1 --domain lab1.makerfloss.eu -environment-manager list environment-manager show lab1 ``` -A tenant with its own VLAN, firewall posture and DNS names — -`lab1.makerfloss.eu` outside, `lab1.internal` inside. +`add` reconciles every plane itself. A tenant with its own VLAN, firewall +posture and DNS names — `lab1.makerfloss.eu` outside, `lab1.internal` inside. @@ -282,12 +280,16 @@ A tenant with its own VLAN, firewall posture and DNS names — ## Demo 2 — install the module ```bash -module-manager module add portainer --environment lab1 +site-manager repository add forgejo.makerfloss.eu/TAPPaaS/makerfloss --branch main -module-manager module list # what is deployed -module-manager module show portainer # the resolved config, cascade applied +module-manager module add portainer --environment lab1 +module-manager module list # what is deployed +module-manager module show portainer-lab1 # note the -lab1 suffix ``` +Outside the default environment the module is **`portainer-lab1`** — `add` takes +the base name, everything after it takes the effective one. + Watch the order: dependencies resolve first, then the VM, then the network, then `install.sh`. Install order is **computed** from every module's `dependsOn` — nobody maintains a list. @@ -299,10 +301,10 @@ maintains a list. ## Demo 3 — prove it, then look at it ```bash -module-manager module test portainer +module-manager module test portainer-lab1 ``` -Then open **`https://portainer.lab1.makerfloss.eu`** and press **Sign in**. +Then open **`https://portainer-lab1.lab1.makerfloss.eu`** and press **Sign in**. - No login form. You are already you — Authentik, via OIDC. - Not in `devops`? No console. The group binding **is** the access gate.