Split the single architecture slide into two: the iron (three nodes, switch,
AP, modem) and the software (foundation band with the AI and productivity
stacks above it). Both read off the running cluster via tappaas-cicd, not
from docs — CPU, RAM, pool topology, link speeds and switch ports are live
values.
The VM layer-cake is inline SVG rather than mermaid: mermaid ignores
`direction LR` inside a subgraph that has a cross-boundary edge, so the bands
came out as a 629x1258 column.
Module slide now counts all three sources — 8 foundation + 12 apps +
21 Community = 41 — and slide 3 is recomputed for today.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Podman and Portainer are one module now — engine plus GUI — so the deck follows:
podman.json, vmid 812, both sockets on the update.sh slide, and the console at
https://lab1.makerfloss.eu because --proxyDomain makes the module the
environment's gateway rather than podman.lab1.makerfloss.eu.
All commands verified against a live install on lab1.
Installed portainer into lab1 on the live system; several slide commands were
wrong. The verb is 'network-manager add', not 'network-manager zone add', and
there is no 'srv' zone here — the live service zone is 'makerfloss'. Status
verbs need the effective name 'portainer-lab1', while 'module add' takes the
base name. The published host is portainer-lab1.lab1.makerfloss.eu, not
portainer.lab1.makerfloss.eu. Adds the repository registration to Demo 2, which
the deck had never shown.
Talk announced at pretalx.varum.dk/sommerhack-2026/talk/WD8EVP/ —
27 August, Taler Teltet, 60 minutes.
Figures come from the repo rather than the abstract: commit counts and the
per-month graph from git log, source counts from src/STATISTICS.md as
regenerated 2026-08-23. Twelve TODO markers remain for the personal
material (costs, the autumn 2025 dip, war stories).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Retargets the deck from podman to portainer: the contract, the three script
slides, both demo slides and the repo-location slide. Demo 3 is now an actual
single sign-on — 'no login form, you are already you' — because Portainer is an
OIDC client and Cockpit never could be.
The test.sh slide keeps the check worth stealing: /api/settings/public reporting
method 3, which catches identity silently falling back to local accounts.
install.sh, update.sh and test.sh get one slide each, with the real content of
each — including why a 401 from Cockpit is a passing test and why test.sh uses
curl -s rather than --fail.
Corrects the identity story: Cockpit is not an OIDC client and cannot be
configured into one, so the contract shows identity:accessControl and the demo
slide is honest that Authentik gates the URL while Cockpit still asks for a
local account. Full analysis in the module's DESIGN.md.
Date 24 August; the demo environment is lab1 (zone lab1, lab1.makerfloss.eu
outside / lab1.internal inside). Adds the upstream 'developing TAPPaaS modules'
topology from tappaas.org ahead of our own repo picture, which now carries
forgejo.makerfloss.eu and highlights that this site tracks main, not stable.
Drops the manager-verbs slide; the demo slides carry the verbs where they are
actually used, with network/environment/module status commands.
Cockpit now logs in via identity:identity rather than a local PAM password, and
identity hand-out uses 'authentik-manager user-recovery-link' so no password is
ever read aloud. NOTE: podman.json in Community does not yet declare
identity:identity — the module needs that change before the session.
Sixteen slides built around the live demo: two orientation diagrams (site
shape with environments/zones/satellite, and the pull-based GitOps repo
topology), a condensed module anatomy anchored on the real podman.json from
Community/src/larsrossen/containers/podman, the three demo beats (test
environment, module add, prove it), and the identity hand-out.
Mermaid subgraph titles collide with the node row under flowchart TB, so both
diagrams use LR; _class directives repeat 'invert' because a local _class
replaces the deck-level one rather than adding to it.
Adds a second Marp source root. Decks under slides/ build to an output path
mirroring their repo path, so slides/TAPPaaS/HOW-TO/NewModule/index.md is
served at slides.makerfloss.eu/TAPPaaS/HOW-TO/NewModule/. Decks in
docs/presentations/ keep their flat URLs.
The deck itself is a frame: structure and headings from the real
src/apps/00-Template anatomy, content still to be written. Unfinished spots
are written as inline `TODO: ...` and rendered in red so a half-finished
deck cannot be presented by accident.
Also fixes the Docker fallback, which could not write to a mktemp directory
on macOS (not shared with Docker Desktop) and must not be passed --user.