wmantly
|
9fb240ff45
|
theta-env: unified SSO Manager + Proxy stack with one-command setup
Composes theta42/sso-manager-node and theta42/proxy (as git submodules) on a
single Docker network and automates first-run wiring.
- docker-compose.yml: sso-manager (build ./sso-manager-node/Dockerfile.openldap)
+ proxy (build ./proxy/Dockerfile) on theta-net; SSO UI + mgmt port bound to
localhost, LDAPS published, proxy 80/443/4443 published.
- setup.sh: idempotent one-command bring-up — validates .env, starts SSO, runs
the bootstrap, writes ./proxy.env, starts the proxy, prints admin login.
- bootstrap/bootstrap.js: runs inside the sso-manager container (self-contained,
Node built-ins + fetch only) — creates the LDAP service account, first admin
(+ app_sso_admin/app_sso_oauth_admin membership), registers the proxy as an
OIDC client via the SSO HTTP API, emits CLIENT_ID/CLIENT_SECRET.
- .env.example: all tunables (LDAP_BASE_DN, LDAP_ADMIN_PASS, JWT_SECRET,
SSO_HOST, PROXY_HOST, BOOTSTRAP_ADMIN_*, LDAP_SERVICE_PASS, SMTP_*, ports).
- README.md + docs/ (Jekyll site for GitHub Pages): quickstart, architecture,
standalone usage.
Co-Authored-By: Claude <noreply@anthropic.com>
|
2026-07-11 17:04:36 -04:00 |
|