3e85e37b63
- CFG_SITE_NAME in setup.env (below CFG_DOMAIN, default "local") names the directory site; slug site_<name> matches ldap-client's parentSlug convention so joined Linux hosts land under the same site. Wired through sso-secrets.js stack.siteName. - setup.sh collects host facts ON THE HOST (hostname, IP, default-route MAC, OS pretty-name, kernel — same collection as ldap-client/index.sh) and passes them into the bootstrap exec env; the stack host is now registered as host_<hostname> with that metadata (subType linux). - Services carry their internal port and git repo in metadata (sso-manager 3001, proxy 3000, openldap 389/ext 636, openresty 443), using the metadata keys the directory UI natively displays. - ensure() now adopts resources from the earlier seed layout (alt slugs 'stack-host' / domain-slug site) and back-fills missing seed metadata via a metadata-only PUT — operator-set values are never overwritten. Verified against a live app: old-layout resources are adopted and back-filled (no duplicates), fresh seed creates the full graph, and a second pass changes nothing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
79 lines
4.5 KiB
Bash
79 lines
4.5 KiB
Bash
# ─────────────────────────────────────────────────────────────────────────────
|
|
# setup.env — first-run setup for the theta-env stack.
|
|
#
|
|
# This file is used ONLY on the FIRST run of ./setup.sh, to generate
|
|
# ./config/sso-secrets.js + ./config/proxy-secrets.js with your domain filled
|
|
# in everywhere consistently. Once ./config/*.js exist they are operator-owned
|
|
# (edit them directly; setup.env is ignored on later runs).
|
|
#
|
|
# cp setup.env.example setup.env
|
|
# $EDITOR setup.env # set CFG_DOMAIN below to your domain
|
|
# ./setup.sh # generates ./config/ and builds the stack
|
|
#
|
|
# Copying this file to setup.env (gitignored) keeps your domain out of git.
|
|
# ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
# Your domain. THIS IS THE ONE PLACE THE DOMAIN IS ENTERED. Everything else
|
|
# derives from it: the SSO/proxy hostnames default to sso.<domain> /
|
|
# proxy.<domain>, and the LDAP base DN is built from it (example.com becomes
|
|
# dc=example,dc=com; a 3-label domain like myhost.duckdns.org becomes
|
|
# dc=myhost,dc=duckdns,dc=org — any number of labels works). Required —
|
|
# setup.sh refuses to run without it.
|
|
CFG_DOMAIN=example.com
|
|
|
|
# Site name for the SSO directory — the root node this stack registers itself
|
|
# under on the Directory page, and the default "Location (Site)" that Linux
|
|
# hosts joined via ldap-client attach to (parent slug: site_<name>).
|
|
# Optional — defaults to "local".
|
|
#CFG_SITE_NAME=local
|
|
|
|
# Public hostnames. Optional — default to sso.<domain> / proxy.<domain> derived
|
|
# from CFG_DOMAIN above. Uncomment and set only if your hostnames differ
|
|
# (e.g. a different subdomain, or the domain isn't the bare apex):
|
|
#CFG_SSO_HOST=sso.example.com
|
|
#CFG_PROXY_HOST=proxy.example.com
|
|
|
|
# Advanced: override the derived LDAP base DN directly (e.g. to namespace
|
|
# under an OU-style prefix). Leave unset to use the DN built from CFG_DOMAIN:
|
|
#CFG_BASE_DN=dc=example,dc=com
|
|
|
|
# Optional — sensible defaults if left blank:
|
|
#CFG_ORG=SSO Manager # app display name + outbound email org
|
|
#CFG_ADMIN_UID=admin # initial SSO admin username
|
|
#CFG_ADMIN_EMAIL=admin@proxy.example.com # defaults to admin@<proxyHost>
|
|
#CFG_LDAP_CERT_CN= # LDAP TLS cert CN; empty -> defaults to the domain
|
|
#
|
|
# Hostname advertised on the SSO /integrations page for direct LDAPS binds.
|
|
# Leave blank to derive it from the public SSO host (same as oauth.issuer).
|
|
# Recommended: set an internal-only name like 'ldap.internal.example.com' or
|
|
# 'sso-manager' so clients don't need a public 636 port forward. See docs.
|
|
#CFG_LDAPS_HOST=
|
|
|
|
# Optional SMTP (outbound email from the SSO app). Leave blank to disable:
|
|
#CFG_SMTP_HOST=smtp.example.com
|
|
#CFG_SMTP_PORT=587
|
|
#CFG_SMTP_USER=noreply@example.com
|
|
#CFG_SMTP_PASS=your-smtp-password
|
|
#CFG_SMTP_FROM=SSO Manager <noreply@example.com>
|
|
|
|
# ── DO NOT put secrets here ──────────────────────────────────────────────────
|
|
# The LDAP admin password, JWT secret, admin password, LDAP service-account
|
|
# password, and the proxy's local admin password are all GENERATED (random)
|
|
# into ./config/sso-secrets.js + ./config/proxy-secrets.js on first run.
|
|
# Change them later by editing those files directly (the proxy's local admin
|
|
# password is the exception — see ./config/proxy-secrets.js's auth.localAdminPass
|
|
# comment for how to actually change it after the account exists). Do NOT set
|
|
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
|
# CFG_PROXY_ADMIN_PASS here.
|
|
|
|
# ── Geo-Location Scaling (N-Way Multi-Master LDAP) ───────────────────────────
|
|
# If deploying this stack across multiple physical sites to provide local HA
|
|
# for directory services, you can enable N-Way Multi-Master OpenLDAP replication.
|
|
# This requires assigning a unique ID to each site and listing the LDAPS URLs
|
|
# of all OTHER sites in the cluster.
|
|
#
|
|
# Each site MUST have a unique LDAP_SERVER_ID (e.g. 1, 2, 3).
|
|
# LDAP_REPLICATION_HOSTS is a space-separated list of the other sites' LDAP URLs.
|
|
# Example for Site 1:
|
|
#LDAP_SERVER_ID=1
|
|
#LDAP_REPLICATION_HOSTS="ldaps://sso.site2.com:636 ldaps://sso.site3.com:636" |